| 31 Aug 2026 | Meta Researcher's AI Agent Accidentally Deleted Her Emails | Meta | other | hallucinated action | | reported |
| 31 Aug 2026 | Origin validation error in ash_ai MCP server allows DNS rebinding attacks | ash-project | other | misconfiguration | | confirmed |
| 31 Aug 2026 | CVE-2026-82905: SSRF in sdcb chats McpController | sdcb | other | tool misuse | | reported |
| 28 Aug 2026 | SiYuan path traversal and path guard bypass vulnerabilities | SiYuan | other | prompt injection | | confirmed |
| 28 Aug 2026 | Multiple vulnerabilities in Microsoft Copilot products | Microsoft | other | misconfiguration | | reported |
| 28 Aug 2026 | Hatchet Dispatcher gRPC Service Missing Tenant Verification | Hatchet | workflow | misconfiguration | | resolved |
| 27 Aug 2026 | GitLab AI Gateway credential disclosure vulnerabilities | GitLab | other | prompt injection | | resolved |
| 27 Aug 2026 | mcp-go HTTP Host header validation vulnerability | mark3labs | other | misconfiguration | | resolved |
| 27 Aug 2026 | mcp-router CLI exposed MCP aggregator without authentication by default | mcp-router | other | misconfiguration | | resolved |
| 27 Aug 2026 | CVE-2026-81096: ToolUniverse sandbox escape and unauthenticated RCE | ToolUniverse | coding | excessive permissions | | confirmed |
| 27 Aug 2026 | Dash MCP server DNS rebinding via missing host header validation | Dropbox | other | misconfiguration | | resolved |
| 27 Aug 2026 | ServiceNow AI platform code injection and SQL injection vulnerabilities | ServiceNow | other | unknown | | resolved |
| 27 Aug 2026 | mcp-use Inspector Proxy SSRF via Unvalidated Target URL | mcp-use | other | misconfiguration | | resolved |
| 27 Aug 2026 | CVE-2026-81093: Apify MCP Server SSRF in get-html-skeleton tool | Apify | browsing | excessive permissions | | resolved |
| 27 Aug 2026 | DNS Rebinding Vulnerability in Timescale MCP Tools | Timescale | other | misconfiguration | | confirmed |
| 27 Aug 2026 | Telnyx MCP Server Missing Authentication on HTTP Transport | Telnyx | coding | misconfiguration | | resolved |
| 27 Aug 2026 | UI-TARS-desktop MCP servers bind to all interfaces without authentication | ByteDance | other | misconfiguration | | confirmed |
| 27 Aug 2026 | Agno Remote Code Execution via Prompt Injection | Agno | coding | prompt injection | | reported |
| 27 Aug 2026 | Nightingale SSRF vulnerability in http_fetch AI-agent tool | Nightingale | other | misconfiguration | | confirmed |
| 26 Aug 2026 | CVE-2026-75062: Eval Injection in Google langfun | Google | coding | prompt injection | | confirmed |
| 25 Aug 2026 | CVE-2026-55529: PraisonAI Origin Validation Bypass | MervinPraison | workflow | misconfiguration | | resolved |
| 25 Aug 2026 | mcp-shell Multiple Command Execution Vulnerabilities | sonirico | coding | misconfiguration | | resolved |
| 25 Aug 2026 | Nextcloud MCP Server unauthenticated webhook endpoint allows index deletion | Nextcloud | coding | misconfiguration | | resolved |
| 25 Aug 2026 | CVE-2026-55637: genieacs-mcp DNS rebinding vulnerability | GeiserX | other | misconfiguration | | resolved |
| 25 Aug 2026 | Path traversal in sublinear-time-solver and consciousness-explorer | ruvnet | other | misconfiguration | | resolved |
| 25 Aug 2026 | Prompt injection in Amazon Strands Agents Tools python_repl | Amazon | coding | prompt injection | | confirmed |
| 25 Aug 2026 | Dradis CE SSRF via unrestricted AI provider address | Dradis | coding | excessive permissions | | reported |
| 25 Aug 2026 | MCP PHP SDK Memory Exhaustion Vulnerability | Anthropic | other | tool misuse | | resolved |
| 24 Aug 2026 | Continue CLI incomplete denylist allows destructive commands | Continue | workflow | prompt injection | | reported |
| 21 Aug 2026 | Spring AI MCP Streamable HTTP server memory exhaustion DoS | Spring | other | misconfiguration | | reported |
| 21 Aug 2026 | Infracost symlink traversal and token disclosure vulnerabilities | Infracost | coding | tool misuse | | resolved |
| 20 Aug 2026 | AI Agent by SiteGround WordPress plugin authorization bypass | SiteGround | coding | excessive permissions | | reported |
| 20 Aug 2026 | LangBot MCP Server RCE via Insufficient Authorization | LangBot | coding | excessive permissions | | reported |
| 20 Aug 2026 | Neo.mjs command injection in FileSystemService.mjs | Neo.mjs | coding | tool misuse | | resolved |
| 20 Aug 2026 | LangChain SitemapLoader SSRF bypass via nested sitemap entries | LangChain | other | excessive permissions | | reported |
| 19 Aug 2026 | Splunk AI Toolkit privilege escalation and MCP Server command execution | Splunk | coding | excessive permissions | | reported |
| 19 Aug 2026 | marimo Code Injection via MCP Server Configuration | marimo-team | coding | prompt injection | | confirmed |
| 19 Aug 2026 | Agno PythonTools path traversal vulnerability CVE-2026-76832 | Agno | coding | prompt injection | | reported |
| 18 Aug 2026 | Command Injection and SSRF Vulnerabilities in Microsoft Copilot | Microsoft | coding | prompt injection | | reported |
| 18 Aug 2026 | Apify MCP Server API Token Exposure via URL Redirection | Apify | coding | prompt injection | | resolved |
| 18 Aug 2026 | ArcadeDB authorization bypass in set_server_setting MCP tool | ArcadeData | other | excessive permissions | | resolved |
| 18 Aug 2026 | CodeWhale Multiple Vulnerabilities in Versions 0.8.41-0.8.63 | CodeWhale | coding | prompt injection | | resolved |
| 18 Aug 2026 | CVE-2026-75130: Context7 prompt injection via Custom AI Instructions | Context7 | coding | prompt injection | | reported |
| 17 Aug 2026 | CVE-2026-19984: SSRF in jkawamoto mcp-florence2 | jkawamoto | other | tool misuse | | confirmed |
| 17 Aug 2026 | MLflow multiple vulnerabilities in versions prior to 3.15.0 | MLflow | other | excessive permissions | | resolved |
| 17 Aug 2026 | MemOS Authentication Bypass via Unset Internal Service Secret | MemTensor | other | misconfiguration | | reported |
| 14 Aug 2026 | CVE-2026-49986: Cortex MCP Arbitrary Code Execution via Environment Variable | Cortex | coding | misconfiguration | | confirmed |
| 14 Aug 2026 | mcp-memory-service authentication bypass in document endpoints | mcp-memory-service | other | misconfiguration | | confirmed |
| 14 Aug 2026 | Multiple vulnerabilities in CKAN MCP Server prior to 0.4.112 | ondata | other | misconfiguration | | resolved |
| 14 Aug 2026 | MindsDB Minds Platform unauthenticated RCE via scratchpad tool | MindsDB | coding | excessive permissions | | reported |