Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Incident database

Structured records of AI agent security incidents: what happened, which vendor and agent type, the root cause, and every source we used. Filter, browse, or download as CSV.

Incidents by month, 2026 · 434 total · click a month to filter
Jan 2026: 23 incidents23JanFeb 2026: 26 incidents26FebMar 2026: 46 incidents46MarApr 2026: 46 incidents46AprMay 2026: 52 incidents52MayJun 2026: 51 incidents51JunJul 2026: 45 incidents45JulAug 2026: 82 incidents82AugSep 2026: 63 incidents63SepOct 2026: 0 incidents0OctNov 2026: 0 incidents0NovDec 2026: 0 incidents0Dec

453 incidents

19 Aug 2026 · marimo-team

marimo Code Injection via MCP Server Configuration

marimo before 0.23.15 contains a code injection vulnerability in the notebook configuration handler that allows attackers to execute arbitrary commands by supplying a crafted MCP server entry. The vulnerability is triggered when a notebook is opened in edit mode without requiring authentication or cell execution.

coding·prompt injection·

18 Aug 2026 · Apify

Apify MCP Server API Token Exposure via URL Redirection

The Apify MCP server prior to version 0.10.11 allows malicious Actor publishers to redirect connections to third-party hosts and steal API tokens through improper URL validation in the getActorMCPServerURL function. Victims must invoke or inspect the attacker-controlled Actor to be affected.

coding·prompt injection·

18 Aug 2026 · Microsoft

Command Injection and SSRF Vulnerabilities in Microsoft Copilot

Two vulnerabilities were identified in Microsoft Copilot: a command injection flaw (CVE-2026-24301) allowing unauthorized attackers to disclose information, and an SSRF vulnerability (CVE-2026-69855) in Azure allowing authorized attackers to access sensitive data over a network.

coding·prompt injection·

18 Aug 2026 · ArcadeData

ArcadeDB authorization bypass in set_server_setting MCP tool

ArcadeDB versions 26.4.2 through 26.7.3 contain an authorization bypass vulnerability in the set_server_setting MCP server-level tool that allows authenticated read-only users to modify server configuration when allowAdmin=true. The vulnerability is fixed in version 26.8.1.

other·excessive permissions·

18 Aug 2026 · CodeWhale

CodeWhale Multiple Vulnerabilities in Versions 0.8.41-0.8.63

CodeWhale versions 0.8.41 through 0.8.63 contain three critical vulnerabilities allowing arbitrary code execution and file writes through prompt injection: auto-approval bypass in exec_shell_interact and rlm_eval tools, and argument injection in git_show tool.

coding·prompt injection·

18 Aug 2026 · Context7

CVE-2026-75130: Context7 prompt injection via Custom AI Instructions

Context7 through version 2.1.2 contains a prompt injection vulnerability in its Custom AI Instructions feature that allows attackers to inject malicious instructions through the MCP server, enabling credential exfiltration and file deletion in connected AI coding agents.

coding·prompt injection·

17 Aug 2026 · jkawamoto

CVE-2026-19984: SSRF in jkawamoto mcp-florence2

A server-side request forgery vulnerability was found in jkawamoto mcp-florence2 up to version 0.3.13 in the get_images function, allowing remote exploitation through manipulation of the src argument.

other·tool misuse·

17 Aug 2026 · MLflow

MLflow multiple vulnerabilities in versions prior to 3.15.0

Three vulnerabilities were identified in MLflow prior to version 3.15.0, including an unauthenticated SSRF via webhook validation bypass, an authentication bypass allowing injection of dataset metadata, and a path traversal enabling unauthorized artifact access. All issues were fixed in version 3.15.0.

other·excessive permissions·

17 Aug 2026 · MemTensor

MemOS Authentication Bypass via Unset Internal Service Secret

MemOS fails to properly validate internal service requests when the INTERNAL_SERVICE_SECRET environment variable is unset, allowing unauthenticated remote attackers to bypass authentication and access admin API endpoints to mint, enumerate, and revoke API keys.

other·misconfiguration·

14 Aug 2026 · mcp-memory-service

mcp-memory-service authentication bypass in document endpoints

mcp-memory-service versions prior to 10.67.1 lack authentication on /api/documents/* endpoints, allowing unauthenticated attackers to read, write, and delete memory content despite configured API keys or OAuth.

other·misconfiguration·

14 Aug 2026 · MindsDB

MindsDB Minds Platform unauthenticated RCE via scratchpad tool

MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability allowing attackers to execute arbitrary OS commands by submitting crafted prompts to the unprotected API endpoint, which reaches the Anton agent's scratchpad tool that calls exec() on attacker-influenced Python code without sandboxing.

coding·excessive permissions·

14 Aug 2026 · ondata

Multiple vulnerabilities in CKAN MCP Server prior to 0.4.112

CKAN MCP Server versions prior to 0.4.112 contain multiple security vulnerabilities including information disclosure through error reflection, URL validation bypass allowing SSRF attacks, and cache poisoning via parameter collision. These issues are fixed in version 0.4.112.

other·misconfiguration·

13 Aug 2026 · ymw0407

auth-fetch-mcp SSRF Protection Bypass via IPv6 Loopback

auth-fetch-mcp version 3.0.1 contains a Server-Side Request Forgery vulnerability where IPv4-mapped IPv6 loopback addresses bypass SSRF protection, allowing access to blocked loopback services. The issue was patched in version 3.0.1.

other·misconfiguration·

13 Aug 2026 · Trigger.dev

Multiple vulnerabilities in Trigger.dev platform

Five CVEs affecting Trigger.dev versions 3.3.8 through 4.5.6 allow prototype pollution, account takeover, cross-tenant resource access, and payload manipulation via insufficient input validation and missing ownership checks.

workflow·misconfiguration·

13 Aug 2026 · Model Context Protocol

CVE-2026-19753: SSRF in mcp-rdf-explorer

A server-side request forgery vulnerability was detected in Model Context Protocol mcp-rdf-explorer 1.0.0 in the explore_url function. The exploit is public and the vendor did not respond to early disclosure.

other·tool misuse·

13 Aug 2026 · Flowise

Flowise code injection vulnerabilities in Agent nodes

Flowise before version 3.1.3 contains multiple code injection vulnerabilities in the Airtable and CSV Agent nodes that allow unauthenticated attackers to execute arbitrary Python code through prompt injection and validator bypasses.

workflow·prompt injection·

13 Aug 2026 · jshookmcp

@jshookmcp/jshook SSRF bypass via ICMP and traceroute tools

CVE-2026-49856 in @jshookmcp/jshook version 0.3.1 allows MCP clients to bypass SSRF authorization policies by using ICMP probe and traceroute tools to probe internal network addresses. The vulnerability exposes internal reachability and route mapping from the server's network position.

other·excessive permissions·

13 Aug 2026 · HCL

HCL AION Indirect Prompt Injection Leading to HTML Injection

HCL AION is affected by a vulnerability where indirect prompt injection can lead to HTML injection in rendered output. Injected markup may be displayed to users, potentially resulting in unintended behavior or security impact.

other·prompt injection·

13 Aug 2026 · EnzoVezzaro

Server-Side Request Forgery in mcp-dominican-layer

Multiple server-side request forgery vulnerabilities were discovered in EnzoVezzaro's mcp-dominican-layer project, affecting the parse-csv and parse-pdf tools through manipulation of csvUrl and pdfUrl arguments. The vulnerabilities have been disclosed publicly and the vendor has not yet responded.

other·tool misuse·

13 Aug 2026 · Fosowl

AgenticSeek unauthenticated remote code execution vulnerability

AgenticSeek contains an unauthenticated remote code execution vulnerability in its POST /query API endpoint that allows network-adjacent attackers to execute arbitrary shell commands through a crafted query.

other·excessive permissions·

12 Aug 2026 · Atlassian

MCP Atlassian arbitrary file read vulnerability

MCP Atlassian versions prior to 0.22.0 allow authenticated clients to read arbitrary files accessible to the server process and exfiltrate them through Confluence attachments. If exploited through AI agents, this could expose sensitive credentials like API tokens and environment variables.

other·excessive permissions·

11 Aug 2026 · Grafana

CVE-2026-19516: Server-side request forgery in mcp-grafana

A vulnerability in mcp-grafana allows callers to control the destination of outbound requests via the X-Grafana-URL header, enabling server-side request forgery attacks against internal and metadata services. The grafana_api_request tool permits manipulation of HTTP methods, paths, and request bodies.

coding·misconfiguration·

11 Aug 2026 · ToolJet

ToolJet authorization bypass allows cross-organization data access

ToolJet prior to version 3.20.207 contains an authorization bypass vulnerability in its Database HTTP API that allows authenticated users to access, modify, and delete data across organization boundaries by manipulating the tj-workspace-id header.

workflow·excessive permissions·

11 Aug 2026 · Cursor

Cursor IDE macOS sandbox escapes in Auto-Run mode

Two vulnerabilities in Cursor IDE for macOS allow agents running in Auto-Run Sandbox mode to escape the sandbox and execute arbitrary commands with user privileges. The first affects versions before 3.1.2 through Python executable replacement; the second affects versions before 3.0.0 through Docker container mounting.

coding·excessive permissions·

11 Aug 2026 · PapersGPT

PapersGPT for Zotero RCE via unsanitized LLM response

PapersGPT for Zotero 0.6.1 contains a remote code execution vulnerability where unsanitized LLM responses are passed to window.eval(), allowing attackers to execute arbitrary JavaScript through prompt injection, MITM interception, or malicious LLM endpoints.

other·prompt injection·

11 Aug 2026 · n8n

n8n MCP Client SSRF Protection Bypass

n8n versions before 2.32.1 contain a server-side request forgery protection bypass vulnerability in the MCP Client node that allows authenticated users to bypass SSRF protections and access internal services.

workflow·misconfiguration·

9 Aug 2026 · adenot

CVE-2026-19337: Server-side request forgery in mcp-google-search

A server-side request forgery vulnerability was identified in adenot mcp-google-search up to version 0.3.1 in the read_webpage component. The vulnerability allows manipulation of the url argument and is restricted to local execution.

other·tool misuse·

8 Aug 2026 · AI Copilot

AI Copilot Content Generator WordPress Plugin Authorization Bypass

The AI Copilot – Content Generator WordPress plugin up to version 1.5.6 is vulnerable to authorization bypass, allowing unauthenticated attackers to create administrator accounts and achieve full site takeover by executing malicious workflows with exposed nonce values.

workflow·excessive permissions·

8 Aug 2026 · INQUIRELAB

CVE-2026-19263: Command injection in INQUIRELAB mcp-bridge-api

A command injection vulnerability was discovered in INQUIRELAB mcp-bridge-api in the Servers Endpoint that allows remote attackers to manipulate command/args arguments. A fix has been proposed but not yet accepted.

other·tool misuse·

7 Aug 2026 · Meta

Meta Ads MCP Authentication Bypass and Token Leakage

Meta Ads MCP server prior to version 1.0.109 failed to authenticate HTTP requests, allowing unauthenticated callers to invoke MCP tools and potentially obtain access tokens through error responses. The vulnerability was fixed in version 1.0.109.

workflow·misconfiguration·

6 Aug 2026 · Kino-Kafkaesque

CVE-2026-19039: Command injection in Kino-Kafkaesque ssh-mcp-server

A command injection vulnerability was detected in the SSH Command Handler component of Kino-Kafkaesque ssh-mcp-server through commit 8ebbbb99b26f80ff6162fe00957c6dec73fbc5a5. The vulnerability allows manipulation of host/username arguments to achieve command injection, though the project maintainer disputes the threat given the tool's intended use model as a local trusted agent.

workflow·tool misuse·

6 Aug 2026 · Microsoft

Multiple authorization vulnerabilities in Microsoft Copilot products

Two separate improper authorization vulnerabilities were discovered in Microsoft Copilot Cowork and Visual Studio Code Copilot Chat Extension, allowing unauthorized attackers to elevate privileges and bypass security features over a network.

coding·excessive permissions·

5 Aug 2026 · IBM

IBM Langflow OSS Multiple Vulnerabilities CVE-2026-17623 et al.

IBM Langflow OSS versions 1.0.0 through 1.10.3 contain multiple vulnerabilities allowing authenticated attackers to execute arbitrary commands, read arbitrary files, bypass restrictions, and execute unintended code through improper validation in MCP server configurations and Agentic Assistant validation.

coding·excessive permissions·

5 Aug 2026 · AgentFront

FrontMCP Sandbox Escape via Zod Schema Proxy Invariant

FrontMCP versions prior to 1.5.7 contain a sandbox escape vulnerability in the codecall:execute tool that allows attackers to achieve remote code execution by accessing the host Function constructor through Zod schema instances. The vulnerability can be exploited unauthenticated on unconfigured servers or via prompt injection on authenticated servers.

coding·excessive permissions·

4 Aug 2026 · FlowiseAI

Flowise supply chain and prompt injection vulnerabilities

Two vulnerabilities in Flowise prior to version 3.1.3 allow arbitrary code execution: CVE-2026-69263 enables supply chain attacks via npm configuration variables during MCP server launch, and CVE-2026-70477 enables prompt injection attacks through CSV Agent nodes that bypass code validation. Both are fixed in version 3.1.3.

workflow·supply chain·

3 Aug 2026 · Q00

Ouroboros AI coding agent local code execution via .env loading

Ouroboros versions prior to 0.39.0 allow arbitrary code execution when users run commands in directories containing malicious repositories, as the runtime loads and executes environment variables from .env files without validation. A second vulnerability in versions prior to 0.42.1 bypasses the initial fix through an incomplete denylist of environment variables.

coding·misconfiguration·

3 Aug 2026 · Amazon Web Services

CVE-2026-18655: Amazon MQ MCP Server prompt injection vulnerability

A prompt injection vulnerability in Amazon MQ MCP Server before version 2.0.24 allows remote unauthenticated actors to obtain RabbitMQ broker credentials or OAuth access tokens through improper endpoint restriction.

coding·prompt injection·

3 Aug 2026 · Amazon

Multiple vulnerabilities in Amazon Strands Agents Tools

Two vulnerabilities were disclosed in Amazon Strands Agents Tools: a prompt injection flaw in the shell tool allowing arbitrary OS command execution, and an insecure direct object reference in memory tools allowing unauthorized access to other tenants' data.

other·prompt injection·

2 Aug 2026 · ArcadeDB

CVE-2026-67357: ArcadeDB MCP information disclosure vulnerability

ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability in the MCP get_server_settings tool that leaks the cluster token in cleartext. Attackers with MCP access can retrieve the token and impersonate root to achieve full server compromise.

other·data leak·

1 Aug 2026 · better-auth

better-auth redirect URI validation bypass enables XSS

better-auth before version 1.6.13 fails to validate redirect URI schemes, allowing attackers to register OAuth clients with javascript: URIs that execute in the authorization server's origin, potentially exposing user sessions and enabling account takeover.

other·misconfiguration·

29 Jul 2026 · Anthropic

MCP Ruby SDK Multiple Vulnerabilities Prior to 0.23.0

The MCP Ruby SDK versions prior to 0.23.0 contain four security vulnerabilities including DNS rebinding attacks, memory exhaustion, session fixation, and unauthenticated remote denial of service. All issues were fixed in version 0.23.0.

other·misconfiguration·

29 Jul 2026 · Flyto

Flyto2 Core SSRF vulnerability in HTTP modules

Flyto2 Core prior to version 2.26.7 contains a server-side request forgery (SSRF) vulnerability in multiple HTTP-emitting modules that fail to validate caller-controlled URLs, allowing access to internal or metadata endpoints.

workflow·misconfiguration·

29 Jul 2026 · Anthropic

MCP Ruby SDK memory exhaustion via unbounded session objects

MCP Ruby SDK versions prior to 0.23.0 fail to expire sessions by default in StreamableHTTPTransport, allowing repeated initialize requests to create unbounded ServerSession objects and exhaust process memory.

other·misconfiguration·

29 Jul 2026 · Pydantic

Pydantic AI Multiple Vulnerabilities in Versions 1.56.0-2.0.0b5

Three vulnerabilities discovered in Pydantic AI framework allow attackers to bypass security controls: cloud metadata credential exposure via IPv6-encoded IPs, arbitrary file access through unvalidated UploadedFile references, and execution of unresolved tool calls with attacker-supplied arguments.

workflow·excessive permissions·