Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Incident database

Structured records of AI agent security incidents: what happened, which vendor and agent type, the root cause, and every source we used. Filter, browse, or download as CSV.

Incidents by month, 2026 · 434 total · click a month to filter
Jan 2026: 23 incidents23JanFeb 2026: 26 incidents26FebMar 2026: 46 incidents46MarApr 2026: 46 incidents46AprMay 2026: 52 incidents52MayJun 2026: 51 incidents51JunJul 2026: 45 incidents45JulAug 2026: 82 incidents82AugSep 2026: 63 incidents63SepOct 2026: 0 incidents0OctNov 2026: 0 incidents0NovDec 2026: 0 incidents0Dec

453 incidents

3 Sept 2026 · Agentimus

Broken Access Control in Agentimus AI SEO Plugin

A subscriber broken access control vulnerability was discovered in Agentimus – AI SEO, llms.txt & MCP for AI Agents plugin versions 1.51.0 and earlier. This vulnerability could allow unauthorized access to restricted functionality.

other·excessive permissions·

3 Sept 2026 · simular-ai

Multiple vulnerabilities in simular-ai Agent-S

Three vulnerabilities were identified in simular-ai Agent-S up to version 0.3.2, affecting the OCR HTTP API, CodeAgent, and Model-generated GUI Action Execution Workflow components. All vulnerabilities enable remote denial of service or resource consumption attacks, with publicly disclosed exploits available.

other·tool misuse·

3 Sept 2026 · Cheshire Cat AI

Cheshire Cat AI memory endpoint lacks per-user filtering

Cheshire Cat AI's GET /memory/collections/{collection_id}/points endpoint fails to apply per-user filtering, allowing authenticated attackers with MEMORY:READ permission to retrieve all users' conversation messages and personal data through pagination.

other·excessive permissions·

2 Sept 2026 · aborruso

CKAN MCP Server: Multiple security vulnerabilities in allowlist and cache

Two critical vulnerabilities discovered in the CKAN MCP Server npm package: an unanchored regex bypass in the MQA server allowlist validation that enables SSRF and prompt injection attacks, and a cache-key canonicalization collision that allows cache poisoning to deliver spoofed responses to legitimate queries.

other·prompt injection·

2 Sept 2026 · Omnigent (Databricks)

Omnigent: Multiple Authenticated RCE and Policy Bypass Vulnerabilities

Four critical vulnerabilities in Omnigent allow authenticated users to execute arbitrary code on runner hosts through malicious agent bundle uploads, unvalidated working directories, and guardrail policy bypasses. These affect shared agent overwrites, Python callable tools, filesystem access controls, and shell command policy evaluation.

other·excessive permissions·

2 Sept 2026 · Anthropic

claude-skill-antivirus fails to analyze executable files in skill directories

claude-skill-antivirus only scans SKILL.md manifests while ignoring Python source code and other executable artifacts in skill directories, allowing attackers to distribute skills with malicious code that receive a SAFE verdict despite containing unanalyzed payloads.

coding·tool misuse·

2 Sept 2026 · ntegrals

ntegrals openbrowser Browser Agent Message Construction DoS

A vulnerability in ntegrals openbrowser's Browser Agent Message Construction component allows remote attackers to cause resource consumption through manipulation of the agent.ts file. The vendor did not respond to early disclosure.

browsing·tool misuse·

2 Sept 2026 · GitHub

SSRF vulnerability in GitHub Enterprise Server Management API

An unauthenticated server-side request forgery vulnerability in GitHub Enterprise Server allowed attackers to cause the Manage API to send crafted outbound requests. The vulnerability affected all versions prior to 3.22 and was fixed in versions 3.17.19, 3.18.13, 3.19.10, 3.20.6, and 3.21.4.

other·misconfiguration·

2 Sept 2026 · zhayujie

Multiple DoS vulnerabilities in zhayujie CowAgent

Two denial of service vulnerabilities were discovered in zhayujie CowAgent affecting the Bash Tool and Browser Tool components. Both vulnerabilities can be exploited remotely and have been publicly disclosed.

coding·tool misuse·

2 Sept 2026 · OpenChoreo

OpenChoreo unauthenticated cluster-gateway management API access

OpenChoreo's cluster-gateway served unauthenticated management APIs on the same listener accepting data-plane connections, allowing attackers reaching the external endpoint to perform privileged operations including Kubernetes API proxy and pod command execution without authentication.

other·misconfiguration·

1 Sept 2026 · runZero

Authorization bypass in runZero Platform MCP service

An authorization bypass vulnerability (CWE-639) was discovered in the runZero Platform MCP service, allowing users with low privileges to access resources they should not have access to. The issue has been resolved in version 5.1.260826.0.

other·excessive permissions·

1 Sept 2026 · Appium

appium-mcp-server Path Traversal in File Write Tools

appium-mcp-server through version 0.1.61 fails to validate file paths in write_file and write_files_batch tools, allowing attackers to write files outside the intended directory and potentially overwrite arbitrary files with server privileges.

other·misconfiguration·

1 Sept 2026 · NousResearch

Multiple vulnerabilities in NousResearch hermes-agent

Six vulnerabilities were discovered in NousResearch hermes-agent versions up to 0.18.2, including denial of service, authorization bypass, uncontrolled memory allocation, and server-side request forgery. The vendor did not respond to early disclosure attempts.

workflow·unknown·

31 Aug 2026 · ash-project

Origin validation error in ash_ai MCP server allows DNS rebinding attacks

A vulnerability in ash_ai's MCP server allows malicious web pages to bypass DNS-rebinding protection through improper origin validation, enabling cross-site requests to local MCP servers. The issue affects versions 0.8.0 before 1.0.0 and has been fixed by trusting only localhost origins by default.

other·misconfiguration·

31 Aug 2026 · sdcb

CVE-2026-82905: SSRF in sdcb chats McpController

A server-side request forgery vulnerability was discovered in sdcb chats up to version 1.12.0 in the McpController's fetch-tools endpoint. The exploit is public and the vendor did not respond to early disclosure attempts.

other·tool misuse·

28 Aug 2026 · SiYuan

SiYuan path traversal and path guard bypass vulnerabilities

Two path-based vulnerabilities in SiYuan before v3.8.2: a path traversal in asset.upload MCP tool allowing upload of sensitive files via prompt injection, and a case-sensitive path guard bypass enabling reading of protected configuration files.

other·prompt injection·

28 Aug 2026 · Microsoft

Multiple vulnerabilities in Microsoft Copilot products

Two vulnerabilities were disclosed in Microsoft's Copilot products: a race condition in Copilot Chat allowing information disclosure, and improper cryptographic signature verification in Copilot Studio allowing privilege escalation.

other·misconfiguration·

28 Aug 2026 · Hatchet

Hatchet Dispatcher gRPC Service Missing Tenant Verification

Hatchet versions 0.40.0 to 0.91.0 lack proper tenant verification in Dispatcher gRPC service, allowing authenticated users to manipulate other tenants' workers and cause denial of service on multi-tenant deployments. The vulnerability was fixed in version 0.91.1.

workflow·misconfiguration·

27 Aug 2026 · Timescale

DNS Rebinding Vulnerability in Timescale MCP Tools

Timescale's pg-aiguide and tiger-slack failed to enable DNS rebinding protection in their MCP HTTP transports, allowing attackers to drive locally reachable servers through a visitor's browser via DNS name control.

other·misconfiguration·

27 Aug 2026 · Agno

Agno Remote Code Execution via Prompt Injection

Agno up to version 2.5.8 is vulnerable to remote code execution through prompt injection in PythonTools and ShellTools components. An unauthenticated attacker can exploit unsanitized LLM-generated arguments to execute arbitrary code and OS commands.

coding·prompt injection·

27 Aug 2026 · Nightingale

Nightingale SSRF vulnerability in http_fetch AI-agent tool

Nightingale (n9e) contains a server-side request forgery vulnerability in the isPublicIP function that fails to properly unwrap certain IPv6 address formats, allowing attackers to bypass SSRF guards and reach internal services or metadata endpoints.

other·misconfiguration·

27 Aug 2026 · Telnyx

Telnyx MCP Server Missing Authentication on HTTP Transport

The Telnyx MCP server exposed its HTTP transport on all interfaces without requiring authentication, allowing unauthenticated access to dispatch tools and the server's stored credentials including API keys and code-execution keys.

coding·misconfiguration·

27 Aug 2026 · mcp-use

mcp-use Inspector Proxy SSRF via Unvalidated Target URL

The proxy middleware in mcp-use's inspector failed to validate the host of requests, allowing callers to make the server issue requests to private, loopback, and link-local addresses and read responses. This server-side request forgery vulnerability has been patched with proper host validation and redirect limiting.

other·misconfiguration·

27 Aug 2026 · mcp-router

mcp-router CLI exposed MCP aggregator without authentication by default

The mcp-router CLI served its MCP aggregator on all network interfaces without requiring authentication unless explicitly configured, exposing the aggregator and all fronted MCP servers to unauthorized network access. The vulnerability was fixed in version 0.6.3 by defaulting to loopback address and requiring authentication for non-loopback hosts.

other·misconfiguration·

27 Aug 2026 · GitLab

GitLab AI Gateway credential disclosure vulnerabilities

GitLab remediated two vulnerabilities in the AI Gateway component that could allow authenticated users with Duo Agent Platform access to redirect requests to external endpoints and disclose cloud service credentials and signing keys.

other·prompt injection·

27 Aug 2026 · Apify

CVE-2026-81093: Apify MCP Server SSRF in get-html-skeleton tool

The get-html-skeleton tool in Apify MCP Server validated URLs only for syntax, allowing callers to request internal endpoints including cloud metadata services. Version 0.9.12 removes the vulnerable tool.

browsing·excessive permissions·

27 Aug 2026 · Dropbox

Dash MCP server DNS rebinding via missing host header validation

The Dash MCP server bound its listener to loopback but failed to validate the Host header, allowing DNS rebinding attacks. A malicious webpage could invoke the server's tools using the visitor's Dropbox credentials.

other·misconfiguration·

27 Aug 2026 · ServiceNow

ServiceNow AI platform code injection and SQL injection vulnerabilities

ServiceNow remediated two vulnerabilities in its AI platform: a code injection flaw and a SQL injection flaw, both allowing unauthenticated users to execute arbitrary code or SQL statements and access or modify instance data. No malicious exploitation has been reported.

other·unknown·

27 Aug 2026 · mark3labs

mcp-go HTTP Host header validation vulnerability

mcp-go accepted HTTP requests without validating the Host header, allowing attackers to bypass loopback restrictions via DNS rebinding. The vulnerability was patched in version 0.56.0 by adding Host header validation.

other·misconfiguration·

26 Aug 2026 · Google

CVE-2026-75062: Eval Injection in Google langfun

An eval injection vulnerability in Google langfun's lf.query protocol allows remote attackers to execute arbitrary Python code via crafted prompt inputs. The vulnerability affects versions prior to 0.1.2.

coding·prompt injection·

25 Aug 2026 · Anthropic

MCP PHP SDK Memory Exhaustion Vulnerability

The MCP PHP SDK versions 0.5.0 through 0.7.0 are vulnerable to memory exhaustion when the HTTP client transport connects to a malicious or compromised server that streams data without sending SSE event delimiters, causing unbounded buffer growth and denial of service.

other·tool misuse·

25 Aug 2026 · Amazon

Prompt injection in Amazon Strands Agents Tools python_repl

Improper input neutralization in the python_repl tool of Amazon Strands Agents Tools before 0.8.5 allows remote attackers to execute arbitrary Python code by bypassing consent gates via crafted prompts.

coding·prompt injection·

25 Aug 2026 · Dradis

Dradis CE SSRF via unrestricted AI provider address

An authorization bypass in Dradis Community Edition allows authenticated non-admin users to create arbitrary AI providers and trigger server-side request forgery attacks. The SSRF vulnerability permits reading response bodies from internal hosts via reflected error messages.

coding·excessive permissions·

25 Aug 2026 · sonirico

mcp-shell Multiple Command Execution Vulnerabilities

Three vulnerabilities in mcp-shell prior to version 0.6.0 allow attackers to execute arbitrary OS commands through the shell_exec MCP tool due to insecure default configuration, insufficient command validation, and shell metacharacter bypass in Git alias handling.

coding·misconfiguration·

25 Aug 2026 · GeiserX

CVE-2026-55637: genieacs-mcp DNS rebinding vulnerability

genieacs-mcp versions prior to 0.3.2 create an unauthenticated HTTP listener on 127.0.0.1:8080 that does not validate Host or Origin headers, allowing DNS rebinding attacks to expose or modify CPE management state through GenieACS operations.

other·misconfiguration·

25 Aug 2026 · ruvnet

Path traversal in sublinear-time-solver and consciousness-explorer

Path traversal vulnerability in MCP tools allows attackers to read, write, or overwrite files accessible to the server process. The vulnerability affects sublinear-time-solver and consciousness-explorer through unsanitized filepath parameters in filesystem operations.

other·misconfiguration·

25 Aug 2026 · MervinPraison

CVE-2026-55529: PraisonAI Origin Validation Bypass

PraisonAI versions prior to 4.6.58 contain an origin validation bypass in the MCP HTTP Stream _validate_origin method that allows attackers to submit tool execution requests to local MCP servers without API key authentication through malicious webpages.

workflow·misconfiguration·

24 Aug 2026 · Continue

Continue CLI incomplete denylist allows destructive commands

The Continue CLI uses an incomplete denylist to block dangerous shell commands in unattended mode, allowing attackers to bypass protections through prompt injection and destroy user data via commands like rm -rf targeting /home, /root, /var, /opt or /srv directories.

workflow·prompt injection·

21 Aug 2026 · Spring

Spring AI MCP Streamable HTTP server memory exhaustion DoS

The MCP Streamable HTTP server transport in Spring AI 2.0.0 does not limit session accumulation, allowing remote attackers to cause memory exhaustion and denial of service without authentication.

other·misconfiguration·

20 Aug 2026 · Neo.mjs

Neo.mjs command injection in FileSystemService.mjs

Neo.mjs contains command injection vulnerabilities in the FileSystemService.mjs component where checkSyntax() and runPlaywrightTest() functions unsafely interpolate caller-controlled paths into shell commands, enabling arbitrary OS command execution when AI agents invoke these tools.

coding·tool misuse·

20 Aug 2026 · SiteGround

AI Agent by SiteGround WordPress plugin authorization bypass

The AI Agent by SiteGround WordPress plugin versions up to 1.2.7 are vulnerable to an authorization bypass that allows unauthenticated attackers to upload images to the media library by exploiting missing upload_files capability checks.

coding·excessive permissions·

20 Aug 2026 · LangChain

LangChain SitemapLoader SSRF bypass via nested sitemap entries

A vulnerability in LangChain Community's SitemapLoader allows attackers to bypass the restrict_to_same_domain control by pointing nested sitemap entries to internal addresses, enabling server-side request forgery and disclosure of internal responses.

other·excessive permissions·

20 Aug 2026 · LangBot

LangBot MCP Server RCE via Insufficient Authorization

LangBot versions 4.10.7 and earlier allow authenticated users to execute arbitrary commands on the server by configuring STDIO MCP servers without proper authorization checks. An attacker with an account can achieve remote code execution with service privileges.

coding·excessive permissions·

19 Aug 2026 · marimo-team

marimo Code Injection via MCP Server Configuration

marimo before 0.23.15 contains a code injection vulnerability in the notebook configuration handler that allows attackers to execute arbitrary commands by supplying a crafted MCP server entry. The vulnerability is triggered when a notebook is opened in edit mode without requiring authentication or cell execution.

coding·prompt injection·

19 Aug 2026 · Agno

Agno PythonTools path traversal vulnerability CVE-2026-76832

A path traversal vulnerability in Agno's PythonTools allows attackers to read, write, or execute arbitrary files by injecting directory traversal sequences through the file_name argument. The vulnerability can be exploited via direct tool invocation or prompt injection in agent-processed content.

coding·prompt injection·