| 3 Sept 2026 | Broken Access Control in Agentimus AI SEO Plugin | Agentimus | other | excessive permissions | | reported |
| 3 Sept 2026 | Multiple vulnerabilities in simular-ai Agent-S | simular-ai | other | tool misuse | | reported |
| 3 Sept 2026 | Cheshire Cat AI memory endpoint lacks per-user filtering | Cheshire Cat AI | other | excessive permissions | | reported |
| 2 Sept 2026 | CKAN MCP Server: Multiple security vulnerabilities in allowlist and cache | aborruso | other | prompt injection | | reported |
| 2 Sept 2026 | Omnigent: Multiple Authenticated RCE and Policy Bypass Vulnerabilities | Omnigent (Databricks) | other | excessive permissions | | reported |
| 2 Sept 2026 | claude-skill-antivirus fails to analyze executable files in skill directories | Anthropic | coding | tool misuse | | reported |
| 2 Sept 2026 | ntegrals openbrowser Browser Agent Message Construction DoS | ntegrals | browsing | tool misuse | | reported |
| 2 Sept 2026 | SSRF vulnerability in GitHub Enterprise Server Management API | GitHub | other | misconfiguration | | resolved |
| 2 Sept 2026 | Multiple DoS vulnerabilities in zhayujie CowAgent | zhayujie | coding | tool misuse | | reported |
| 2 Sept 2026 | OpenChoreo unauthenticated cluster-gateway management API access | OpenChoreo | other | misconfiguration | | confirmed |
| 1 Sept 2026 | Authorization bypass in runZero Platform MCP service | runZero | other | excessive permissions | | resolved |
| 1 Sept 2026 | appium-mcp-server Path Traversal in File Write Tools | Appium | other | misconfiguration | | reported |
| 1 Sept 2026 | Multiple vulnerabilities in NousResearch hermes-agent | NousResearch | workflow | unknown | | reported |
| 31 Aug 2026 | Origin validation error in ash_ai MCP server allows DNS rebinding attacks | ash-project | other | misconfiguration | | confirmed |
| 31 Aug 2026 | Meta Researcher's AI Agent Accidentally Deleted Her Emails | Meta | other | hallucinated action | | reported |
| 31 Aug 2026 | CVE-2026-82905: SSRF in sdcb chats McpController | sdcb | other | tool misuse | | reported |
| 28 Aug 2026 | SiYuan path traversal and path guard bypass vulnerabilities | SiYuan | other | prompt injection | | confirmed |
| 28 Aug 2026 | Multiple vulnerabilities in Microsoft Copilot products | Microsoft | other | misconfiguration | | reported |
| 28 Aug 2026 | Hatchet Dispatcher gRPC Service Missing Tenant Verification | Hatchet | workflow | misconfiguration | | resolved |
| 27 Aug 2026 | DNS Rebinding Vulnerability in Timescale MCP Tools | Timescale | other | misconfiguration | | confirmed |
| 27 Aug 2026 | Agno Remote Code Execution via Prompt Injection | Agno | coding | prompt injection | | reported |
| 27 Aug 2026 | Nightingale SSRF vulnerability in http_fetch AI-agent tool | Nightingale | other | misconfiguration | | confirmed |
| 27 Aug 2026 | Telnyx MCP Server Missing Authentication on HTTP Transport | Telnyx | coding | misconfiguration | | resolved |
| 27 Aug 2026 | mcp-use Inspector Proxy SSRF via Unvalidated Target URL | mcp-use | other | misconfiguration | | resolved |
| 27 Aug 2026 | mcp-router CLI exposed MCP aggregator without authentication by default | mcp-router | other | misconfiguration | | resolved |
| 27 Aug 2026 | CVE-2026-81096: ToolUniverse sandbox escape and unauthenticated RCE | ToolUniverse | coding | excessive permissions | | confirmed |
| 27 Aug 2026 | UI-TARS-desktop MCP servers bind to all interfaces without authentication | ByteDance | other | misconfiguration | | confirmed |
| 27 Aug 2026 | GitLab AI Gateway credential disclosure vulnerabilities | GitLab | other | prompt injection | | resolved |
| 27 Aug 2026 | CVE-2026-81093: Apify MCP Server SSRF in get-html-skeleton tool | Apify | browsing | excessive permissions | | resolved |
| 27 Aug 2026 | Dash MCP server DNS rebinding via missing host header validation | Dropbox | other | misconfiguration | | resolved |
| 27 Aug 2026 | ServiceNow AI platform code injection and SQL injection vulnerabilities | ServiceNow | other | unknown | | resolved |
| 27 Aug 2026 | mcp-go HTTP Host header validation vulnerability | mark3labs | other | misconfiguration | | resolved |
| 26 Aug 2026 | CVE-2026-75062: Eval Injection in Google langfun | Google | coding | prompt injection | | confirmed |
| 25 Aug 2026 | MCP PHP SDK Memory Exhaustion Vulnerability | Anthropic | other | tool misuse | | resolved |
| 25 Aug 2026 | Prompt injection in Amazon Strands Agents Tools python_repl | Amazon | coding | prompt injection | | confirmed |
| 25 Aug 2026 | Dradis CE SSRF via unrestricted AI provider address | Dradis | coding | excessive permissions | | reported |
| 25 Aug 2026 | mcp-shell Multiple Command Execution Vulnerabilities | sonirico | coding | misconfiguration | | resolved |
| 25 Aug 2026 | CVE-2026-55637: genieacs-mcp DNS rebinding vulnerability | GeiserX | other | misconfiguration | | resolved |
| 25 Aug 2026 | Path traversal in sublinear-time-solver and consciousness-explorer | ruvnet | other | misconfiguration | | resolved |
| 25 Aug 2026 | CVE-2026-55529: PraisonAI Origin Validation Bypass | MervinPraison | workflow | misconfiguration | | resolved |
| 25 Aug 2026 | Nextcloud MCP Server unauthenticated webhook endpoint allows index deletion | Nextcloud | coding | misconfiguration | | resolved |
| 24 Aug 2026 | Continue CLI incomplete denylist allows destructive commands | Continue | workflow | prompt injection | | reported |
| 21 Aug 2026 | Spring AI MCP Streamable HTTP server memory exhaustion DoS | Spring | other | misconfiguration | | reported |
| 21 Aug 2026 | Infracost symlink traversal and token disclosure vulnerabilities | Infracost | coding | tool misuse | | resolved |
| 20 Aug 2026 | Neo.mjs command injection in FileSystemService.mjs | Neo.mjs | coding | tool misuse | | resolved |
| 20 Aug 2026 | AI Agent by SiteGround WordPress plugin authorization bypass | SiteGround | coding | excessive permissions | | reported |
| 20 Aug 2026 | LangChain SitemapLoader SSRF bypass via nested sitemap entries | LangChain | other | excessive permissions | | reported |
| 20 Aug 2026 | LangBot MCP Server RCE via Insufficient Authorization | LangBot | coding | excessive permissions | | reported |
| 19 Aug 2026 | marimo Code Injection via MCP Server Configuration | marimo-team | coding | prompt injection | | confirmed |
| 19 Aug 2026 | Agno PythonTools path traversal vulnerability CVE-2026-76832 | Agno | coding | prompt injection | | reported |