Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Incident database

Structured records of AI agent security incidents: what happened, which vendor and agent type, the root cause, and every source we used. Filter, browse, or download as CSV.

Incidents by month, 2026 · 434 total · click a month to filter
Jan 2026: 23 incidents23JanFeb 2026: 26 incidents26FebMar 2026: 46 incidents46MarApr 2026: 46 incidents46AprMay 2026: 52 incidents52MayJun 2026: 51 incidents51JunJul 2026: 45 incidents45JulAug 2026: 82 incidents82AugSep 2026: 63 incidents63SepOct 2026: 0 incidents0OctNov 2026: 0 incidents0NovDec 2026: 0 incidents0Dec
Clear

82 incidents match

Incident dateIncidentVendorAgentRoot causeSeverityStatus
31 Aug 2026Meta Researcher's AI Agent Accidentally Deleted Her EmailsMetaotherhallucinated actionreported
31 Aug 2026Origin validation error in ash_ai MCP server allows DNS rebinding attacksash-projectothermisconfigurationconfirmed
31 Aug 2026CVE-2026-82905: SSRF in sdcb chats McpControllersdcbothertool misusereported
28 Aug 2026SiYuan path traversal and path guard bypass vulnerabilitiesSiYuanotherprompt injectionconfirmed
28 Aug 2026Multiple vulnerabilities in Microsoft Copilot productsMicrosoftothermisconfigurationreported
28 Aug 2026Hatchet Dispatcher gRPC Service Missing Tenant VerificationHatchetworkflowmisconfigurationresolved
27 Aug 2026GitLab AI Gateway credential disclosure vulnerabilitiesGitLabotherprompt injectionresolved
27 Aug 2026mcp-go HTTP Host header validation vulnerabilitymark3labsothermisconfigurationresolved
27 Aug 2026mcp-router CLI exposed MCP aggregator without authentication by defaultmcp-routerothermisconfigurationresolved
27 Aug 2026CVE-2026-81096: ToolUniverse sandbox escape and unauthenticated RCEToolUniversecodingexcessive permissionsconfirmed
27 Aug 2026Dash MCP server DNS rebinding via missing host header validationDropboxothermisconfigurationresolved
27 Aug 2026ServiceNow AI platform code injection and SQL injection vulnerabilitiesServiceNowotherunknownresolved
27 Aug 2026mcp-use Inspector Proxy SSRF via Unvalidated Target URLmcp-useothermisconfigurationresolved
27 Aug 2026CVE-2026-81093: Apify MCP Server SSRF in get-html-skeleton toolApifybrowsingexcessive permissionsresolved
27 Aug 2026DNS Rebinding Vulnerability in Timescale MCP ToolsTimescaleothermisconfigurationconfirmed
27 Aug 2026Telnyx MCP Server Missing Authentication on HTTP TransportTelnyxcodingmisconfigurationresolved
27 Aug 2026UI-TARS-desktop MCP servers bind to all interfaces without authenticationByteDanceothermisconfigurationconfirmed
27 Aug 2026Agno Remote Code Execution via Prompt InjectionAgnocodingprompt injectionreported
27 Aug 2026Nightingale SSRF vulnerability in http_fetch AI-agent toolNightingaleothermisconfigurationconfirmed
26 Aug 2026CVE-2026-75062: Eval Injection in Google langfunGooglecodingprompt injectionconfirmed
25 Aug 2026CVE-2026-55529: PraisonAI Origin Validation BypassMervinPraisonworkflowmisconfigurationresolved
25 Aug 2026mcp-shell Multiple Command Execution Vulnerabilitiessoniricocodingmisconfigurationresolved
25 Aug 2026Nextcloud MCP Server unauthenticated webhook endpoint allows index deletionNextcloudcodingmisconfigurationresolved
25 Aug 2026CVE-2026-55637: genieacs-mcp DNS rebinding vulnerabilityGeiserXothermisconfigurationresolved
25 Aug 2026Path traversal in sublinear-time-solver and consciousness-explorerruvnetothermisconfigurationresolved
25 Aug 2026Prompt injection in Amazon Strands Agents Tools python_replAmazoncodingprompt injectionconfirmed
25 Aug 2026Dradis CE SSRF via unrestricted AI provider addressDradiscodingexcessive permissionsreported
25 Aug 2026MCP PHP SDK Memory Exhaustion VulnerabilityAnthropicothertool misuseresolved
24 Aug 2026Continue CLI incomplete denylist allows destructive commandsContinueworkflowprompt injectionreported
21 Aug 2026Spring AI MCP Streamable HTTP server memory exhaustion DoSSpringothermisconfigurationreported
21 Aug 2026Infracost symlink traversal and token disclosure vulnerabilitiesInfracostcodingtool misuseresolved
20 Aug 2026AI Agent by SiteGround WordPress plugin authorization bypassSiteGroundcodingexcessive permissionsreported
20 Aug 2026LangBot MCP Server RCE via Insufficient AuthorizationLangBotcodingexcessive permissionsreported
20 Aug 2026Neo.mjs command injection in FileSystemService.mjsNeo.mjscodingtool misuseresolved
20 Aug 2026LangChain SitemapLoader SSRF bypass via nested sitemap entriesLangChainotherexcessive permissionsreported
19 Aug 2026Splunk AI Toolkit privilege escalation and MCP Server command executionSplunkcodingexcessive permissionsreported
19 Aug 2026marimo Code Injection via MCP Server Configurationmarimo-teamcodingprompt injectionconfirmed
19 Aug 2026Agno PythonTools path traversal vulnerability CVE-2026-76832Agnocodingprompt injectionreported
18 Aug 2026Command Injection and SSRF Vulnerabilities in Microsoft CopilotMicrosoftcodingprompt injectionreported
18 Aug 2026Apify MCP Server API Token Exposure via URL RedirectionApifycodingprompt injectionresolved
18 Aug 2026ArcadeDB authorization bypass in set_server_setting MCP toolArcadeDataotherexcessive permissionsresolved
18 Aug 2026CodeWhale Multiple Vulnerabilities in Versions 0.8.41-0.8.63CodeWhalecodingprompt injectionresolved
18 Aug 2026CVE-2026-75130: Context7 prompt injection via Custom AI InstructionsContext7codingprompt injectionreported
17 Aug 2026CVE-2026-19984: SSRF in jkawamoto mcp-florence2jkawamotoothertool misuseconfirmed
17 Aug 2026MLflow multiple vulnerabilities in versions prior to 3.15.0MLflowotherexcessive permissionsresolved
17 Aug 2026MemOS Authentication Bypass via Unset Internal Service SecretMemTensorothermisconfigurationreported
14 Aug 2026CVE-2026-49986: Cortex MCP Arbitrary Code Execution via Environment VariableCortexcodingmisconfigurationconfirmed
14 Aug 2026mcp-memory-service authentication bypass in document endpointsmcp-memory-serviceothermisconfigurationconfirmed
14 Aug 2026Multiple vulnerabilities in CKAN MCP Server prior to 0.4.112ondataothermisconfigurationresolved
14 Aug 2026MindsDB Minds Platform unauthenticated RCE via scratchpad toolMindsDBcodingexcessive permissionsreported