Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Incident database

Structured records of AI agent security incidents: what happened, which vendor and agent type, the root cause, and every source we used. Filter, browse, or download as CSV.

Incidents by month, 2026 · 434 total · click a month to filter
Jan 2026: 23 incidents23JanFeb 2026: 26 incidents26FebMar 2026: 46 incidents46MarApr 2026: 46 incidents46AprMay 2026: 52 incidents52MayJun 2026: 51 incidents51JunJul 2026: 45 incidents45JulAug 2026: 82 incidents82AugSep 2026: 63 incidents63SepOct 2026: 0 incidents0OctNov 2026: 0 incidents0NovDec 2026: 0 incidents0Dec

Highlighted: incidents recorded on 13 September 2026, shown in place among all incidents.Clear

453 incidents

Incident dateIncidentVendorAgentRoot causeSeverityStatus
12 Sept 2026MCPHub OAuth 2.0 authentication bypass vulnerabilityMCPHubothermisconfigurationconfirmed
11 Sept 2026Multiple vulnerabilities in IBM Langflow OSS 1.0.0-1.11.5IBMworkflowexcessive permissionsreported
11 Sept 2026MySQL MCP Server SSE transport allows unauthenticated SQL execution (CVE-2026-59971)mysql-mcp-serverworkflowmisconfigurationresolved
11 Sept 2026CVE-2026-59973: SSRF fix bypass in FrontMCP and mcp-from-openapi OpenAPI $ref handlingFrontMCPothersupply chainconfirmed
11 Sept 2026Threat actors abused Anthropic's Claude to extract secrets from 1.8M Android appsAnthropicothertool misuseconfirmed
10 Sept 2026n8n Multiple Vulnerabilities in Workflow Execution and Access Controln8nworkflowmisconfigurationconfirmed
10 Sept 2026AWS Security Agent MCP Server S3 Bucket Ownership Verification MissingAWSothermisconfigurationconfirmed
10 Sept 2026Command injection in Tianxi AI Agent PC ApplicationLenovoothertool misusereported
10 Sept 2026Path Injection in n8n Elasticsearch and ElasticSecurity Nodesn8nworkflowtool misuseresolved
10 Sept 2026OmniRoute RCE via unauthenticated POST /api/acp/agents endpointOmniRouteotherexcessive permissionsreported
9 Sept 2026functype-mcp-server RCE via unsanitized pnpm installfunctype-mcp-serverworkflowprompt injectionconfirmed
9 Sept 2026Open WebUI vulnerabilities allow DoS and message tamperingOpen WebUIothermisconfigurationresolved
8 Sept 2026Roo-Code auto-approve bypass vulnerabilities in shell command parsingRoo-Codecodingexcessive permissionsreported
8 Sept 2026Covert channel in ChatGPT's internal Artifactory enabled cross-account Gmail data theftOpenAIotherprompt injectionresolved
8 Sept 2026ASUS Control Center Express Agent missing authentication vulnerabilityASUSothermisconfigurationreported
8 Sept 2026Command injection and credential exposure in GitHub Copilot and Visual Studio CodeMicrosoftcodingprompt injectionconfirmed
8 Sept 2026Okta Hyperdrive agent plugin authentication and logging vulnerabilitiesOktaothermisconfigurationreported
7 Sept 2026knowns path traversal vulnerabilities in MCP tool argumentsknowns-devcodingtool misusereported
7 Sept 2026Eclipse Ankaios wildcard authorization bypass in Control InterfaceEclipse Ankaiosothermisconfigurationreported
5 Sept 2026Rowboat fails to validate custom MCP server and webhook URLsRowboat Labsworkflowmisconfigurationreported
5 Sept 2026AVideo API rate limit bypass via bot User-Agent headerAVideoothermisconfigurationreported
4 Sept 2026Postgres MCP Pro 0.3.0 restricted-mode bypass via RangeFunctionPostgres MCP Procodingmisconfigurationreported
4 Sept 2026CodeWhale Multiple Critical Vulnerabilities in v0.8.37-0.8.63CodeWhalecodingexcessive permissionsconfirmed
4 Sept 2026Aider arbitrary code execution via malicious .aider.conf.ymlaider-chatcodingmisconfigurationreported
4 Sept 2026Multiple vulnerabilities in IBM ContextForge and Langflow OSSIBMotherexcessive permissionsreported
4 Sept 2026Arbitrary local file read in firecrawl-mcp-server 3.20.2firecrawlcodingexcessive permissionsreported
4 Sept 2026SSRF vulnerability in OWL DocumentProcessingToolkitOWLotherprompt injectionconfirmed
4 Sept 2026LLaMA-Factory SSRF vulnerability in OpenAI API handlerLLaMA-Factorycodingmisconfigurationreported
4 Sept 2026OGX Unauthenticated Server-Side Request Forgery via MCP ToolOGXotherexcessive permissionsreported
4 Sept 2026git-mcp-server argument injection in git toolsgit-mcp-servercodingprompt injectionreported
4 Sept 2026xiaobei webhook endpoint lacks authentication, allows SSRF attacksxiaobeiworkflowmisconfigurationreported
4 Sept 2026cli-mcp-server command allowlist bypass via shell operatorscli-mcp-servercodingmisconfigurationreported
4 Sept 2026LobeChat webhook signature verification bypass in QQ and Feishu adaptersLobeHubworkflowmisconfigurationreported
4 Sept 2026ms-swift 4.5.2 SSRF via unvalidated media URLsms-swiftcodingtool misusereported
4 Sept 2026Multiple vulnerabilities in Amazon AWS Labs MCP serversAmazonworkflowprompt injectionconfirmed
4 Sept 2026LaVague 0.2.35 Remote Code Execution via Prompt InjectionLaVaguecodingprompt injectionreported
4 Sept 2026CodeWhale SSRF bypass via DNS pinning TOCTOUCodeWhalebrowsingtool misuseconfirmed
4 Sept 2026excel-mcp-server path confinement bypass in stdio modeexcel-mcp-serverothermisconfigurationreported
4 Sept 2026AgentScope path traversal vulnerability in LocalWorkspace.add_skillAgentScopeworkflowexcessive permissionsreported
4 Sept 2026Xinference unauthenticated arbitrary-path file read vulnerabilityXinferenceotherexcessive permissionsreported
3 Sept 2026Cheshire Cat AI memory endpoint lacks per-user filteringCheshire Cat AIotherexcessive permissionsreported
3 Sept 2026Missing Authorization in MountDev AI MCP Connector for WordPressCascadia Web Servicesotherexcessive permissionsreported
3 Sept 2026Orval: Multiple RCE vulnerabilities in code generationOrvalcodingprompt injectionreported
3 Sept 2026KP Agent Ready sensitive data insertion vulnerabilityKevin Pirnieotherdata leakreported
3 Sept 2026Multiple vulnerabilities in simular-ai Agent-Ssimular-aiothertool misusereported
3 Sept 2026Broken Access Control in Agentimus AI SEO PluginAgentimusotherexcessive permissionsreported
3 Sept 2026CKAN MCP Server: Information disclosure via verbose error reflectionaborrusootherdata leakreported
3 Sept 2026Helicone vault key exposure via inadequate org validationHeliconeothermisconfigurationreported
3 Sept 2026Multiple vulnerabilities in n8n workflow automation platformn8nworkflowtool misuseconfirmed
3 Sept 2026SSRF vulnerability in unstructured library URL handlingunstructuredothermisconfigurationreported