Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Incident database

Structured records of AI agent security incidents: what happened, which vendor and agent type, the root cause, and every source we used. Filter, browse, or download as CSV.

Incidents by month, 2026 · 434 total · click a month to filter
Jan 2026: 23 incidents23JanFeb 2026: 26 incidents26FebMar 2026: 46 incidents46MarApr 2026: 46 incidents46AprMay 2026: 52 incidents52MayJun 2026: 51 incidents51JunJul 2026: 45 incidents45JulAug 2026: 82 incidents82AugSep 2026: 63 incidents63SepOct 2026: 0 incidents0OctNov 2026: 0 incidents0NovDec 2026: 0 incidents0Dec

453 incidents

Incident dateIncidentVendorAgentRoot causeSeverityStatus
28 Jul 2026CVE-2026-9680: Alibabacloud RDS OpenAPI MCP Server ExposedAlibaba Cloudothermisconfigurationreported
28 Jul 2026GitHub MCP Server nil pointer dereference denial of serviceGitHubothermisconfigurationresolved
27 Jul 2026CVE-2026-17534: Kimi Code SSRF via DNS resolution bypassMoonshot AIcodingprompt injectionresolved
26 Jul 2026CVE-2026-17433: Improper authorization in nanocoai NanoClawnanocoaiotherexcessive permissionsreported
25 Jul 2026CVE-2026-66012: SiYuan Missing Authorization in MCP Kernel EndpointSiYuanotherexcessive permissionsconfirmed
24 Jul 2026BlenderMCP path traversal vulnerability in download_polyhaven_assetBlenderMCPcodingprompt injectionconfirmed
24 Jul 2026Jan Local API Server CORS Misconfiguration (CVE-2026-66005)Janothermisconfigurationresolved
24 Jul 2026CVE-2026-50517: Unsafe deserialization in M365 CopilotMicrosoftothertool misusereported
24 Jul 2026Suna message queue API broken access control vulnerabilityKortix AIotherexcessive permissionsconfirmed
23 Jul 2026AgentGPT authorization bypass allows unauthorized task attachmentAgentGPTworkflowexcessive permissionsreported
23 Jul 2026Void path traversal in AI agent file-reading toolsVoidcodingprompt injectionreported
23 Jul 2026APIFold webhook endpoint accepts unauthenticated arbitrary JSONAPIFoldothermisconfigurationresolved
22 Jul 2026n8n privilege escalation and OAuth authorization vulnerabilitiesn8notherexcessive permissionsconfirmed
22 Jul 2026Path traversal in Ansible Lightspeed MCP server via prompt injectionRed Hatcodingprompt injectionreported
21 Jul 2026mcp-webresearch 0.1.7 SSRF vulnerability via LLM prompt injectionmcp-webresearchbrowsingprompt injectionreported
21 Jul 2026MCP-for-Stata Command Injection via log_file_name ParameterSepineTamcodingprompt injectionconfirmed
20 Jul 2026AgenticMail Multiple Vulnerabilities Allowing Agent Impersonation and Prompt InjectionAgenticMailcodingprompt injectionresolved
20 Jul 2026NextCRM MCP API Missing Role Checks in Product OperationsNextCRMcodingexcessive permissionsconfirmed
20 Jul 2026nono Sandbox Escape via Unix Domain Socket Accessnolabsothermisconfigurationresolved
20 Jul 2026Network-AI MCP SSE Server Missing AuthenticationNetwork-AIothermisconfigurationconfirmed
17 Jul 2026AI Copilot WordPress plugin OAuth token binding vulnerabilityAI Copilotothermisconfigurationreported
17 Jul 2026ForgeCode automatically executes arbitrary commands from malicious .mcp.jsontailcallhqcodingmisconfigurationreported
17 Jul 2026CVE-2026-58195: Agentic-Flow Command Injection via MCP Server Toolsruvnetworkflowtool misuseresolved
17 Jul 2026IBM Langflow OSS code injection via ToolGuard integrationIBMworkflowexcessive permissionsreported
16 Jul 2026Claude Code Action arbitrary code execution via malicious .mcp.jsonAnthropiccodingmisconfigurationresolved
16 Jul 2026Apify MCP Server URL Validation BypassApifyothermisconfigurationresolved
16 Jul 2026dbt-mcp argument injection and data leak vulnerabilitiesdbt Labsworkflowexcessive permissionsresolved
9 Jul 2026n8n and n8n-MCP flaws expose credentials and cross-tenant workflow backupsn8nworkflowexcessive permissionsresolved
9 Jul 2026CVE-2026-15189: SSRF in aerostack-mcp WhatsApp MCP upload_media toolaerostackdevworkflowtool misusereported
8 Jul 2026LiteLLM MCP endpoint authentication bypass via forged Authorization header (CVE-2026-59822)BerriAIotherexcessive permissionsresolved
8 Jul 2026CVE-2026-59723: Cline Hub dashboard WebSocket flaw allows remote command executionClinecodingmisconfigurationresolved
8 Jul 2026Researchers trick GitHub's AI coding agent into leaking private repositoriesGitHubcodingprompt injectionreported
8 Jul 2026CVE-2026-59807: Composio SDK path validation bypass enables credential file exfiltrationComposioworkflowprompt injectionresolved
6 Jul 2026CVE-2026-44934: SUSE Rancher AI Agent leaks API keys in DEBUG logsSUSEworkflowdata leakresolved
6 Jul 2026CVE-2026-14898: Codex macOS app image rendering enables prompt-injection data exfiltrationOpenAIcodingprompt injectionreported
5 Jul 2026CVE-2026-14742: Weak hash in LangGraph task result cache keylangchain-aiworkflowunknownreported
5 Jul 2026SSRF in AIAnytime Awesome-MCP-Server wiki-summary tool (CVE-2026-14748)AIAnytimeworkflowtool misusereported
3 Jul 2026CVE-2026-13341: Indirect prompt injection in Kong Konnect MCP serverKongworkflowprompt injectionresolved
2 Jul 2026fast-mcp-telegram MCP server auth bypass via path traversal in bearer token (CVE-2026-52830)leshchenko1979otherexcessive permissionsresolved
2 Jul 2026CVE-2026-41106: Open redirect in M365 Copilot enables privilege elevationMicrosoftworkflowmisconfigurationconfirmed
30 Jun 2026CVE-2026-10564: SSRF in IBM Langflow OSS RSS and SearXNG componentsIBMworkflowprompt injectionconfirmed
30 Jun 2026CVE-2026-9132: GitHub Enterprise Server Copilot diff endpoint exposed private repo codeGitHubcodingexcessive permissionsresolved
30 Jun 2026CVE-2026-58446: Presenton MCP endpoint bypasses session authenticationPresentonworkflowmisconfigurationresolved
30 Jun 2026CVE-2026-58168: DeepTutor authorization bypass grants unrestricted MCP tool accessHKUDSotherexcessive permissionsresolved
29 Jun 2026CVE-2026-13437: App tokens leaked via AI Agent job API in Devolutions PowerShell UniversalDevolutionsworkflowdata leakconfirmed
29 Jun 2026CVE-2026-13524: Improper authorization in Cherry Studio MCP OAuth callback serverCherryHQotherexcessive permissionsreported
29 Jun 2026Two Claude Code vulnerabilities: world-readable /copy output and worktree sandbox escapeAnthropiccodingmisconfigurationresolved
28 Jun 2026Flowise Custom MCP env var denylist bypass enables RCE (CVE-2026-58057)FlowiseAIworkflowtool misuseresolved
26 Jun 2026Mattermost Agents MCP server SSRF allows internal data exfiltration (CVE-2026-4339)Mattermostworkflowtool misuseconfirmed
26 Jun 2026AutoGPT denial-of-service flaw in AITextSummarizerBlock (CVE-2025-32394)Significant Gravitasworkflowunknownresolved