| 19 Aug 2026 | marimo Code Injection via MCP Server Configuration | marimo-team | coding | prompt injection | | confirmed |
| 18 Aug 2026 | Apify MCP Server API Token Exposure via URL Redirection | Apify | coding | prompt injection | | resolved |
| 18 Aug 2026 | Command Injection and SSRF Vulnerabilities in Microsoft Copilot | Microsoft | coding | prompt injection | | reported |
| 18 Aug 2026 | ArcadeDB authorization bypass in set_server_setting MCP tool | ArcadeData | other | excessive permissions | | resolved |
| 18 Aug 2026 | CodeWhale Multiple Vulnerabilities in Versions 0.8.41-0.8.63 | CodeWhale | coding | prompt injection | | resolved |
| 18 Aug 2026 | CVE-2026-75130: Context7 prompt injection via Custom AI Instructions | Context7 | coding | prompt injection | | reported |
| 17 Aug 2026 | CVE-2026-19984: SSRF in jkawamoto mcp-florence2 | jkawamoto | other | tool misuse | | confirmed |
| 17 Aug 2026 | MLflow multiple vulnerabilities in versions prior to 3.15.0 | MLflow | other | excessive permissions | | resolved |
| 17 Aug 2026 | MemOS Authentication Bypass via Unset Internal Service Secret | MemTensor | other | misconfiguration | | reported |
| 14 Aug 2026 | CVE-2026-49986: Cortex MCP Arbitrary Code Execution via Environment Variable | Cortex | coding | misconfiguration | | confirmed |
| 14 Aug 2026 | mcp-memory-service authentication bypass in document endpoints | mcp-memory-service | other | misconfiguration | | confirmed |
| 14 Aug 2026 | MindsDB Minds Platform unauthenticated RCE via scratchpad tool | MindsDB | coding | excessive permissions | | reported |
| 14 Aug 2026 | Multiple vulnerabilities in CKAN MCP Server prior to 0.4.112 | ondata | other | misconfiguration | | resolved |
| 13 Aug 2026 | auth-fetch-mcp SSRF Protection Bypass via IPv6 Loopback | ymw0407 | other | misconfiguration | | resolved |
| 13 Aug 2026 | Multiple vulnerabilities in Trigger.dev platform | Trigger.dev | workflow | misconfiguration | | resolved |
| 13 Aug 2026 | CVE-2026-19753: SSRF in mcp-rdf-explorer | Model Context Protocol | other | tool misuse | | reported |
| 13 Aug 2026 | Flowise code injection vulnerabilities in Agent nodes | Flowise | workflow | prompt injection | | confirmed |
| 13 Aug 2026 | @jshookmcp/jshook SSRF bypass via ICMP and traceroute tools | jshookmcp | other | excessive permissions | | resolved |
| 13 Aug 2026 | HCL AION Indirect Prompt Injection Leading to HTML Injection | HCL | other | prompt injection | | confirmed |
| 13 Aug 2026 | Prompt Injection Hidden in Legal Filing to Manipulate AI Review | | other | prompt injection | | reported |
| 13 Aug 2026 | Server-Side Request Forgery in mcp-dominican-layer | EnzoVezzaro | other | tool misuse | | reported |
| 13 Aug 2026 | AgenticSeek unauthenticated remote code execution vulnerability | Fosowl | other | excessive permissions | | reported |
| 12 Aug 2026 | MCP Atlassian arbitrary file read vulnerability | Atlassian | other | excessive permissions | | resolved |
| 11 Aug 2026 | CVE-2026-19516: Server-side request forgery in mcp-grafana | Grafana | coding | misconfiguration | | confirmed |
| 11 Aug 2026 | ToolJet authorization bypass allows cross-organization data access | ToolJet | workflow | excessive permissions | | resolved |
| 11 Aug 2026 | Cursor IDE macOS sandbox escapes in Auto-Run mode | Cursor | coding | excessive permissions | | resolved |
| 11 Aug 2026 | OS Command Injection in GitHub Copilot and Visual Studio Code | Microsoft | coding | tool misuse | | reported |
| 11 Aug 2026 | PapersGPT for Zotero RCE via unsanitized LLM response | PapersGPT | other | prompt injection | | reported |
| 11 Aug 2026 | n8n MCP Client SSRF Protection Bypass | n8n | workflow | misconfiguration | | confirmed |
| 10 Aug 2026 | CVE-2026-72718: Goose AI agent arbitrary command execution via Git config | AAIF | coding | misconfiguration | | resolved |
| 9 Aug 2026 | CVE-2026-19337: Server-side request forgery in mcp-google-search | adenot | other | tool misuse | | confirmed |
| 8 Aug 2026 | AI Copilot Content Generator WordPress Plugin Authorization Bypass | AI Copilot | workflow | excessive permissions | | reported |
| 8 Aug 2026 | CVE-2026-19263: Command injection in INQUIRELAB mcp-bridge-api | INQUIRELAB | other | tool misuse | | reported |
| 7 Aug 2026 | Meta Ads MCP Authentication Bypass and Token Leakage | Meta | workflow | misconfiguration | | resolved |
| 6 Aug 2026 | CVE-2026-19039: Command injection in Kino-Kafkaesque ssh-mcp-server | Kino-Kafkaesque | workflow | tool misuse | | disputed |
| 6 Aug 2026 | Multiple authorization vulnerabilities in Microsoft Copilot products | Microsoft | coding | excessive permissions | | reported |
| 6 Aug 2026 | CVE-2026-19040: Server-side request forgery in MissionSquad mcp-api | MissionSquad | other | tool misuse | | resolved |
| 5 Aug 2026 | IBM Langflow OSS Multiple Vulnerabilities CVE-2026-17623 et al. | IBM | coding | excessive permissions | | reported |
| 5 Aug 2026 | FrontMCP Sandbox Escape via Zod Schema Proxy Invariant | AgentFront | coding | excessive permissions | | confirmed |
| 4 Aug 2026 | Flowise supply chain and prompt injection vulnerabilities | FlowiseAI | workflow | supply chain | | resolved |
| 3 Aug 2026 | Ouroboros AI coding agent local code execution via .env loading | Q00 | coding | misconfiguration | | resolved |
| 3 Aug 2026 | CVE-2026-18655: Amazon MQ MCP Server prompt injection vulnerability | Amazon Web Services | coding | prompt injection | | confirmed |
| 3 Aug 2026 | Multiple vulnerabilities in Amazon Strands Agents Tools | Amazon | other | prompt injection | | confirmed |
| 2 Aug 2026 | CVE-2026-67357: ArcadeDB MCP information disclosure vulnerability | ArcadeDB | other | data leak | | confirmed |
| 1 Aug 2026 | better-auth redirect URI validation bypass enables XSS | better-auth | other | misconfiguration | | reported |
| 31 Jul 2026 | CVE-2026-18394: Incorrect authorization in Strands Agents Tools http_request | Strands | other | excessive permissions | | confirmed |
| 29 Jul 2026 | MCP Ruby SDK Multiple Vulnerabilities Prior to 0.23.0 | Anthropic | other | misconfiguration | | resolved |
| 29 Jul 2026 | Flyto2 Core SSRF vulnerability in HTTP modules | Flyto | workflow | misconfiguration | | confirmed |
| 29 Jul 2026 | MCP Ruby SDK memory exhaustion via unbounded session objects | Anthropic | other | misconfiguration | | resolved |
| 29 Jul 2026 | Pydantic AI Multiple Vulnerabilities in Versions 1.56.0-2.0.0b5 | Pydantic | workflow | excessive permissions | | resolved |