Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Incident database

Structured records of AI agent security incidents: what happened, which vendor and agent type, the root cause, and every source we used. Filter, browse, or download as CSV.

Incidents by month, 2026 · 434 total · click a month to filter
Jan 2026: 23 incidents23JanFeb 2026: 26 incidents26FebMar 2026: 46 incidents46MarApr 2026: 46 incidents46AprMay 2026: 52 incidents52MayJun 2026: 51 incidents51JunJul 2026: 45 incidents45JulAug 2026: 82 incidents82AugSep 2026: 63 incidents63SepOct 2026: 0 incidents0OctNov 2026: 0 incidents0NovDec 2026: 0 incidents0Dec

453 incidents

Incident dateIncidentVendorAgentRoot causeSeverityStatus
26 Jun 2026Mattermost Agents MCP server SSRF allows internal data exfiltration (CVE-2026-4339)Mattermostworkflowtool misuseconfirmed
25 Jun 2026ToolJet patches three flaws: cross-tenant credential decryption, SSRF and plugin RCEToolJetworkflowexcessive permissionsresolved
25 Jun 2026LibreChat: agent file-upload authorization bypass and MCP OAuth token theft flawsLibreChatotherexcessive permissionsresolved
25 Jun 2026Cursor sandbox escape flaws (CVE-2026-50548/50549) allow writes outside workspaceCursorcodingexcessive permissionsresolved
24 Jun 2026Multiple command injection and policy bypass flaws in Warp agentic dev environmentWarpcodingtool misuseresolved
24 Jun 2026Twenty CRM AI agent monitor IDOR exposed cross-workspace chat history (CVE-2026-55583)Twentyotherexcessive permissionsresolved
24 Jun 2026Jenkins MCP Server Plugin missing permission check exposes Pipeline replay scriptsJenkinsworkflowexcessive permissionsconfirmed
23 Jun 2026CVE-2026-12112: Session hijacking flaw in foreman-mcp-server enables privilege escalationRed Hatworkflowmisconfigurationresolved
23 Jun 2026CVE-2026-54316: Claude Code WebFetch allowlist enabled covert data exfiltrationAnthropiccodingexcessive permissionsresolved
23 Jun 2026Multiple Langflow vulnerabilities: unauthenticated RCE, IDOR and path traversalLangflowworkflowexcessive permissionsresolved
23 Jun 2026Daytona AI code-execution runtime discloses six flaws including cross-tenant accessDaytonacodingexcessive permissionsresolved
23 Jun 2026CVE-2026-55249: Command injection in @rtk-ai/rtk-rewrite OpenClaw pluginrtk-aicodingtool misuseconfirmed
22 Jun 2026CVE-2026-55443: LangChain path traversal allows file disclosure outside intended rootLangChainworkflowexcessive permissionsresolved
22 Jun 2026CVE-2025-66336: SQL injection and authorization bypass in Apache Doris MCP ServerApache Software Foundationotherexcessive permissionsresolved
21 Jun 2026Two SSRF vulnerabilities in BerriAI LiteLLM MCP server components (<=1.82.2)BerriAIothertool misusereported
20 Jun 2026Multiple remote code execution flaws in Flowise AI agent-builder platformFlowiseAIworkflowexcessive permissionsresolved
19 Jun 2026gin-vue-admin 2.9.1 code-generation/MCP flaw allows remote code execution (CVE-2026-48787)flipped-auroracodingtool misusereported
19 Jun 2026line-desktop-mcp HTTP mode exposes unauthenticated MCP endpoint (CVE-2026-49357)dtwangworkflowmisconfigurationresolved
18 Jun 2026CVE-2026-49257: mcp-pinot MCP server exposes unauthenticated Pinot accessStarTree (startreedata)othermisconfigurationresolved
18 Jun 2026Eclipse Theia AI chat prompt injection and data exfiltration flaws before 1.71.0Eclipse Foundationcodingprompt injectionresolved
18 Jun 2026PraisonAI flaw lets agents run arbitrary shell commands via forced auto-approvalPraisonAIworkflowexcessive permissionsresolved
18 Jun 2026CVE-2026-12045: pgAdmin 4 AI Assistant read-only transaction bypass via prompt injectionpgAdminworkflowprompt injectionresolved
18 Jun 2026CVE-2026-11719: Scope enforcement bypass in MCP Toolbox for DatabasesGoogle (googleapis)workflowexcessive permissionsconfirmed
18 Jun 2026Multiple Microsoft Copilot vulnerabilities disclosed, including workspace escape and data exposureMicrosoftcodingexcessive permissionsconfirmed
17 Jun 2026Windows-MCP unauthenticated HTTP control plane allowed arbitrary PowerShell executionCursorTouchothermisconfigurationresolved
17 Jun 2026Network-AI MCP SSE server unauthenticated by default (CVE-2026-48814)Jovancodingworkflowmisconfigurationresolved
17 Jun 2026CVE-2026-20265: Splunk AI Toolkit allowlist flaw enables agent data exfiltrationSplunkothermisconfigurationresolved
17 Jun 2026Pydantic AI cloud-metadata blocklist bypass via IPv6 transition addresses (CVE-2026-48782)Pydanticworkflowtool misuseresolved
16 Jun 2026CVE-2026-53840: OpenClaw leaks custom headers via MCP cross-origin redirectsOpenClawotherdata leakresolved
15 Jun 2026CVE-2026-12203: Unauthenticated data exposure in HKUDS AI-Trader research exportHKUDSotherexcessive permissionsresolved
15 Jun 2026Cursor Desktop ran workspace-defined Claude hooks without user approval (CVE-2026-48124)Cursorcodingexcessive permissionsresolved
13 Jun 2026browse-mcp Path Traversal and Arbitrary File WriteThat1Drifterbrowsingexcessive permissionsresolved
12 Jun 2026CVE-2026-50287: AgenticMail MCP server HTTP endpoint lacks authenticationAgenticMailothermisconfigurationresolved
11 Jun 2026CVE-2026-47250: mcp-server-kubernetes kubectl_generic allows token exfiltration via log prompt injectionFlux159workflowprompt injectionresolved
11 Jun 2026mcp-server-kubernetes access controls bypassable at tool execution layer (CVE-2026-46519)Flux159workflowexcessive permissionsresolved
9 Jun 2026CVE-2026-45482: Path traversal in GitHub Copilot and Visual Studio CodeMicrosoftcodingunknownconfirmed
4 Jun 2026Injection flaws in Microsoft Copilot products allow info disclosure and code executionMicrosoftotherunknownconfirmed
2 Jun 2026CVE-2026-42073: OpenClaude MCP OAuth state check bypass allows callback server shutdownGitlawbcodingunknownresolved
2 Jun 2026LibreChat MCP integration flaws leak server secrets and allow cross-agent file deletionLibreChatotherdata leakresolved
1 Jun 2026Langroid SQLChatAgent prompt injection enables RCE on database host (CVE-2026-25879)Langroidotherprompt injectionresolved
1 Jun 2026SSRF in horizon921 mcpilot 0.1.0 MCP API call endpoint (CVE-2026-10280)horizon921workflowtool misusereported
29 May 2026CVE-2026-45312: RAGFlow Jinja2 template injection enables remote code executionInfiniFlowworkflowprompt injectionconfirmed
29 May 2026FastGPT SSRF and code sandbox escape flaws fixed in 4.15.0-beta1labringworkflowmisconfigurationresolved
29 May 2026n8n-MCP flaws leak telemetry data and misroute multi-tenant n8n API callsczlonkowski (n8n-mcp project)workflowdata leakresolved
29 May 2026CVE-2026-45555: RCE in Roslyn CodeLens MCP Server via unchecked analyzer DLL loadingMarcelRoozekranscodingsupply chainresolved
29 May 2026jqwik library contained hidden prompt injection telling AI coding agents to delete app outputjqwikcodingprompt injectionreported
28 May 2026AnythingLLM agent filesystem skills allow command execution and path escapeMintplex Labsworkflowtool misuseresolved
27 May 2026CVE-2026-44830: Nocturne Memory MCP server auth bypass exposes agent memoryDataojitoriothermisconfigurationresolved
27 May 2026Gryph AI coding agent security layer logs sensitive file content (CVE-2026-45046)SafeDepcodingdata leakresolved
26 May 2026CVE-2026-44450: Lumiverse MCP server endpoint allows authenticated remote code executionprolix-ocotherexcessive permissionsresolved