| 28 Jul 2026 | CVE-2026-9680: Alibabacloud RDS OpenAPI MCP Server Exposed | Alibaba Cloud | other | misconfiguration | | reported |
| 28 Jul 2026 | GitHub MCP Server nil pointer dereference denial of service | GitHub | other | misconfiguration | | resolved |
| 27 Jul 2026 | CVE-2026-17534: Kimi Code SSRF via DNS resolution bypass | Moonshot AI | coding | prompt injection | | resolved |
| 26 Jul 2026 | CVE-2026-17433: Improper authorization in nanocoai NanoClaw | nanocoai | other | excessive permissions | | reported |
| 25 Jul 2026 | CVE-2026-66012: SiYuan Missing Authorization in MCP Kernel Endpoint | SiYuan | other | excessive permissions | | confirmed |
| 24 Jul 2026 | BlenderMCP path traversal vulnerability in download_polyhaven_asset | BlenderMCP | coding | prompt injection | | confirmed |
| 24 Jul 2026 | Jan Local API Server CORS Misconfiguration (CVE-2026-66005) | Jan | other | misconfiguration | | resolved |
| 24 Jul 2026 | CVE-2026-50517: Unsafe deserialization in M365 Copilot | Microsoft | other | tool misuse | | reported |
| 24 Jul 2026 | Suna message queue API broken access control vulnerability | Kortix AI | other | excessive permissions | | confirmed |
| 23 Jul 2026 | AgentGPT authorization bypass allows unauthorized task attachment | AgentGPT | workflow | excessive permissions | | reported |
| 23 Jul 2026 | Void path traversal in AI agent file-reading tools | Void | coding | prompt injection | | reported |
| 23 Jul 2026 | APIFold webhook endpoint accepts unauthenticated arbitrary JSON | APIFold | other | misconfiguration | | resolved |
| 22 Jul 2026 | n8n privilege escalation and OAuth authorization vulnerabilities | n8n | other | excessive permissions | | confirmed |
| 22 Jul 2026 | Path traversal in Ansible Lightspeed MCP server via prompt injection | Red Hat | coding | prompt injection | | reported |
| 21 Jul 2026 | mcp-webresearch 0.1.7 SSRF vulnerability via LLM prompt injection | mcp-webresearch | browsing | prompt injection | | reported |
| 21 Jul 2026 | MCP-for-Stata Command Injection via log_file_name Parameter | SepineTam | coding | prompt injection | | confirmed |
| 20 Jul 2026 | AgenticMail Multiple Vulnerabilities Allowing Agent Impersonation and Prompt Injection | AgenticMail | coding | prompt injection | | resolved |
| 20 Jul 2026 | NextCRM MCP API Missing Role Checks in Product Operations | NextCRM | coding | excessive permissions | | confirmed |
| 20 Jul 2026 | nono Sandbox Escape via Unix Domain Socket Access | nolabs | other | misconfiguration | | resolved |
| 20 Jul 2026 | Network-AI MCP SSE Server Missing Authentication | Network-AI | other | misconfiguration | | confirmed |
| 17 Jul 2026 | AI Copilot WordPress plugin OAuth token binding vulnerability | AI Copilot | other | misconfiguration | | reported |
| 17 Jul 2026 | ForgeCode automatically executes arbitrary commands from malicious .mcp.json | tailcallhq | coding | misconfiguration | | reported |
| 17 Jul 2026 | CVE-2026-58195: Agentic-Flow Command Injection via MCP Server Tools | ruvnet | workflow | tool misuse | | resolved |
| 17 Jul 2026 | IBM Langflow OSS code injection via ToolGuard integration | IBM | workflow | excessive permissions | | reported |
| 16 Jul 2026 | Claude Code Action arbitrary code execution via malicious .mcp.json | Anthropic | coding | misconfiguration | | resolved |
| 16 Jul 2026 | Apify MCP Server URL Validation Bypass | Apify | other | misconfiguration | | resolved |
| 16 Jul 2026 | dbt-mcp argument injection and data leak vulnerabilities | dbt Labs | workflow | excessive permissions | | resolved |
| 9 Jul 2026 | n8n and n8n-MCP flaws expose credentials and cross-tenant workflow backups | n8n | workflow | excessive permissions | | resolved |
| 9 Jul 2026 | CVE-2026-15189: SSRF in aerostack-mcp WhatsApp MCP upload_media tool | aerostackdev | workflow | tool misuse | | reported |
| 8 Jul 2026 | LiteLLM MCP endpoint authentication bypass via forged Authorization header (CVE-2026-59822) | BerriAI | other | excessive permissions | | resolved |
| 8 Jul 2026 | CVE-2026-59723: Cline Hub dashboard WebSocket flaw allows remote command execution | Cline | coding | misconfiguration | | resolved |
| 8 Jul 2026 | Researchers trick GitHub's AI coding agent into leaking private repositories | GitHub | coding | prompt injection | | reported |
| 8 Jul 2026 | CVE-2026-59807: Composio SDK path validation bypass enables credential file exfiltration | Composio | workflow | prompt injection | | resolved |
| 6 Jul 2026 | CVE-2026-44934: SUSE Rancher AI Agent leaks API keys in DEBUG logs | SUSE | workflow | data leak | | resolved |
| 6 Jul 2026 | CVE-2026-14898: Codex macOS app image rendering enables prompt-injection data exfiltration | OpenAI | coding | prompt injection | | reported |
| 5 Jul 2026 | CVE-2026-14742: Weak hash in LangGraph task result cache key | langchain-ai | workflow | unknown | | reported |
| 5 Jul 2026 | SSRF in AIAnytime Awesome-MCP-Server wiki-summary tool (CVE-2026-14748) | AIAnytime | workflow | tool misuse | | reported |
| 3 Jul 2026 | CVE-2026-13341: Indirect prompt injection in Kong Konnect MCP server | Kong | workflow | prompt injection | | resolved |
| 2 Jul 2026 | fast-mcp-telegram MCP server auth bypass via path traversal in bearer token (CVE-2026-52830) | leshchenko1979 | other | excessive permissions | | resolved |
| 2 Jul 2026 | CVE-2026-41106: Open redirect in M365 Copilot enables privilege elevation | Microsoft | workflow | misconfiguration | | confirmed |
| 30 Jun 2026 | CVE-2026-10564: SSRF in IBM Langflow OSS RSS and SearXNG components | IBM | workflow | prompt injection | | confirmed |
| 30 Jun 2026 | CVE-2026-9132: GitHub Enterprise Server Copilot diff endpoint exposed private repo code | GitHub | coding | excessive permissions | | resolved |
| 30 Jun 2026 | CVE-2026-58446: Presenton MCP endpoint bypasses session authentication | Presenton | workflow | misconfiguration | | resolved |
| 30 Jun 2026 | CVE-2026-58168: DeepTutor authorization bypass grants unrestricted MCP tool access | HKUDS | other | excessive permissions | | resolved |
| 29 Jun 2026 | CVE-2026-13437: App tokens leaked via AI Agent job API in Devolutions PowerShell Universal | Devolutions | workflow | data leak | | confirmed |
| 29 Jun 2026 | CVE-2026-13524: Improper authorization in Cherry Studio MCP OAuth callback server | CherryHQ | other | excessive permissions | | reported |
| 29 Jun 2026 | Two Claude Code vulnerabilities: world-readable /copy output and worktree sandbox escape | Anthropic | coding | misconfiguration | | resolved |
| 28 Jun 2026 | Flowise Custom MCP env var denylist bypass enables RCE (CVE-2026-58057) | FlowiseAI | workflow | tool misuse | | resolved |
| 26 Jun 2026 | Mattermost Agents MCP server SSRF allows internal data exfiltration (CVE-2026-4339) | Mattermost | workflow | tool misuse | | confirmed |
| 26 Jun 2026 | AutoGPT denial-of-service flaw in AITextSummarizerBlock (CVE-2025-32394) | Significant Gravitas | workflow | unknown | | resolved |