28 Jul 2026 · Alibaba Cloud
Alibabacloud RDS OpenAPI MCP server improperly exposes MCP endpoints listening on all network interfaces by default, allowing remote attackers to invoke exposed MCP tools.
other·misconfiguration·
28 Jul 2026 · GitHub
GitHub MCP Server prior to version 1.1.0 is vulnerable to a denial of service attack due to improper nil checking in the CompletionsHandler function. An unauthenticated client can crash the server by sending a completion request with a missing or empty ref field.
other·misconfiguration·
27 Jul 2026 · Moonshot AI
Kimi Code before version 0.27.0 has a Server-Side Request Forgery (SSRF) vulnerability in its FetchURL function that can be exploited via prompt injection. An attacker can bypass the hostname denylist by using crafted public hostnames that resolve to internal addresses or URLs that redirect to internal targets.
coding·prompt injection·
26 Jul 2026 · nanocoai
A vulnerability in nanocoai NanoClaw up to version 2.0.64 allows improper authorization through manipulation of the createChatSdkBridge.setup function in the MCP Server Approval component. The exploit is now public and requires local access.
other·excessive permissions·
25 Jul 2026 · SiYuan
SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint that, when Publish server is enabled in anonymous mode, allows remote unauthenticated attackers to read sensitive configuration files, write arbitrary files, and plant malicious plugins leading to administrator takeover.
other·excessive permissions·
24 Jul 2026 · BlenderMCP
BlenderMCP before commit 30a3308 contains a path traversal vulnerability in the download_polyhaven_asset method that allows attackers to write arbitrary files and achieve persistent code execution through MITM attacks or prompt injection.
coding·prompt injection·
24 Jul 2026 · Jan
Jan versions through 0.8.4 contain a CORS misconfiguration vulnerability in the local API server that allows network-adjacent attackers to bypass trusted host restrictions and access the unauthenticated API to perform inference, enumerate models, invoke MCP tools, and read cross-origin responses.
other·misconfiguration·
24 Jul 2026 · Microsoft
Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.
other·tool misuse·
24 Jul 2026 · Kortix AI
Suna before version 0.9.102 contains a broken access control vulnerability in its message queue API that allows authenticated attackers to access queue resources belonging to other users, read their prompt queues, and inject malicious prompts into their AI agent sessions.
other·excessive permissions·
23 Jul 2026 · AgentGPT
AgentGPT through version 1.0.0 contains an authorization bypass vulnerability that allows authenticated users to attach tasks to another user's agent run by supplying a target run_id without ownership verification. Attackers can corrupt task history, exhaust loop budgets, and drive LLM costs against victims.
workflow·excessive permissions·
23 Jul 2026 · Void
Void through version 1.3.4 contains a path traversal vulnerability in AI agent file-reading tools that allows network-adjacent attackers to read arbitrary files outside the workspace by injecting instructions into content the agent processes. Attackers can silently exfiltrate sensitive files such as SSH keys or cloud credentials.
coding·prompt injection·
23 Jul 2026 · APIFold
APIFold's webhook endpoint fails to validate signatures or require authentication, allowing unauthenticated attackers to inject arbitrary payloads into Redis and PostgreSQL. The vulnerability was patched in commit 7f19b52280f414f57af2b79a95333d1c8fbeece5.
other·misconfiguration·
22 Jul 2026 · n8n
n8n versions before 2.30.1 contain two critical vulnerabilities in AI Agents and OAuth 2.1 features that allow users to escalate privileges, execute arbitrary nodes, access credential secrets, and bypass workflow authorization checks.
other·excessive permissions·
22 Jul 2026 · Red Hat
A path traversal vulnerability in Ansible Lightspeed's Model Context Protocol server allows attackers to manipulate AI agents through indirect prompt injection, enabling unauthorized file writes and potential system compromise.
coding·prompt injection·
21 Jul 2026 · mcp-webresearch
A server-side request forgery vulnerability in mcp-webresearch 0.1.7 allows attackers to use prompt injection to steer an LLM into accessing internal network services and cloud metadata endpoints through the visit_page tool, exposing sensitive credentials.
browsing·prompt injection·
21 Jul 2026 · SepineTam
MCP-for-Stata versions prior to 1.17.3 are vulnerable to command injection through the unsanitized log_file_name parameter in the stata_do API and CLI. An attacker can inject arbitrary Stata commands by crafting a malicious log_file_name parameter.
coding·prompt injection·
20 Jul 2026 · AgenticMail
Multiple vulnerabilities in AgenticMail packages allow AI agents to impersonate other agents, enumerate tasks, and execute prompt injection attacks. Fixes have been released in versions 0.9.32 and later.
coding·prompt injection·
20 Jul 2026 · NextCRM
NextCRM version 0.12.1 fails to enforce role-based access controls in its MCP product tools API, allowing any authenticated low-privileged user with an MCP API token to create, modify, archive, or delete products in the shared CRM catalog. The vulnerability was fixed in version 0.12.3.
coding·excessive permissions·
20 Jul 2026 · nolabs
The nono AI agent sandbox software prior to version 0.55.0 allowed access to local Unix domain sockets, enabling sandbox escape through the systemd dbus socket. Version 0.55.0 patches the vulnerability.
other·misconfiguration·
20 Jul 2026 · Network-AI
Network-AI versions prior to 5.4.5 have an MCP SSE server that defaults to empty authentication and allows CORS, enabling unauthenticated attackers to invoke all 22 exposed MCP tools via cross-origin requests.
other·misconfiguration·
17 Jul 2026 · AI Copilot
The AI Copilot WordPress plugin before version 1.5.4 fails to bind OAuth access tokens to specific WordPress users, allowing unauthenticated attackers to complete a public OAuth flow and execute privileged MCP tools as an administrator, including arbitrary user creation and role escalation.
other·misconfiguration·
17 Jul 2026 · tailcallhq
ForgeCode, an AI pair-programming CLI, automatically loads and executes MCP servers defined in a repository's .mcp.json file without user confirmation, allowing arbitrary code execution when developers evaluate untrusted repositories.
coding·misconfiguration·
17 Jul 2026 · ruvnet
Agentic-Flow prior to version 2.0.14 contains a command injection vulnerability in MCP server tools where attacker-controlled parameters are directly interpolated into shell commands passed to execSync(), allowing arbitrary OS command execution with server privileges.
workflow·tool misuse·
17 Jul 2026 · IBM
IBM Langflow OSS versions 1.0.0 through 1.10.0 contain a code injection vulnerability in the ToolGuard component that allows authenticated users to bypass custom component restrictions and achieve arbitrary Python code execution on the backend.
workflow·excessive permissions·
16 Jul 2026 · Anthropic
A vulnerability in Claude Code Action prior to version 1.0.74 allowed attackers to achieve arbitrary code execution on GitHub Actions runners by including a malicious .mcp.json file in pull requests, potentially exfiltrating workflow secrets like API keys and tokens.
coding·misconfiguration·
16 Jul 2026 · Apify
The Apify MCP server's fetch-apify-docs tool failed to properly validate documentation URLs, allowing attackers to bypass domain allowlisting and return arbitrary content to AI agents. The vulnerability was fixed in version 0.9.21.
other·misconfiguration·
16 Jul 2026 · dbt Labs
dbt-mcp versions prior to 1.17.1 contained two vulnerabilities: unsanitized command-line argument injection allowing MCP clients to inject dbt flags, and unredacted telemetry transmission of sensitive query parameters and variables to dbt Labs.
workflow·excessive permissions·
9 Jul 2026 · n8n
Three disclosed vulnerabilities in the n8n workflow automation ecosystem allowed AI Agents to bypass a credential's Allowed HTTP Request Domains restriction via an MCP tool pointed at an attacker-controlled URL (CVE-2026-59207), and let authenticated tenants in n8n-MCP multi-tenant HTTP mode read or delete other tenants' workflow version backups containing credential references and authorization headers (CVE-2026-54052, CVE-2026-55608). All issues were fixed in updated releases.
workflow·excessive permissions·
9 Jul 2026 · aerostackdev
A server-side request forgery vulnerability was reported in aerostackdev's aerostack-mcp, where the media_url argument of the upload_media function in the mcp-whatsapp component can be manipulated remotely. The project, which uses rolling releases, was notified via an issue report but has not responded.
workflow·tool misuse·
8 Jul 2026 · BerriAI
Prior to version 1.84.0, LiteLLM's MCP Streamable HTTP endpoint let an unauthenticated attacker send a fabricated Authorization header that triggered an OAuth2 passthrough fallback, substituting an empty UserAPIKeyAuth() object for failed key validation and granting access to MCP tooling without a valid LiteLLM key. The issue was fixed in release 1.84.0.
other·excessive permissions·
8 Jul 2026 · Cline
Prior to version 3.0.30, the Cline Hub dashboard server launched by the `cline dashboard` command accepted WebSocket connections on /browser without validating the Origin header, and permitted unauthorized browser requests when ROOM_SECRET was unset on local 127.0.0.1 binds. Malicious websites could send desktopCommand frames to read workspace state, alter MCP and provider settings, and trigger command execution; fixed in 3.0.30.
coding·misconfiguration·
8 Jul 2026 · GitHub
Security researchers at Noma Security published research dubbed "GitLost" describing how they manipulated GitHub's AI agent into exposing the contents of private repositories. The disclosure was widely discussed on Hacker News.
coding·prompt injection·
8 Jul 2026 · Composio
Composio SDK versions before 0.2.32-beta.283 lack an assertSafeFileUploadPath check in the readFileFromDisk function of tool-file-uploads.ts, letting attackers use prompt injection to manipulate file_uploadable parameters and make the CLI upload sensitive files such as SSH private keys to attacker-controlled storage. The issue was fixed in release 0.2.32-beta.283.
workflow·prompt injection·
6 Jul 2026 · SUSE
An information disclosure flaw in SUSE Rancher AI Agent 1.0 before 1.0.2 causes API keys and LLM response text containing potentially sensitive data to be written into logfiles when the DEBUG loglevel is set, allowing local attackers to misuse the exposed data or credentials.
workflow·data leak·
6 Jul 2026 · OpenAI
The OpenAI Codex desktop app for macOS automatically fetched remote images referenced in Markdown model responses, allowing an indirect prompt injection to encode session secrets into an image URL that was sent to an attacker-controlled server without user interaction. Exploitation could leak API keys, source code and data returned by connected tools.
coding·prompt injection·
5 Jul 2026 · langchain-ai
A vulnerability in langchain-ai LangGraph up to version 1.2.4 involves the _freeze function in the Task Result Cache (libs/langgraph/langgraph/_internal/_cache.py), where manipulation of the default_cache_key argument leads to use of a weak hash. The issue can be exploited remotely but with high attack complexity, and a fix pull request is still awaiting acceptance.
workflow·unknown·
5 Jul 2026 · AIAnytime
A server-side request forgery flaw in the mcp-wiki/wiki-summary component of AIAnytime's Awesome-MCP-Server allows remote attackers to manipulate the 'url' argument in mcp-wiki/src/mcp_wiki/server.py. An exploit has been published and the project has not responded to the issue report.
workflow·tool misuse·
3 Jul 2026 · Kong
A vulnerability in the Kong Konnect Model Context Protocol (MCP) server before version 1.0.0 allows a remote attacker to carry out an indirect prompt injection attack and cause the server to execute unintended API requests. The issue is addressed in version 1.0.0 and documented in a GitHub security advisory.
workflow·prompt injection·
2 Jul 2026 · leshchenko1979
Versions of the fast-mcp-telegram Telegram MCP server prior to 0.19.1 built session-file paths directly from HTTP Bearer tokens without normalising path separators, letting a remote client authenticate as the default legacy Telegram session using a token such as '../fast-mcp-telegram/telegram'. The flaw bypassed the reserved session-name control and was fixed in release 0.19.1.
other·excessive permissions·
2 Jul 2026 · Microsoft
A URL redirection to untrusted site ('open redirect') vulnerability in Microsoft M365 Copilot allows an unauthorized attacker to elevate privileges over a network. The issue is tracked as CVE-2026-41106 and documented in Microsoft's security update guide.
workflow·misconfiguration·
30 Jun 2026 · IBM
IBM Langflow OSS versions 1.0.0 through 1.9.6 contain a server-side request forgery flaw in the legacy RSSReaderComponent and SearXNG component, which make unvalidated HTTP requests to user-controlled URLs and bypass SSRF protections added in 1.9.3. An authenticated attacker, or an attacker using prompt injection against agentic workflows where the components are exposed as tools, can reach internal resources such as cloud metadata services and potentially exfiltrate IAM credentials.
workflow·prompt injection·
30 Jun 2026 · GitHub
A missing authorization flaw in the GitHub Copilot pull request description diff summary endpoint in GitHub Enterprise Server let any authenticated user render cross-repository comparison diffs and read source code from private repositories they had no access to. It affected all versions prior to 3.21 and was fixed in 3.17.17, 3.18.11, 3.19.8 and 3.20.4.
coding·excessive permissions·
30 Jun 2026 · Presenton
Presenton before 0.8.8-beta exposed its bundled MCP server unauthenticated at /mcp because the nginx front-end did not apply the auth_request gate and the MCP server auto-minted a valid internal session token. Remote unauthenticated attackers could invoke MCP tools such as generate_presentation, consuming the operator's LLM API keys and creating presentations in their instance.
workflow·misconfiguration·
30 Jun 2026 · HKUDS
DeepTutor before 1.4.10 contained an authorization bypass in its multi-user tool access control, where allowed_mcp_tools returned None instead of a denial when mcp_tools was omitted from a user's grant. Low-privilege users or prompt-injected content in a user session could enumerate and invoke any configured MCP tool, including filesystem, shell, and browser servers.
other·excessive permissions·
29 Jun 2026 · Devolutions
Devolutions PowerShell Universal 2026.2.0 serializes App Tokens in plaintext within AI Agent job API responses, allowing an authenticated user with AI Agent read access to obtain reusable, potentially higher-privileged authentication tokens.
workflow·data leak·
29 Jun 2026 · CherryHQ
A vulnerability in CherryHQ cherry-studio up to version 1.9.6 affects the MCP OAuth Local Callback Server (src/main/services/mcp/oauth/callback.ts), where manipulation of the 'code' argument leads to improper authorization and can be triggered remotely. The exploit has been publicly disclosed and a fix pull request is still awaiting acceptance.
other·excessive permissions·
29 Jun 2026 · Anthropic
Anthropic's Claude Code agentic coding tool had two disclosed flaws: CVE-2026-46406, where the /copy command wrote responses to a predictable world-readable path (/tmp/claude/response.md) allowing local users to read secrets or plant symlinks to overwrite files, and CVE-2026-55607, where worktree handling allowed git directory confusion and symlink abuse to overwrite home-directory files and execute code outside the seatbelt sandbox. Both were fixed in later releases (2.1.128 and 2.1.163 respectively).
coding·misconfiguration·
28 Jun 2026 · FlowiseAI
Flowise before 3.1.3 compared Custom MCP stdio environment variable names against a denylist case-sensitively, so on Windows an authenticated user could supply 'node_options' to bypass the NODE_OPTIONS block. This allowed injection of NODE_OPTIONS --require and arbitrary code execution in the Flowise server context.
workflow·tool misuse·
26 Jun 2026 · Mattermost
Mattermost versions 10.11.x <= 10.11.18, 11.6.x <= 11.6.3 and 11.5.x <= 11.5.6 fail to validate attachment URLs against internal or private IP ranges in the Mattermost Agents plugin MCP server. An attacker with access to the MCP server in stdio mode can supply internal URLs as file attachments in post creation requests to perform server-side request forgery and exfiltrate data from internal network services.
workflow·tool misuse·
26 Jun 2026 · Significant Gravitas
A vulnerability in AutoGPT's AITextSummarizerBlock prior to version 0.6.32 allowed malicious users to amplify input (e.g. 10K of content causing ~50G of memory consumption), exhausting server memory and causing denial of service. The issue is fixed in version 0.6.32.
workflow·unknown·