19 Aug 2026 · marimo-team
marimo before 0.23.15 contains a code injection vulnerability in the notebook configuration handler that allows attackers to execute arbitrary commands by supplying a crafted MCP server entry. The vulnerability is triggered when a notebook is opened in edit mode without requiring authentication or cell execution.
coding·prompt injection·
18 Aug 2026 · Apify
The Apify MCP server prior to version 0.10.11 allows malicious Actor publishers to redirect connections to third-party hosts and steal API tokens through improper URL validation in the getActorMCPServerURL function. Victims must invoke or inspect the attacker-controlled Actor to be affected.
coding·prompt injection·
18 Aug 2026 · Microsoft
Two vulnerabilities were identified in Microsoft Copilot: a command injection flaw (CVE-2026-24301) allowing unauthorized attackers to disclose information, and an SSRF vulnerability (CVE-2026-69855) in Azure allowing authorized attackers to access sensitive data over a network.
coding·prompt injection·
18 Aug 2026 · ArcadeData
ArcadeDB versions 26.4.2 through 26.7.3 contain an authorization bypass vulnerability in the set_server_setting MCP server-level tool that allows authenticated read-only users to modify server configuration when allowAdmin=true. The vulnerability is fixed in version 26.8.1.
other·excessive permissions·
18 Aug 2026 · CodeWhale
CodeWhale versions 0.8.41 through 0.8.63 contain three critical vulnerabilities allowing arbitrary code execution and file writes through prompt injection: auto-approval bypass in exec_shell_interact and rlm_eval tools, and argument injection in git_show tool.
coding·prompt injection·
18 Aug 2026 · Context7
Context7 through version 2.1.2 contains a prompt injection vulnerability in its Custom AI Instructions feature that allows attackers to inject malicious instructions through the MCP server, enabling credential exfiltration and file deletion in connected AI coding agents.
coding·prompt injection·
17 Aug 2026 · jkawamoto
A server-side request forgery vulnerability was found in jkawamoto mcp-florence2 up to version 0.3.13 in the get_images function, allowing remote exploitation through manipulation of the src argument.
other·tool misuse·
17 Aug 2026 · MLflow
Three vulnerabilities were identified in MLflow prior to version 3.15.0, including an unauthenticated SSRF via webhook validation bypass, an authentication bypass allowing injection of dataset metadata, and a path traversal enabling unauthorized artifact access. All issues were fixed in version 3.15.0.
other·excessive permissions·
17 Aug 2026 · MemTensor
MemOS fails to properly validate internal service requests when the INTERNAL_SERVICE_SECRET environment variable is unset, allowing unauthenticated remote attackers to bypass authentication and access admin API endpoints to mint, enumerate, and revoke API keys.
other·misconfiguration·
14 Aug 2026 · Cortex
The Cortex MCP server prior to version 3.17.1 treats the CLAUDE_PROJECT_DIR environment variable as trusted, allowing attackers to execute arbitrary code by placing marker files in a malicious repository.
coding·misconfiguration·
14 Aug 2026 · mcp-memory-service
mcp-memory-service versions prior to 10.67.1 lack authentication on /api/documents/* endpoints, allowing unauthenticated attackers to read, write, and delete memory content despite configured API keys or OAuth.
other·misconfiguration·
14 Aug 2026 · MindsDB
MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability allowing attackers to execute arbitrary OS commands by submitting crafted prompts to the unprotected API endpoint, which reaches the Anton agent's scratchpad tool that calls exec() on attacker-influenced Python code without sandboxing.
coding·excessive permissions·
14 Aug 2026 · ondata
CKAN MCP Server versions prior to 0.4.112 contain multiple security vulnerabilities including information disclosure through error reflection, URL validation bypass allowing SSRF attacks, and cache poisoning via parameter collision. These issues are fixed in version 0.4.112.
other·misconfiguration·
13 Aug 2026 · ymw0407
auth-fetch-mcp version 3.0.1 contains a Server-Side Request Forgery vulnerability where IPv4-mapped IPv6 loopback addresses bypass SSRF protection, allowing access to blocked loopback services. The issue was patched in version 3.0.1.
other·misconfiguration·
13 Aug 2026 · Trigger.dev
Five CVEs affecting Trigger.dev versions 3.3.8 through 4.5.6 allow prototype pollution, account takeover, cross-tenant resource access, and payload manipulation via insufficient input validation and missing ownership checks.
workflow·misconfiguration·
13 Aug 2026 · Model Context Protocol
A server-side request forgery vulnerability was detected in Model Context Protocol mcp-rdf-explorer 1.0.0 in the explore_url function. The exploit is public and the vendor did not respond to early disclosure.
other·tool misuse·
13 Aug 2026 · Flowise
Flowise before version 3.1.3 contains multiple code injection vulnerabilities in the Airtable and CSV Agent nodes that allow unauthenticated attackers to execute arbitrary Python code through prompt injection and validator bypasses.
workflow·prompt injection·
13 Aug 2026 · jshookmcp
CVE-2026-49856 in @jshookmcp/jshook version 0.3.1 allows MCP clients to bypass SSRF authorization policies by using ICMP probe and traceroute tools to probe internal network addresses. The vulnerability exposes internal reachability and route mapping from the server's network position.
other·excessive permissions·
13 Aug 2026 · HCL
HCL AION is affected by a vulnerability where indirect prompt injection can lead to HTML injection in rendered output. Injected markup may be displayed to users, potentially resulting in unintended behavior or security impact.
other·prompt injection·
13 Aug 2026 ·
A person embedded a prompt injection within a legal filing, instructing any AI system that reviewed the document to rule in their favor, according to a 404 Media report.
other·prompt injection·
13 Aug 2026 · EnzoVezzaro
Multiple server-side request forgery vulnerabilities were discovered in EnzoVezzaro's mcp-dominican-layer project, affecting the parse-csv and parse-pdf tools through manipulation of csvUrl and pdfUrl arguments. The vulnerabilities have been disclosed publicly and the vendor has not yet responded.
other·tool misuse·
13 Aug 2026 · Fosowl
AgenticSeek contains an unauthenticated remote code execution vulnerability in its POST /query API endpoint that allows network-adjacent attackers to execute arbitrary shell commands through a crafted query.
other·excessive permissions·
12 Aug 2026 · Atlassian
MCP Atlassian versions prior to 0.22.0 allow authenticated clients to read arbitrary files accessible to the server process and exfiltrate them through Confluence attachments. If exploited through AI agents, this could expose sensitive credentials like API tokens and environment variables.
other·excessive permissions·
11 Aug 2026 · Grafana
A vulnerability in mcp-grafana allows callers to control the destination of outbound requests via the X-Grafana-URL header, enabling server-side request forgery attacks against internal and metadata services. The grafana_api_request tool permits manipulation of HTTP methods, paths, and request bodies.
coding·misconfiguration·
11 Aug 2026 · ToolJet
ToolJet prior to version 3.20.207 contains an authorization bypass vulnerability in its Database HTTP API that allows authenticated users to access, modify, and delete data across organization boundaries by manipulating the tj-workspace-id header.
workflow·excessive permissions·
11 Aug 2026 · Cursor
Two vulnerabilities in Cursor IDE for macOS allow agents running in Auto-Run Sandbox mode to escape the sandbox and execute arbitrary commands with user privileges. The first affects versions before 3.1.2 through Python executable replacement; the second affects versions before 3.0.0 through Docker container mounting.
coding·excessive permissions·
11 Aug 2026 · Microsoft
An improper neutralization of special elements in os commands vulnerability in GitHub Copilot and Visual Studio Code allows unauthorized attackers to elevate privileges locally.
coding·tool misuse·
11 Aug 2026 · PapersGPT
PapersGPT for Zotero 0.6.1 contains a remote code execution vulnerability where unsanitized LLM responses are passed to window.eval(), allowing attackers to execute arbitrary JavaScript through prompt injection, MITM interception, or malicious LLM endpoints.
other·prompt injection·
11 Aug 2026 · n8n
n8n versions before 2.32.1 contain a server-side request forgery protection bypass vulnerability in the MCP Client node that allows authenticated users to bypass SSRF protections and access internal services.
workflow·misconfiguration·
10 Aug 2026 · AAIF
The goose AI agent's `review` command prior to version 1.44.0 executes arbitrary commands from malicious Git repository configurations without user approval or sandboxing, allowing attackers to access files and steal environment secrets.
coding·misconfiguration·
9 Aug 2026 · adenot
A server-side request forgery vulnerability was identified in adenot mcp-google-search up to version 0.3.1 in the read_webpage component. The vulnerability allows manipulation of the url argument and is restricted to local execution.
other·tool misuse·
8 Aug 2026 · AI Copilot
The AI Copilot – Content Generator WordPress plugin up to version 1.5.6 is vulnerable to authorization bypass, allowing unauthenticated attackers to create administrator accounts and achieve full site takeover by executing malicious workflows with exposed nonce values.
workflow·excessive permissions·
8 Aug 2026 · INQUIRELAB
A command injection vulnerability was discovered in INQUIRELAB mcp-bridge-api in the Servers Endpoint that allows remote attackers to manipulate command/args arguments. A fix has been proposed but not yet accepted.
other·tool misuse·
7 Aug 2026 · Meta
Meta Ads MCP server prior to version 1.0.109 failed to authenticate HTTP requests, allowing unauthenticated callers to invoke MCP tools and potentially obtain access tokens through error responses. The vulnerability was fixed in version 1.0.109.
workflow·misconfiguration·
6 Aug 2026 · Kino-Kafkaesque
A command injection vulnerability was detected in the SSH Command Handler component of Kino-Kafkaesque ssh-mcp-server through commit 8ebbbb99b26f80ff6162fe00957c6dec73fbc5a5. The vulnerability allows manipulation of host/username arguments to achieve command injection, though the project maintainer disputes the threat given the tool's intended use model as a local trusted agent.
workflow·tool misuse·
6 Aug 2026 · Microsoft
Two separate improper authorization vulnerabilities were discovered in Microsoft Copilot Cowork and Visual Studio Code Copilot Chat Extension, allowing unauthorized attackers to elevate privileges and bypass security features over a network.
coding·excessive permissions·
6 Aug 2026 · MissionSquad
A server-side request forgery vulnerability was found in MissionSquad mcp-api up to version 1.11.9 in the src/services/dcrClients.ts file. The issue was fixed in version 1.11.10.
other·tool misuse·
5 Aug 2026 · IBM
IBM Langflow OSS versions 1.0.0 through 1.10.3 contain multiple vulnerabilities allowing authenticated attackers to execute arbitrary commands, read arbitrary files, bypass restrictions, and execute unintended code through improper validation in MCP server configurations and Agentic Assistant validation.
coding·excessive permissions·
5 Aug 2026 · AgentFront
FrontMCP versions prior to 1.5.7 contain a sandbox escape vulnerability in the codecall:execute tool that allows attackers to achieve remote code execution by accessing the host Function constructor through Zod schema instances. The vulnerability can be exploited unauthenticated on unconfigured servers or via prompt injection on authenticated servers.
coding·excessive permissions·
4 Aug 2026 · FlowiseAI
Two vulnerabilities in Flowise prior to version 3.1.3 allow arbitrary code execution: CVE-2026-69263 enables supply chain attacks via npm configuration variables during MCP server launch, and CVE-2026-70477 enables prompt injection attacks through CSV Agent nodes that bypass code validation. Both are fixed in version 3.1.3.
workflow·supply chain·
3 Aug 2026 · Q00
Ouroboros versions prior to 0.39.0 allow arbitrary code execution when users run commands in directories containing malicious repositories, as the runtime loads and executes environment variables from .env files without validation. A second vulnerability in versions prior to 0.42.1 bypasses the initial fix through an incomplete denylist of environment variables.
coding·misconfiguration·
3 Aug 2026 · Amazon Web Services
A prompt injection vulnerability in Amazon MQ MCP Server before version 2.0.24 allows remote unauthenticated actors to obtain RabbitMQ broker credentials or OAuth access tokens through improper endpoint restriction.
coding·prompt injection·
3 Aug 2026 · Amazon
Two vulnerabilities were disclosed in Amazon Strands Agents Tools: a prompt injection flaw in the shell tool allowing arbitrary OS command execution, and an insecure direct object reference in memory tools allowing unauthorized access to other tenants' data.
other·prompt injection·
2 Aug 2026 · ArcadeDB
ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability in the MCP get_server_settings tool that leaks the cluster token in cleartext. Attackers with MCP access can retrieve the token and impersonate root to achieve full server compromise.
other·data leak·
1 Aug 2026 · better-auth
better-auth before version 1.6.13 fails to validate redirect URI schemes, allowing attackers to register OAuth clients with javascript: URIs that execute in the authorization server's origin, potentially exposing user sessions and enabling account takeover.
other·misconfiguration·
31 Jul 2026 · Strands
Incorrect authorization in the http_request tool in Strands Agents Tools before version 0.8.2 could allow remote attackers to obtain credentials by influencing the LLM to route requests through attacker-controlled proxy infrastructure.
other·excessive permissions·
29 Jul 2026 · Anthropic
The MCP Ruby SDK versions prior to 0.23.0 contain four security vulnerabilities including DNS rebinding attacks, memory exhaustion, session fixation, and unauthenticated remote denial of service. All issues were fixed in version 0.23.0.
other·misconfiguration·
29 Jul 2026 · Flyto
Flyto2 Core prior to version 2.26.7 contains a server-side request forgery (SSRF) vulnerability in multiple HTTP-emitting modules that fail to validate caller-controlled URLs, allowing access to internal or metadata endpoints.
workflow·misconfiguration·
29 Jul 2026 · Anthropic
MCP Ruby SDK versions prior to 0.23.0 fail to expire sessions by default in StreamableHTTPTransport, allowing repeated initialize requests to create unbounded ServerSession objects and exhaust process memory.
other·misconfiguration·
29 Jul 2026 · Pydantic
Three vulnerabilities discovered in Pydantic AI framework allow attackers to bypass security controls: cloud metadata credential exposure via IPv6-encoded IPs, arbitrary file access through unvalidated UploadedFile references, and execution of unresolved tool calls with attacker-supplied arguments.
workflow·excessive permissions·