Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Incident database

Structured records of AI agent security incidents: what happened, which vendor and agent type, the root cause, and every source we used. Filter, browse, or download as CSV.

Incidents by month, 2026 · 434 total · click a month to filter
Jan 2026: 23 incidents23JanFeb 2026: 26 incidents26FebMar 2026: 46 incidents46MarApr 2026: 46 incidents46AprMay 2026: 52 incidents52MayJun 2026: 51 incidents51JunJul 2026: 45 incidents45JulAug 2026: 82 incidents82AugSep 2026: 63 incidents63SepOct 2026: 0 incidents0OctNov 2026: 0 incidents0NovDec 2026: 0 incidents0Dec

453 incidents

Incident dateIncidentVendorAgentRoot causeSeverityStatus
19 Aug 2026marimo Code Injection via MCP Server Configurationmarimo-teamcodingprompt injectionconfirmed
18 Aug 2026Apify MCP Server API Token Exposure via URL RedirectionApifycodingprompt injectionresolved
18 Aug 2026Command Injection and SSRF Vulnerabilities in Microsoft CopilotMicrosoftcodingprompt injectionreported
18 Aug 2026ArcadeDB authorization bypass in set_server_setting MCP toolArcadeDataotherexcessive permissionsresolved
18 Aug 2026CodeWhale Multiple Vulnerabilities in Versions 0.8.41-0.8.63CodeWhalecodingprompt injectionresolved
18 Aug 2026CVE-2026-75130: Context7 prompt injection via Custom AI InstructionsContext7codingprompt injectionreported
17 Aug 2026CVE-2026-19984: SSRF in jkawamoto mcp-florence2jkawamotoothertool misuseconfirmed
17 Aug 2026MLflow multiple vulnerabilities in versions prior to 3.15.0MLflowotherexcessive permissionsresolved
17 Aug 2026MemOS Authentication Bypass via Unset Internal Service SecretMemTensorothermisconfigurationreported
14 Aug 2026CVE-2026-49986: Cortex MCP Arbitrary Code Execution via Environment VariableCortexcodingmisconfigurationconfirmed
14 Aug 2026mcp-memory-service authentication bypass in document endpointsmcp-memory-serviceothermisconfigurationconfirmed
14 Aug 2026MindsDB Minds Platform unauthenticated RCE via scratchpad toolMindsDBcodingexcessive permissionsreported
14 Aug 2026Multiple vulnerabilities in CKAN MCP Server prior to 0.4.112ondataothermisconfigurationresolved
13 Aug 2026auth-fetch-mcp SSRF Protection Bypass via IPv6 Loopbackymw0407othermisconfigurationresolved
13 Aug 2026Multiple vulnerabilities in Trigger.dev platformTrigger.devworkflowmisconfigurationresolved
13 Aug 2026CVE-2026-19753: SSRF in mcp-rdf-explorerModel Context Protocolothertool misusereported
13 Aug 2026Flowise code injection vulnerabilities in Agent nodesFlowiseworkflowprompt injectionconfirmed
13 Aug 2026@jshookmcp/jshook SSRF bypass via ICMP and traceroute toolsjshookmcpotherexcessive permissionsresolved
13 Aug 2026HCL AION Indirect Prompt Injection Leading to HTML InjectionHCLotherprompt injectionconfirmed
13 Aug 2026Prompt Injection Hidden in Legal Filing to Manipulate AI Reviewotherprompt injectionreported
13 Aug 2026Server-Side Request Forgery in mcp-dominican-layerEnzoVezzaroothertool misusereported
13 Aug 2026AgenticSeek unauthenticated remote code execution vulnerabilityFosowlotherexcessive permissionsreported
12 Aug 2026MCP Atlassian arbitrary file read vulnerabilityAtlassianotherexcessive permissionsresolved
11 Aug 2026CVE-2026-19516: Server-side request forgery in mcp-grafanaGrafanacodingmisconfigurationconfirmed
11 Aug 2026ToolJet authorization bypass allows cross-organization data accessToolJetworkflowexcessive permissionsresolved
11 Aug 2026Cursor IDE macOS sandbox escapes in Auto-Run modeCursorcodingexcessive permissionsresolved
11 Aug 2026OS Command Injection in GitHub Copilot and Visual Studio CodeMicrosoftcodingtool misusereported
11 Aug 2026PapersGPT for Zotero RCE via unsanitized LLM responsePapersGPTotherprompt injectionreported
11 Aug 2026n8n MCP Client SSRF Protection Bypassn8nworkflowmisconfigurationconfirmed
10 Aug 2026CVE-2026-72718: Goose AI agent arbitrary command execution via Git configAAIFcodingmisconfigurationresolved
9 Aug 2026CVE-2026-19337: Server-side request forgery in mcp-google-searchadenotothertool misuseconfirmed
8 Aug 2026AI Copilot Content Generator WordPress Plugin Authorization BypassAI Copilotworkflowexcessive permissionsreported
8 Aug 2026CVE-2026-19263: Command injection in INQUIRELAB mcp-bridge-apiINQUIRELABothertool misusereported
7 Aug 2026Meta Ads MCP Authentication Bypass and Token LeakageMetaworkflowmisconfigurationresolved
6 Aug 2026CVE-2026-19039: Command injection in Kino-Kafkaesque ssh-mcp-serverKino-Kafkaesqueworkflowtool misusedisputed
6 Aug 2026Multiple authorization vulnerabilities in Microsoft Copilot productsMicrosoftcodingexcessive permissionsreported
6 Aug 2026CVE-2026-19040: Server-side request forgery in MissionSquad mcp-apiMissionSquadothertool misuseresolved
5 Aug 2026IBM Langflow OSS Multiple Vulnerabilities CVE-2026-17623 et al.IBMcodingexcessive permissionsreported
5 Aug 2026FrontMCP Sandbox Escape via Zod Schema Proxy InvariantAgentFrontcodingexcessive permissionsconfirmed
4 Aug 2026Flowise supply chain and prompt injection vulnerabilitiesFlowiseAIworkflowsupply chainresolved
3 Aug 2026Ouroboros AI coding agent local code execution via .env loadingQ00codingmisconfigurationresolved
3 Aug 2026CVE-2026-18655: Amazon MQ MCP Server prompt injection vulnerabilityAmazon Web Servicescodingprompt injectionconfirmed
3 Aug 2026Multiple vulnerabilities in Amazon Strands Agents ToolsAmazonotherprompt injectionconfirmed
2 Aug 2026CVE-2026-67357: ArcadeDB MCP information disclosure vulnerabilityArcadeDBotherdata leakconfirmed
1 Aug 2026better-auth redirect URI validation bypass enables XSSbetter-authothermisconfigurationreported
31 Jul 2026CVE-2026-18394: Incorrect authorization in Strands Agents Tools http_requestStrandsotherexcessive permissionsconfirmed
29 Jul 2026MCP Ruby SDK Multiple Vulnerabilities Prior to 0.23.0Anthropicothermisconfigurationresolved
29 Jul 2026Flyto2 Core SSRF vulnerability in HTTP modulesFlytoworkflowmisconfigurationconfirmed
29 Jul 2026MCP Ruby SDK memory exhaustion via unbounded session objectsAnthropicothermisconfigurationresolved
29 Jul 2026Pydantic AI Multiple Vulnerabilities in Versions 1.56.0-2.0.0b5Pydanticworkflowexcessive permissionsresolved