12 Sept 2026 · MCPHub
MCPHub before version 1.0.32 contains an authentication bypass vulnerability in its embedded OAuth 2.0 authorization server where client authentication is disabled by default and PKCE enforcement is optional, allowing attackers to redeem intercepted authorization codes for access tokens without proper credentials.
other·misconfiguration·
11 Sept 2026 · FrontMCP
A GitHub advisory reports that the patch for an earlier SSRF issue (CVE-2026-39885) in mcp-from-openapi 2.3.0 can be bypassed, letting untrusted OpenAPI specs loaded by FrontMCP 1.2.1 trigger backend-origin requests to loopback or private services via DNS-to-loopback names, redirects, and IPv4-mapped IPv6 forms. In hosted or multi-user FrontMCP deployments where users can import specs, this can expose internal APIs not reachable externally.
other·supply chain·
11 Sept 2026 · Anthropic
Anthropic reported that multiple threat groups, including financially motivated actors and state-linked espionage groups associated with Russia and China, attempted to abuse its Claude AI model for malicious purposes, including extracting secrets from 1.8 million Android apps. Separate reporting describes attackers abusing trusted AI platforms, such as weaponized Claude Artifacts and shared AI conversations, to host malicious content and lure users into installing malware.
other·tool misuse·
11 Sept 2026 · mysql-mcp-server
The mysql-mcp-server MCP package, when run in SSE/HTTP transport mode, created its SSE transport without security settings, disabling DNS-rebinding protection and leaving all routes unauthenticated while binding to 0.0.0.0. This allowed network attackers or malicious web pages to invoke execute_sql for arbitrary unauthenticated SQL execution, data exfiltration, and potentially file read/write and RCE; 25 publicly reachable instances were found.
workflow·misconfiguration·
11 Sept 2026 · IBM
IBM Langflow OSS versions 1.0.0 through 1.11.5 contain multiple vulnerabilities allowing remote authenticated attackers to execute arbitrary Python code, OS commands, and access sensitive information due to improper authorization, insufficient session expiration, and pathname restrictions.
workflow·excessive permissions·
10 Sept 2026 · Lenovo
A command injection vulnerability in Tianxi AI Agent PC Application could allow OS command execution if a local user opens a specially crafted link handled by the application.
other·tool misuse·
10 Sept 2026 · AWS
A missing S3 bucket ownership verification in the AWS Security Agent MCP server before version 0.2.0 allows remote attackers to obtain private source archives including credentials and infrastructure state via pre-registered storage buckets derived from publicly known account identifiers.
other·misconfiguration·
10 Sept 2026 · n8n
Five security vulnerabilities were disclosed in n8n affecting regular expression denial of service, domain-restriction bypass, approval-gate bypass, workflow disclosure, and prototype pollution. The vulnerabilities could allow authenticated users to freeze instances, bypass domain restrictions, bypass approval gates, disclose workflow information, or cause denial of service.
workflow·misconfiguration·
10 Sept 2026 · OmniRoute
OmniRoute versions 3.8.49 and earlier allowed remote code execution through the POST /api/acp/agents endpoint by passing attacker-controlled binary and versionCommand values that bypassed security filters. An unauthenticated attacker could execute arbitrary code on the server when requireLogin was false or during bootstrap.
other·excessive permissions·
10 Sept 2026 · n8n
The Elasticsearch and ElasticSecurity nodes in n8n allowed path injection attacks through unencoded identifiers, enabling attackers to access unintended endpoints or documents using stored Elasticsearch credentials. The vulnerability was patched in versions 1.123.76, 2.37.7, and 2.38.2.
workflow·tool misuse·
9 Sept 2026 · functype-mcp-server
The set_functype_version MCP tool in functype-mcp-server accepts an unconstrained version string, allowing attackers to inject arbitrary package aliases and execute remote code through dynamic import of attacker-controlled packages.
workflow·prompt injection·
9 Sept 2026 · Open WebUI
Three vulnerabilities in Open WebUI allow authenticated users to hang the server via cyclic chat structures and channel members to overwrite other users' messages. Versions 0.5.0-0.11.0 are affected; fixes are available in 0.11.1.
other·misconfiguration·
8 Sept 2026 · OpenAI
Check Point Research disclosed that ChatGPT's internal JFrog Artifactory instance exposed a hidden channel letting one account plant instructions that a victim's ChatGPT session would silently execute, reading data from the victim's connected Gmail account and returning it to the attacker's account. The proof-of-concept was disclosed to OpenAI in late June 2026, by which time the Artifactory instance had already been decommissioned, closing the channel.
other·prompt injection·
8 Sept 2026 · Microsoft
Two vulnerabilities in GitHub Copilot and Visual Studio Code allow attackers to disclose information over a network through command injection and insufficiently protected credentials.
coding·prompt injection·
8 Sept 2026 · Roo-Code
Roo-Code through version 3.54.0 contains multiple auto-approve bypass vulnerabilities in shell command parsing that allow attackers to execute denied shell commands by exploiting parser logic flaws. Attackers can craft malicious command lines that pass the approval gate but execute denied commands with the agent's auto-execute privileges on developer machines.
coding·excessive permissions·
8 Sept 2026 · Okta
Two vulnerabilities were discovered in the Okta Hyperdrive agent plugin: one returns unverified authentication responses without signed SAML assertions when MFA is not required, and another writes decoded SAML bearer assertions to local log files, exposing authentication credentials to local users.
other·misconfiguration·
8 Sept 2026 · ASUS
Missing authentication for a critical function in ASUS Control Center Express Agent allows an unauthenticated nearby user to control the host via direct connection when an active login session exists.
other·misconfiguration·
7 Sept 2026 · knowns-dev
Multiple path traversal vulnerabilities in knowns before version 0.30.0 and through 0.33.0 allow attackers to read, create, overwrite and delete files outside the project directory via MCP tool arguments. AI agent sessions can bypass permission checks and access arbitrary files on the host system.
coding·tool misuse·
7 Sept 2026 · Eclipse Ankaios
Eclipse Ankaios versions v0.5.1 through v1.0.1 have an authorization bypass vulnerability where multi-segment allow rules with leading wildcards incorrectly authorize empty field masks, allowing authenticated workloads to access or modify restricted cluster state.
other·misconfiguration·
5 Sept 2026 · AVideo
AVideo API fails to enforce rate limits when clients send a bot User-Agent header, allowing attackers to bypass protected operations including login brute-force protection and perform unlimited password guessing attempts.
other·misconfiguration·
5 Sept 2026 · Rowboat Labs
Rowboat through version 0.9.1 fails to validate custom MCP server and webhook URLs, allowing authenticated users to configure arbitrary destinations and perform server-side request forgery attacks against internal services and cloud metadata endpoints.
workflow·misconfiguration·
4 Sept 2026 · AgentScope
AgentScope through version 2.0.7.post1 contains a path traversal vulnerability in LocalWorkspace.add_skill that allows attackers to copy arbitrary server directories into the agent workspace via an unconfined source path parameter.
workflow·excessive permissions·
4 Sept 2026 · aider-chat
Aider automatically loads and executes commands from a .aider.conf.yml configuration file in git repositories without user confirmation, allowing arbitrary code execution when users clone and run aider in attacker-controlled repositories.
coding·misconfiguration·
4 Sept 2026 · OWL
OWL's DocumentProcessingToolkit contains a server-side request forgery vulnerability in the extract_document_content tool that allows attackers to inject malicious URLs through prompt injection to fetch internal resources.
other·prompt injection·
4 Sept 2026 · LaVague
LaVague 0.2.35 contains a remote code execution vulnerability in PythonFromMarkdownExtractor.extract_as_object that evaluates untrusted language model output derived from web page content. Attackers can inject malicious Python code through web pages using indirect prompt injection to execute arbitrary code.
coding·prompt injection·
4 Sept 2026 · CodeWhale
A time-of-check-time-of-use (TOCTOU) vulnerability in CodeWhale's DNS pinning implementation allows attackers to bypass SSRF mitigations by controlling a custom DNS server to fail initial requests and succeed on secondary requests.
browsing·tool misuse·
4 Sept 2026 · OGX
OGX (formerly Llama Stack) contains an unauthenticated SSRF vulnerability in the /v1/responses endpoint where MCP tool definitions accept a server_url parameter that is fetched server-side without destination validation, allowing remote attackers to access arbitrary internal addresses including cloud metadata endpoints.
other·excessive permissions·
4 Sept 2026 · IBM
IBM ContextForge MCP Gateway and Langflow OSS 1.0.0-1.11.2 contain multiple vulnerabilities including server-side request forgery, authentication bypass, arbitrary file writes, path traversal, stored XSS, and remote code execution affecting authenticated attackers.
other·excessive permissions·
4 Sept 2026 · LobeHub
LobeChat 2.2.1 fails to properly verify webhook signatures in QQ and Feishu adapters, allowing unauthenticated attackers to forge inbound messages and manipulate bot behavior by sending crafted requests to the unauthenticated webhook endpoint.
workflow·misconfiguration·
4 Sept 2026 · Postgres MCP Pro
Postgres MCP Pro 0.3.0 contains a restricted-mode bypass vulnerability where function-name validation is not applied to RangeFunction nodes in FROM clauses, allowing attackers to execute file-reading functions and read arbitrary files.
coding·misconfiguration·
4 Sept 2026 · firecrawl
firecrawl-mcp-server 3.20.2 contains an arbitrary local file read vulnerability in the firecrawl_parse tool that accepts unconstrained filePath arguments without directory containment validation. Attackers can read sensitive files like credentials and environment variables.
coding·excessive permissions·
4 Sept 2026 · excel-mcp-server
excel-mcp-server 0.1.8 fails to enforce path confinement when EXCEL_FILES_PATH is unset, allowing attackers to read and write arbitrary files accessible to the process through unchecked file paths in tools.
other·misconfiguration·
4 Sept 2026 · git-mcp-server
git-mcp-server 2.15.1 contains an argument injection vulnerability in git_log, git_diff, and git_show tools that allows attackers to inject git command-line options and write files to arbitrary paths.
coding·prompt injection·
4 Sept 2026 · xiaobei
xiaobei through version 5.5.2 fails to validate webhook authentication, allowing unauthenticated attackers to inject malicious messages into the agent pipeline and exploit unvalidated media URL fetching to perform server-side request forgery attacks.
workflow·misconfiguration·
4 Sept 2026 · LLaMA-Factory
LLaMA-Factory contains a server-side request forgery vulnerability in its OpenAI-compatible API multimodal media URL handler. Unauthenticated attackers can bypass SSRF validation using HTTP redirects or DNS rebinding to access internal addresses and cloud metadata endpoints.
coding·misconfiguration·
4 Sept 2026 · Xinference
Xinference v3.x contains an unauthenticated arbitrary-path file read vulnerability in the POST /v1/models/llm/auto-register endpoint that allows attackers to extract file contents from the server filesystem without authentication.
other·excessive permissions·
4 Sept 2026 · ms-swift
ms-swift 4.5.2 contains a server-side request forgery vulnerability in its OpenAI-compatible API that fetches multimodal media URLs without proper validation. Unauthenticated attackers can supply arbitrary image_url, audio_url, or video_url parameters to make the server access internal services and cloud metadata endpoints.
coding·tool misuse·
4 Sept 2026 · CodeWhale
Multiple critical vulnerabilities were discovered in CodeWhale affecting versions 0.8.37 through 0.8.63, including symlink-following leading to file leaks, auto-approved shell interaction enabling privilege escalation, argument injection in git_show allowing unauthorized file writes, environment variable leakage in JavaScript execution, and auto-approved arbitrary Python execution. All vulnerabilities were fixed in version 0.8.64.
coding·excessive permissions·
4 Sept 2026 · Amazon
Three vulnerabilities discovered in Amazon awslabs MCP server products: template injection in dynamodb-mcp-server, SQL injection in postgres-mcp-server, and OS command injection via COPY TO PROGRAM statement. Additionally, a supply chain issue in Kiro IDE allows remote actors to redirect registry requests and exfiltrate workspace data.
workflow·prompt injection·
4 Sept 2026 · cli-mcp-server
cli-mcp-server 0.2.5 contains a command allowlist bypass vulnerability in the _validate_command_with_operators function when ALLOW_SHELL_OPERATORS is enabled. Attackers can use shell command substitution syntax to execute non-allowlisted commands.
coding·misconfiguration·
3 Sept 2026 · Helicone
Helicone's VaultManager.getDecryptedProviderKeyById() function fails to validate organization membership, allowing attackers with admin privileges to retrieve decrypted provider API keys for other organizations. This could expose plaintext credentials for OpenAI, Anthropic, and Bedrock.
other·misconfiguration·
3 Sept 2026 · simular-ai
Three vulnerabilities were identified in simular-ai Agent-S up to version 0.3.2, affecting the OCR HTTP API, CodeAgent, and Model-generated GUI Action Execution Workflow components. All vulnerabilities enable remote denial of service or resource consumption attacks, with publicly disclosed exploits available.
other·tool misuse·
3 Sept 2026 · Langgenius
A cross-site scripting vulnerability exists in Langgenius Dify 1.13.0 in the Splash Layout component where the redirect_url parameter is not properly sanitized, allowing remote attackers to execute arbitrary JavaScript code.
other·prompt injection·
3 Sept 2026 · Cheshire Cat AI
Cheshire Cat AI's GET /memory/collections/{collection_id}/points endpoint fails to apply per-user filtering, allowing authenticated attackers with MEMORY:READ permission to retrieve all users' conversation messages and personal data through pagination.
other·excessive permissions·
3 Sept 2026 · Cascadia Web Services
A missing authorization vulnerability in MountDev AI MCP Connector for WordPress (versions up to 1.6.5) allows exploitation through incorrectly configured access control security levels.
other·excessive permissions·
3 Sept 2026 · aborruso
The CKAN MCP Server (@aborruso/ckan-mcp-server) reflects raw upstream response bodies and internal exception messages to callers instead of sanitized messages, disclosing sensitive information like hostnames, internal IPs, and database errors. This vulnerability amplifies SSRF attacks by providing a response-content channel to internal endpoints.
other·data leak·
3 Sept 2026 · 2FastLabs
A resource consumption vulnerability was discovered in 2FastLabs agent-squad up to version 1.1.4 in the streaming agent response workflow component. The vulnerability is remotely exploitable with public exploit code available.
workflow·tool misuse·
3 Sept 2026 · Orval
Three remote code execution vulnerabilities were discovered in Orval's OpenAPI schema generation affecting zod schemas, server URLs, and API paths. These vulnerabilities allow attackers to inject arbitrary code that executes during import or function calls.
coding·prompt injection·
3 Sept 2026 · n8n
Six vulnerabilities were disclosed in n8n affecting versions before 2.35.4 and 2.36.x before 2.36.2, including credential exfiltration, sandbox escapes, query injection, and remote code execution in multiple nodes.
workflow·tool misuse·
3 Sept 2026 · Agentimus
A subscriber broken access control vulnerability was discovered in Agentimus – AI SEO, llms.txt & MCP for AI Agents plugin versions 1.51.0 and earlier. This vulnerability could allow unauthorized access to restricted functionality.
other·excessive permissions·