Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Incident database

Structured records of AI agent security incidents: what happened, which vendor and agent type, the root cause, and every source we used. Filter, browse, or download as CSV.

Incidents by month, 2026 · 434 total · click a month to filter
Jan 2026: 23 incidents23JanFeb 2026: 26 incidents26FebMar 2026: 46 incidents46MarApr 2026: 46 incidents46AprMay 2026: 52 incidents52MayJun 2026: 51 incidents51JunJul 2026: 45 incidents45JulAug 2026: 82 incidents82AugSep 2026: 63 incidents63SepOct 2026: 0 incidents0OctNov 2026: 0 incidents0NovDec 2026: 0 incidents0Dec

453 incidents

Incident dateIncidentVendorAgentRoot causeSeverityStatus
3 Sept 2026Broken Access Control in Agentimus AI SEO PluginAgentimusotherexcessive permissionsreported
3 Sept 2026Multiple vulnerabilities in simular-ai Agent-Ssimular-aiothertool misusereported
3 Sept 2026Cheshire Cat AI memory endpoint lacks per-user filteringCheshire Cat AIotherexcessive permissionsreported
2 Sept 2026CKAN MCP Server: Multiple security vulnerabilities in allowlist and cacheaborrusootherprompt injectionreported
2 Sept 2026Omnigent: Multiple Authenticated RCE and Policy Bypass VulnerabilitiesOmnigent (Databricks)otherexcessive permissionsreported
2 Sept 2026claude-skill-antivirus fails to analyze executable files in skill directoriesAnthropiccodingtool misusereported
2 Sept 2026ntegrals openbrowser Browser Agent Message Construction DoSntegralsbrowsingtool misusereported
2 Sept 2026SSRF vulnerability in GitHub Enterprise Server Management APIGitHubothermisconfigurationresolved
2 Sept 2026Multiple DoS vulnerabilities in zhayujie CowAgentzhayujiecodingtool misusereported
2 Sept 2026OpenChoreo unauthenticated cluster-gateway management API accessOpenChoreoothermisconfigurationconfirmed
1 Sept 2026Authorization bypass in runZero Platform MCP servicerunZerootherexcessive permissionsresolved
1 Sept 2026appium-mcp-server Path Traversal in File Write ToolsAppiumothermisconfigurationreported
1 Sept 2026Multiple vulnerabilities in NousResearch hermes-agentNousResearchworkflowunknownreported
31 Aug 2026Origin validation error in ash_ai MCP server allows DNS rebinding attacksash-projectothermisconfigurationconfirmed
31 Aug 2026Meta Researcher's AI Agent Accidentally Deleted Her EmailsMetaotherhallucinated actionreported
31 Aug 2026CVE-2026-82905: SSRF in sdcb chats McpControllersdcbothertool misusereported
28 Aug 2026SiYuan path traversal and path guard bypass vulnerabilitiesSiYuanotherprompt injectionconfirmed
28 Aug 2026Multiple vulnerabilities in Microsoft Copilot productsMicrosoftothermisconfigurationreported
28 Aug 2026Hatchet Dispatcher gRPC Service Missing Tenant VerificationHatchetworkflowmisconfigurationresolved
27 Aug 2026DNS Rebinding Vulnerability in Timescale MCP ToolsTimescaleothermisconfigurationconfirmed
27 Aug 2026Agno Remote Code Execution via Prompt InjectionAgnocodingprompt injectionreported
27 Aug 2026Nightingale SSRF vulnerability in http_fetch AI-agent toolNightingaleothermisconfigurationconfirmed
27 Aug 2026Telnyx MCP Server Missing Authentication on HTTP TransportTelnyxcodingmisconfigurationresolved
27 Aug 2026mcp-use Inspector Proxy SSRF via Unvalidated Target URLmcp-useothermisconfigurationresolved
27 Aug 2026mcp-router CLI exposed MCP aggregator without authentication by defaultmcp-routerothermisconfigurationresolved
27 Aug 2026CVE-2026-81096: ToolUniverse sandbox escape and unauthenticated RCEToolUniversecodingexcessive permissionsconfirmed
27 Aug 2026UI-TARS-desktop MCP servers bind to all interfaces without authenticationByteDanceothermisconfigurationconfirmed
27 Aug 2026GitLab AI Gateway credential disclosure vulnerabilitiesGitLabotherprompt injectionresolved
27 Aug 2026CVE-2026-81093: Apify MCP Server SSRF in get-html-skeleton toolApifybrowsingexcessive permissionsresolved
27 Aug 2026Dash MCP server DNS rebinding via missing host header validationDropboxothermisconfigurationresolved
27 Aug 2026ServiceNow AI platform code injection and SQL injection vulnerabilitiesServiceNowotherunknownresolved
27 Aug 2026mcp-go HTTP Host header validation vulnerabilitymark3labsothermisconfigurationresolved
26 Aug 2026CVE-2026-75062: Eval Injection in Google langfunGooglecodingprompt injectionconfirmed
25 Aug 2026MCP PHP SDK Memory Exhaustion VulnerabilityAnthropicothertool misuseresolved
25 Aug 2026Prompt injection in Amazon Strands Agents Tools python_replAmazoncodingprompt injectionconfirmed
25 Aug 2026Dradis CE SSRF via unrestricted AI provider addressDradiscodingexcessive permissionsreported
25 Aug 2026mcp-shell Multiple Command Execution Vulnerabilitiessoniricocodingmisconfigurationresolved
25 Aug 2026CVE-2026-55637: genieacs-mcp DNS rebinding vulnerabilityGeiserXothermisconfigurationresolved
25 Aug 2026Path traversal in sublinear-time-solver and consciousness-explorerruvnetothermisconfigurationresolved
25 Aug 2026CVE-2026-55529: PraisonAI Origin Validation BypassMervinPraisonworkflowmisconfigurationresolved
25 Aug 2026Nextcloud MCP Server unauthenticated webhook endpoint allows index deletionNextcloudcodingmisconfigurationresolved
24 Aug 2026Continue CLI incomplete denylist allows destructive commandsContinueworkflowprompt injectionreported
21 Aug 2026Spring AI MCP Streamable HTTP server memory exhaustion DoSSpringothermisconfigurationreported
21 Aug 2026Infracost symlink traversal and token disclosure vulnerabilitiesInfracostcodingtool misuseresolved
20 Aug 2026Neo.mjs command injection in FileSystemService.mjsNeo.mjscodingtool misuseresolved
20 Aug 2026AI Agent by SiteGround WordPress plugin authorization bypassSiteGroundcodingexcessive permissionsreported
20 Aug 2026LangChain SitemapLoader SSRF bypass via nested sitemap entriesLangChainotherexcessive permissionsreported
20 Aug 2026LangBot MCP Server RCE via Insufficient AuthorizationLangBotcodingexcessive permissionsreported
19 Aug 2026marimo Code Injection via MCP Server Configurationmarimo-teamcodingprompt injectionconfirmed
19 Aug 2026Agno PythonTools path traversal vulnerability CVE-2026-76832Agnocodingprompt injectionreported