Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Incident database

Structured records of AI agent security incidents: what happened, which vendor and agent type, the root cause, and every source we used. Filter, browse, or download as CSV.

Incidents by month, 2026 · 434 total · click a month to filter
Jan 2026: 23 incidents23JanFeb 2026: 26 incidents26FebMar 2026: 46 incidents46MarApr 2026: 46 incidents46AprMay 2026: 52 incidents52MayJun 2026: 51 incidents51JunJul 2026: 45 incidents45JulAug 2026: 82 incidents82AugSep 2026: 63 incidents63SepOct 2026: 0 incidents0OctNov 2026: 0 incidents0NovDec 2026: 0 incidents0Dec
Clear

63 incidents match

12 Sept 2026 · MCPHub

MCPHub OAuth 2.0 authentication bypass vulnerability

MCPHub before version 1.0.32 contains an authentication bypass vulnerability in its embedded OAuth 2.0 authorization server where client authentication is disabled by default and PKCE enforcement is optional, allowing attackers to redeem intercepted authorization codes for access tokens without proper credentials.

other·misconfiguration·

11 Sept 2026 · FrontMCP

CVE-2026-59973: SSRF fix bypass in FrontMCP and mcp-from-openapi OpenAPI $ref handling

A GitHub advisory reports that the patch for an earlier SSRF issue (CVE-2026-39885) in mcp-from-openapi 2.3.0 can be bypassed, letting untrusted OpenAPI specs loaded by FrontMCP 1.2.1 trigger backend-origin requests to loopback or private services via DNS-to-loopback names, redirects, and IPv4-mapped IPv6 forms. In hosted or multi-user FrontMCP deployments where users can import specs, this can expose internal APIs not reachable externally.

other·supply chain·

11 Sept 2026 · Anthropic

Threat actors abused Anthropic's Claude to extract secrets from 1.8M Android apps

Anthropic reported that multiple threat groups, including financially motivated actors and state-linked espionage groups associated with Russia and China, attempted to abuse its Claude AI model for malicious purposes, including extracting secrets from 1.8 million Android apps. Separate reporting describes attackers abusing trusted AI platforms, such as weaponized Claude Artifacts and shared AI conversations, to host malicious content and lure users into installing malware.

other·tool misuse·

11 Sept 2026 · mysql-mcp-server

MySQL MCP Server SSE transport allows unauthenticated SQL execution (CVE-2026-59971)

The mysql-mcp-server MCP package, when run in SSE/HTTP transport mode, created its SSE transport without security settings, disabling DNS-rebinding protection and leaving all routes unauthenticated while binding to 0.0.0.0. This allowed network attackers or malicious web pages to invoke execute_sql for arbitrary unauthenticated SQL execution, data exfiltration, and potentially file read/write and RCE; 25 publicly reachable instances were found.

workflow·misconfiguration·

11 Sept 2026 · IBM

Multiple vulnerabilities in IBM Langflow OSS 1.0.0-1.11.5

IBM Langflow OSS versions 1.0.0 through 1.11.5 contain multiple vulnerabilities allowing remote authenticated attackers to execute arbitrary Python code, OS commands, and access sensitive information due to improper authorization, insufficient session expiration, and pathname restrictions.

workflow·excessive permissions·

10 Sept 2026 · Lenovo

Command injection in Tianxi AI Agent PC Application

A command injection vulnerability in Tianxi AI Agent PC Application could allow OS command execution if a local user opens a specially crafted link handled by the application.

other·tool misuse·

10 Sept 2026 · AWS

AWS Security Agent MCP Server S3 Bucket Ownership Verification Missing

A missing S3 bucket ownership verification in the AWS Security Agent MCP server before version 0.2.0 allows remote attackers to obtain private source archives including credentials and infrastructure state via pre-registered storage buckets derived from publicly known account identifiers.

other·misconfiguration·

10 Sept 2026 · n8n

n8n Multiple Vulnerabilities in Workflow Execution and Access Control

Five security vulnerabilities were disclosed in n8n affecting regular expression denial of service, domain-restriction bypass, approval-gate bypass, workflow disclosure, and prototype pollution. The vulnerabilities could allow authenticated users to freeze instances, bypass domain restrictions, bypass approval gates, disclose workflow information, or cause denial of service.

workflow·misconfiguration·

10 Sept 2026 · OmniRoute

OmniRoute RCE via unauthenticated POST /api/acp/agents endpoint

OmniRoute versions 3.8.49 and earlier allowed remote code execution through the POST /api/acp/agents endpoint by passing attacker-controlled binary and versionCommand values that bypassed security filters. An unauthenticated attacker could execute arbitrary code on the server when requireLogin was false or during bootstrap.

other·excessive permissions·

10 Sept 2026 · n8n

Path Injection in n8n Elasticsearch and ElasticSecurity Nodes

The Elasticsearch and ElasticSecurity nodes in n8n allowed path injection attacks through unencoded identifiers, enabling attackers to access unintended endpoints or documents using stored Elasticsearch credentials. The vulnerability was patched in versions 1.123.76, 2.37.7, and 2.38.2.

workflow·tool misuse·

9 Sept 2026 · functype-mcp-server

functype-mcp-server RCE via unsanitized pnpm install

The set_functype_version MCP tool in functype-mcp-server accepts an unconstrained version string, allowing attackers to inject arbitrary package aliases and execute remote code through dynamic import of attacker-controlled packages.

workflow·prompt injection·

9 Sept 2026 · Open WebUI

Open WebUI vulnerabilities allow DoS and message tampering

Three vulnerabilities in Open WebUI allow authenticated users to hang the server via cyclic chat structures and channel members to overwrite other users' messages. Versions 0.5.0-0.11.0 are affected; fixes are available in 0.11.1.

other·misconfiguration·

8 Sept 2026 · OpenAI

Covert channel in ChatGPT's internal Artifactory enabled cross-account Gmail data theft

Check Point Research disclosed that ChatGPT's internal JFrog Artifactory instance exposed a hidden channel letting one account plant instructions that a victim's ChatGPT session would silently execute, reading data from the victim's connected Gmail account and returning it to the attacker's account. The proof-of-concept was disclosed to OpenAI in late June 2026, by which time the Artifactory instance had already been decommissioned, closing the channel.

other·prompt injection·

8 Sept 2026 · Roo-Code

Roo-Code auto-approve bypass vulnerabilities in shell command parsing

Roo-Code through version 3.54.0 contains multiple auto-approve bypass vulnerabilities in shell command parsing that allow attackers to execute denied shell commands by exploiting parser logic flaws. Attackers can craft malicious command lines that pass the approval gate but execute denied commands with the agent's auto-execute privileges on developer machines.

coding·excessive permissions·

8 Sept 2026 · Okta

Okta Hyperdrive agent plugin authentication and logging vulnerabilities

Two vulnerabilities were discovered in the Okta Hyperdrive agent plugin: one returns unverified authentication responses without signed SAML assertions when MFA is not required, and another writes decoded SAML bearer assertions to local log files, exposing authentication credentials to local users.

other·misconfiguration·

7 Sept 2026 · knowns-dev

knowns path traversal vulnerabilities in MCP tool arguments

Multiple path traversal vulnerabilities in knowns before version 0.30.0 and through 0.33.0 allow attackers to read, create, overwrite and delete files outside the project directory via MCP tool arguments. AI agent sessions can bypass permission checks and access arbitrary files on the host system.

coding·tool misuse·

7 Sept 2026 · Eclipse Ankaios

Eclipse Ankaios wildcard authorization bypass in Control Interface

Eclipse Ankaios versions v0.5.1 through v1.0.1 have an authorization bypass vulnerability where multi-segment allow rules with leading wildcards incorrectly authorize empty field masks, allowing authenticated workloads to access or modify restricted cluster state.

other·misconfiguration·

5 Sept 2026 · AVideo

AVideo API rate limit bypass via bot User-Agent header

AVideo API fails to enforce rate limits when clients send a bot User-Agent header, allowing attackers to bypass protected operations including login brute-force protection and perform unlimited password guessing attempts.

other·misconfiguration·

5 Sept 2026 · Rowboat Labs

Rowboat fails to validate custom MCP server and webhook URLs

Rowboat through version 0.9.1 fails to validate custom MCP server and webhook URLs, allowing authenticated users to configure arbitrary destinations and perform server-side request forgery attacks against internal services and cloud metadata endpoints.

workflow·misconfiguration·

4 Sept 2026 · AgentScope

AgentScope path traversal vulnerability in LocalWorkspace.add_skill

AgentScope through version 2.0.7.post1 contains a path traversal vulnerability in LocalWorkspace.add_skill that allows attackers to copy arbitrary server directories into the agent workspace via an unconfined source path parameter.

workflow·excessive permissions·

4 Sept 2026 · aider-chat

Aider arbitrary code execution via malicious .aider.conf.yml

Aider automatically loads and executes commands from a .aider.conf.yml configuration file in git repositories without user confirmation, allowing arbitrary code execution when users clone and run aider in attacker-controlled repositories.

coding·misconfiguration·

4 Sept 2026 · OWL

SSRF vulnerability in OWL DocumentProcessingToolkit

OWL's DocumentProcessingToolkit contains a server-side request forgery vulnerability in the extract_document_content tool that allows attackers to inject malicious URLs through prompt injection to fetch internal resources.

other·prompt injection·

4 Sept 2026 · LaVague

LaVague 0.2.35 Remote Code Execution via Prompt Injection

LaVague 0.2.35 contains a remote code execution vulnerability in PythonFromMarkdownExtractor.extract_as_object that evaluates untrusted language model output derived from web page content. Attackers can inject malicious Python code through web pages using indirect prompt injection to execute arbitrary code.

coding·prompt injection·

4 Sept 2026 · CodeWhale

CodeWhale SSRF bypass via DNS pinning TOCTOU

A time-of-check-time-of-use (TOCTOU) vulnerability in CodeWhale's DNS pinning implementation allows attackers to bypass SSRF mitigations by controlling a custom DNS server to fail initial requests and succeed on secondary requests.

browsing·tool misuse·

4 Sept 2026 · OGX

OGX Unauthenticated Server-Side Request Forgery via MCP Tool

OGX (formerly Llama Stack) contains an unauthenticated SSRF vulnerability in the /v1/responses endpoint where MCP tool definitions accept a server_url parameter that is fetched server-side without destination validation, allowing remote attackers to access arbitrary internal addresses including cloud metadata endpoints.

other·excessive permissions·

4 Sept 2026 · IBM

Multiple vulnerabilities in IBM ContextForge and Langflow OSS

IBM ContextForge MCP Gateway and Langflow OSS 1.0.0-1.11.2 contain multiple vulnerabilities including server-side request forgery, authentication bypass, arbitrary file writes, path traversal, stored XSS, and remote code execution affecting authenticated attackers.

other·excessive permissions·

4 Sept 2026 · LobeHub

LobeChat webhook signature verification bypass in QQ and Feishu adapters

LobeChat 2.2.1 fails to properly verify webhook signatures in QQ and Feishu adapters, allowing unauthenticated attackers to forge inbound messages and manipulate bot behavior by sending crafted requests to the unauthenticated webhook endpoint.

workflow·misconfiguration·

4 Sept 2026 · Postgres MCP Pro

Postgres MCP Pro 0.3.0 restricted-mode bypass via RangeFunction

Postgres MCP Pro 0.3.0 contains a restricted-mode bypass vulnerability where function-name validation is not applied to RangeFunction nodes in FROM clauses, allowing attackers to execute file-reading functions and read arbitrary files.

coding·misconfiguration·

4 Sept 2026 · firecrawl

Arbitrary local file read in firecrawl-mcp-server 3.20.2

firecrawl-mcp-server 3.20.2 contains an arbitrary local file read vulnerability in the firecrawl_parse tool that accepts unconstrained filePath arguments without directory containment validation. Attackers can read sensitive files like credentials and environment variables.

coding·excessive permissions·

4 Sept 2026 · excel-mcp-server

excel-mcp-server path confinement bypass in stdio mode

excel-mcp-server 0.1.8 fails to enforce path confinement when EXCEL_FILES_PATH is unset, allowing attackers to read and write arbitrary files accessible to the process through unchecked file paths in tools.

other·misconfiguration·

4 Sept 2026 · git-mcp-server

git-mcp-server argument injection in git tools

git-mcp-server 2.15.1 contains an argument injection vulnerability in git_log, git_diff, and git_show tools that allows attackers to inject git command-line options and write files to arbitrary paths.

coding·prompt injection·

4 Sept 2026 · xiaobei

xiaobei webhook endpoint lacks authentication, allows SSRF attacks

xiaobei through version 5.5.2 fails to validate webhook authentication, allowing unauthenticated attackers to inject malicious messages into the agent pipeline and exploit unvalidated media URL fetching to perform server-side request forgery attacks.

workflow·misconfiguration·

4 Sept 2026 · LLaMA-Factory

LLaMA-Factory SSRF vulnerability in OpenAI API handler

LLaMA-Factory contains a server-side request forgery vulnerability in its OpenAI-compatible API multimodal media URL handler. Unauthenticated attackers can bypass SSRF validation using HTTP redirects or DNS rebinding to access internal addresses and cloud metadata endpoints.

coding·misconfiguration·

4 Sept 2026 · Xinference

Xinference unauthenticated arbitrary-path file read vulnerability

Xinference v3.x contains an unauthenticated arbitrary-path file read vulnerability in the POST /v1/models/llm/auto-register endpoint that allows attackers to extract file contents from the server filesystem without authentication.

other·excessive permissions·

4 Sept 2026 · ms-swift

ms-swift 4.5.2 SSRF via unvalidated media URLs

ms-swift 4.5.2 contains a server-side request forgery vulnerability in its OpenAI-compatible API that fetches multimodal media URLs without proper validation. Unauthenticated attackers can supply arbitrary image_url, audio_url, or video_url parameters to make the server access internal services and cloud metadata endpoints.

coding·tool misuse·

4 Sept 2026 · CodeWhale

CodeWhale Multiple Critical Vulnerabilities in v0.8.37-0.8.63

Multiple critical vulnerabilities were discovered in CodeWhale affecting versions 0.8.37 through 0.8.63, including symlink-following leading to file leaks, auto-approved shell interaction enabling privilege escalation, argument injection in git_show allowing unauthorized file writes, environment variable leakage in JavaScript execution, and auto-approved arbitrary Python execution. All vulnerabilities were fixed in version 0.8.64.

coding·excessive permissions·

4 Sept 2026 · Amazon

Multiple vulnerabilities in Amazon AWS Labs MCP servers

Three vulnerabilities discovered in Amazon awslabs MCP server products: template injection in dynamodb-mcp-server, SQL injection in postgres-mcp-server, and OS command injection via COPY TO PROGRAM statement. Additionally, a supply chain issue in Kiro IDE allows remote actors to redirect registry requests and exfiltrate workspace data.

workflow·prompt injection·

4 Sept 2026 · cli-mcp-server

cli-mcp-server command allowlist bypass via shell operators

cli-mcp-server 0.2.5 contains a command allowlist bypass vulnerability in the _validate_command_with_operators function when ALLOW_SHELL_OPERATORS is enabled. Attackers can use shell command substitution syntax to execute non-allowlisted commands.

coding·misconfiguration·

3 Sept 2026 · Helicone

Helicone vault key exposure via inadequate org validation

Helicone's VaultManager.getDecryptedProviderKeyById() function fails to validate organization membership, allowing attackers with admin privileges to retrieve decrypted provider API keys for other organizations. This could expose plaintext credentials for OpenAI, Anthropic, and Bedrock.

other·misconfiguration·

3 Sept 2026 · simular-ai

Multiple vulnerabilities in simular-ai Agent-S

Three vulnerabilities were identified in simular-ai Agent-S up to version 0.3.2, affecting the OCR HTTP API, CodeAgent, and Model-generated GUI Action Execution Workflow components. All vulnerabilities enable remote denial of service or resource consumption attacks, with publicly disclosed exploits available.

other·tool misuse·

3 Sept 2026 · Langgenius

Langgenius Dify XSS via redirect_url parameter in Splash Layout

A cross-site scripting vulnerability exists in Langgenius Dify 1.13.0 in the Splash Layout component where the redirect_url parameter is not properly sanitized, allowing remote attackers to execute arbitrary JavaScript code.

other·prompt injection·

3 Sept 2026 · Cheshire Cat AI

Cheshire Cat AI memory endpoint lacks per-user filtering

Cheshire Cat AI's GET /memory/collections/{collection_id}/points endpoint fails to apply per-user filtering, allowing authenticated attackers with MEMORY:READ permission to retrieve all users' conversation messages and personal data through pagination.

other·excessive permissions·

3 Sept 2026 · aborruso

CKAN MCP Server: Information disclosure via verbose error reflection

The CKAN MCP Server (@aborruso/ckan-mcp-server) reflects raw upstream response bodies and internal exception messages to callers instead of sanitized messages, disclosing sensitive information like hostnames, internal IPs, and database errors. This vulnerability amplifies SSRF attacks by providing a response-content channel to internal endpoints.

other·data leak·

3 Sept 2026 · 2FastLabs

agent-squad Resource Exhaustion Vulnerability in Streaming

A resource consumption vulnerability was discovered in 2FastLabs agent-squad up to version 1.1.4 in the streaming agent response workflow component. The vulnerability is remotely exploitable with public exploit code available.

workflow·tool misuse·

3 Sept 2026 · Orval

Orval: Multiple RCE vulnerabilities in code generation

Three remote code execution vulnerabilities were discovered in Orval's OpenAPI schema generation affecting zod schemas, server URLs, and API paths. These vulnerabilities allow attackers to inject arbitrary code that executes during import or function calls.

coding·prompt injection·

3 Sept 2026 · n8n

Multiple vulnerabilities in n8n workflow automation platform

Six vulnerabilities were disclosed in n8n affecting versions before 2.35.4 and 2.36.x before 2.36.2, including credential exfiltration, sandbox escapes, query injection, and remote code execution in multiple nodes.

workflow·tool misuse·

3 Sept 2026 · Agentimus

Broken Access Control in Agentimus AI SEO Plugin

A subscriber broken access control vulnerability was discovered in Agentimus – AI SEO, llms.txt & MCP for AI Agents plugin versions 1.51.0 and earlier. This vulnerability could allow unauthorized access to restricted functionality.

other·excessive permissions·