Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Incident database

Structured records of AI agent security incidents: what happened, which vendor and agent type, the root cause, and every source we used. Filter, browse, or download as CSV.

Incidents by month, 2026 · 434 total · click a month to filter
Jan 2026: 23 incidents23JanFeb 2026: 26 incidents26FebMar 2026: 46 incidents46MarApr 2026: 46 incidents46AprMay 2026: 52 incidents52MayJun 2026: 51 incidents51JunJul 2026: 45 incidents45JulAug 2026: 82 incidents82AugSep 2026: 63 incidents63SepOct 2026: 0 incidents0OctNov 2026: 0 incidents0NovDec 2026: 0 incidents0Dec
Clear

45 incidents match

Incident dateIncidentVendorAgentRoot causeSeverityStatus
31 Jul 2026CVE-2026-18394: Incorrect authorization in Strands Agents Tools http_requestStrandsotherexcessive permissionsconfirmed
29 Jul 2026MCP Ruby SDK memory exhaustion via unbounded session objectsAnthropicothermisconfigurationresolved
29 Jul 2026Pydantic AI Multiple Vulnerabilities in Versions 1.56.0-2.0.0b5Pydanticworkflowexcessive permissionsresolved
29 Jul 2026Flyto2 Core SSRF vulnerability in HTTP modulesFlytoworkflowmisconfigurationconfirmed
29 Jul 2026MCP Ruby SDK Multiple Vulnerabilities Prior to 0.23.0Anthropicothermisconfigurationresolved
28 Jul 2026CVE-2026-9680: Alibabacloud RDS OpenAPI MCP Server ExposedAlibaba Cloudothermisconfigurationreported
28 Jul 2026GitHub MCP Server nil pointer dereference denial of serviceGitHubothermisconfigurationresolved
27 Jul 2026CVE-2026-17534: Kimi Code SSRF via DNS resolution bypassMoonshot AIcodingprompt injectionresolved
26 Jul 2026CVE-2026-17433: Improper authorization in nanocoai NanoClawnanocoaiotherexcessive permissionsreported
25 Jul 2026CVE-2026-66012: SiYuan Missing Authorization in MCP Kernel EndpointSiYuanotherexcessive permissionsconfirmed
24 Jul 2026CVE-2026-50517: Unsafe deserialization in M365 CopilotMicrosoftothertool misusereported
24 Jul 2026BlenderMCP path traversal vulnerability in download_polyhaven_assetBlenderMCPcodingprompt injectionconfirmed
24 Jul 2026Jan Local API Server CORS Misconfiguration (CVE-2026-66005)Janothermisconfigurationresolved
24 Jul 2026Suna message queue API broken access control vulnerabilityKortix AIotherexcessive permissionsconfirmed
23 Jul 2026APIFold webhook endpoint accepts unauthenticated arbitrary JSONAPIFoldothermisconfigurationresolved
23 Jul 2026Void path traversal in AI agent file-reading toolsVoidcodingprompt injectionreported
23 Jul 2026AgentGPT authorization bypass allows unauthorized task attachmentAgentGPTworkflowexcessive permissionsreported
22 Jul 2026n8n privilege escalation and OAuth authorization vulnerabilitiesn8notherexcessive permissionsconfirmed
22 Jul 2026Path traversal in Ansible Lightspeed MCP server via prompt injectionRed Hatcodingprompt injectionreported
21 Jul 2026MCP-for-Stata Command Injection via log_file_name ParameterSepineTamcodingprompt injectionconfirmed
21 Jul 2026mcp-webresearch 0.1.7 SSRF vulnerability via LLM prompt injectionmcp-webresearchbrowsingprompt injectionreported
20 Jul 2026Network-AI MCP SSE Server Missing AuthenticationNetwork-AIothermisconfigurationconfirmed
20 Jul 2026nono Sandbox Escape via Unix Domain Socket Accessnolabsothermisconfigurationresolved
20 Jul 2026AgenticMail Multiple Vulnerabilities Allowing Agent Impersonation and Prompt InjectionAgenticMailcodingprompt injectionresolved
20 Jul 2026NextCRM MCP API Missing Role Checks in Product OperationsNextCRMcodingexcessive permissionsconfirmed
17 Jul 2026AI Copilot WordPress plugin OAuth token binding vulnerabilityAI Copilotothermisconfigurationreported
17 Jul 2026ForgeCode automatically executes arbitrary commands from malicious .mcp.jsontailcallhqcodingmisconfigurationreported
17 Jul 2026CVE-2026-58195: Agentic-Flow Command Injection via MCP Server Toolsruvnetworkflowtool misuseresolved
17 Jul 2026IBM Langflow OSS code injection via ToolGuard integrationIBMworkflowexcessive permissionsreported
16 Jul 2026Claude Code Action arbitrary code execution via malicious .mcp.jsonAnthropiccodingmisconfigurationresolved
16 Jul 2026dbt-mcp argument injection and data leak vulnerabilitiesdbt Labsworkflowexcessive permissionsresolved
16 Jul 2026Apify MCP Server URL Validation BypassApifyothermisconfigurationresolved
9 Jul 2026CVE-2026-15189: SSRF in aerostack-mcp WhatsApp MCP upload_media toolaerostackdevworkflowtool misusereported
9 Jul 2026n8n and n8n-MCP flaws expose credentials and cross-tenant workflow backupsn8nworkflowexcessive permissionsresolved
8 Jul 2026Researchers trick GitHub's AI coding agent into leaking private repositoriesGitHubcodingprompt injectionreported
8 Jul 2026CVE-2026-59807: Composio SDK path validation bypass enables credential file exfiltrationComposioworkflowprompt injectionresolved
8 Jul 2026LiteLLM MCP endpoint authentication bypass via forged Authorization header (CVE-2026-59822)BerriAIotherexcessive permissionsresolved
8 Jul 2026CVE-2026-59723: Cline Hub dashboard WebSocket flaw allows remote command executionClinecodingmisconfigurationresolved
6 Jul 2026CVE-2026-14898: Codex macOS app image rendering enables prompt-injection data exfiltrationOpenAIcodingprompt injectionreported
6 Jul 2026CVE-2026-44934: SUSE Rancher AI Agent leaks API keys in DEBUG logsSUSEworkflowdata leakresolved
5 Jul 2026CVE-2026-14742: Weak hash in LangGraph task result cache keylangchain-aiworkflowunknownreported
5 Jul 2026SSRF in AIAnytime Awesome-MCP-Server wiki-summary tool (CVE-2026-14748)AIAnytimeworkflowtool misusereported
3 Jul 2026CVE-2026-13341: Indirect prompt injection in Kong Konnect MCP serverKongworkflowprompt injectionresolved
2 Jul 2026fast-mcp-telegram MCP server auth bypass via path traversal in bearer token (CVE-2026-52830)leshchenko1979otherexcessive permissionsresolved
2 Jul 2026CVE-2026-41106: Open redirect in M365 Copilot enables privilege elevationMicrosoftworkflowmisconfigurationconfirmed