| 26 Jun 2026 | Mattermost Agents MCP server SSRF allows internal data exfiltration (CVE-2026-4339) | Mattermost | workflow | tool misuse | | confirmed |
| 25 Jun 2026 | ToolJet patches three flaws: cross-tenant credential decryption, SSRF and plugin RCE | ToolJet | workflow | excessive permissions | | resolved |
| 25 Jun 2026 | LibreChat: agent file-upload authorization bypass and MCP OAuth token theft flaws | LibreChat | other | excessive permissions | | resolved |
| 25 Jun 2026 | Cursor sandbox escape flaws (CVE-2026-50548/50549) allow writes outside workspace | Cursor | coding | excessive permissions | | resolved |
| 24 Jun 2026 | Multiple command injection and policy bypass flaws in Warp agentic dev environment | Warp | coding | tool misuse | | resolved |
| 24 Jun 2026 | Twenty CRM AI agent monitor IDOR exposed cross-workspace chat history (CVE-2026-55583) | Twenty | other | excessive permissions | | resolved |
| 24 Jun 2026 | Jenkins MCP Server Plugin missing permission check exposes Pipeline replay scripts | Jenkins | workflow | excessive permissions | | confirmed |
| 23 Jun 2026 | CVE-2026-12112: Session hijacking flaw in foreman-mcp-server enables privilege escalation | Red Hat | workflow | misconfiguration | | resolved |
| 23 Jun 2026 | CVE-2026-54316: Claude Code WebFetch allowlist enabled covert data exfiltration | Anthropic | coding | excessive permissions | | resolved |
| 23 Jun 2026 | Multiple Langflow vulnerabilities: unauthenticated RCE, IDOR and path traversal | Langflow | workflow | excessive permissions | | resolved |
| 23 Jun 2026 | Daytona AI code-execution runtime discloses six flaws including cross-tenant access | Daytona | coding | excessive permissions | | resolved |
| 23 Jun 2026 | CVE-2026-55249: Command injection in @rtk-ai/rtk-rewrite OpenClaw plugin | rtk-ai | coding | tool misuse | | confirmed |
| 22 Jun 2026 | CVE-2026-55443: LangChain path traversal allows file disclosure outside intended root | LangChain | workflow | excessive permissions | | resolved |
| 22 Jun 2026 | CVE-2025-66336: SQL injection and authorization bypass in Apache Doris MCP Server | Apache Software Foundation | other | excessive permissions | | resolved |
| 21 Jun 2026 | Two SSRF vulnerabilities in BerriAI LiteLLM MCP server components (<=1.82.2) | BerriAI | other | tool misuse | | reported |
| 20 Jun 2026 | Multiple remote code execution flaws in Flowise AI agent-builder platform | FlowiseAI | workflow | excessive permissions | | resolved |
| 19 Jun 2026 | gin-vue-admin 2.9.1 code-generation/MCP flaw allows remote code execution (CVE-2026-48787) | flipped-aurora | coding | tool misuse | | reported |
| 19 Jun 2026 | line-desktop-mcp HTTP mode exposes unauthenticated MCP endpoint (CVE-2026-49357) | dtwang | workflow | misconfiguration | | resolved |
| 18 Jun 2026 | CVE-2026-49257: mcp-pinot MCP server exposes unauthenticated Pinot access | StarTree (startreedata) | other | misconfiguration | | resolved |
| 18 Jun 2026 | Eclipse Theia AI chat prompt injection and data exfiltration flaws before 1.71.0 | Eclipse Foundation | coding | prompt injection | | resolved |
| 18 Jun 2026 | PraisonAI flaw lets agents run arbitrary shell commands via forced auto-approval | PraisonAI | workflow | excessive permissions | | resolved |
| 18 Jun 2026 | CVE-2026-12045: pgAdmin 4 AI Assistant read-only transaction bypass via prompt injection | pgAdmin | workflow | prompt injection | | resolved |
| 18 Jun 2026 | CVE-2026-11719: Scope enforcement bypass in MCP Toolbox for Databases | Google (googleapis) | workflow | excessive permissions | | confirmed |
| 18 Jun 2026 | Multiple Microsoft Copilot vulnerabilities disclosed, including workspace escape and data exposure | Microsoft | coding | excessive permissions | | confirmed |
| 17 Jun 2026 | Windows-MCP unauthenticated HTTP control plane allowed arbitrary PowerShell execution | CursorTouch | other | misconfiguration | | resolved |
| 17 Jun 2026 | Network-AI MCP SSE server unauthenticated by default (CVE-2026-48814) | Jovancoding | workflow | misconfiguration | | resolved |
| 17 Jun 2026 | CVE-2026-20265: Splunk AI Toolkit allowlist flaw enables agent data exfiltration | Splunk | other | misconfiguration | | resolved |
| 17 Jun 2026 | Pydantic AI cloud-metadata blocklist bypass via IPv6 transition addresses (CVE-2026-48782) | Pydantic | workflow | tool misuse | | resolved |
| 16 Jun 2026 | CVE-2026-53840: OpenClaw leaks custom headers via MCP cross-origin redirects | OpenClaw | other | data leak | | resolved |
| 15 Jun 2026 | CVE-2026-12203: Unauthenticated data exposure in HKUDS AI-Trader research export | HKUDS | other | excessive permissions | | resolved |
| 15 Jun 2026 | Cursor Desktop ran workspace-defined Claude hooks without user approval (CVE-2026-48124) | Cursor | coding | excessive permissions | | resolved |
| 13 Jun 2026 | browse-mcp Path Traversal and Arbitrary File Write | That1Drifter | browsing | excessive permissions | | resolved |
| 12 Jun 2026 | CVE-2026-50287: AgenticMail MCP server HTTP endpoint lacks authentication | AgenticMail | other | misconfiguration | | resolved |
| 11 Jun 2026 | CVE-2026-47250: mcp-server-kubernetes kubectl_generic allows token exfiltration via log prompt injection | Flux159 | workflow | prompt injection | | resolved |
| 11 Jun 2026 | mcp-server-kubernetes access controls bypassable at tool execution layer (CVE-2026-46519) | Flux159 | workflow | excessive permissions | | resolved |
| 9 Jun 2026 | CVE-2026-45482: Path traversal in GitHub Copilot and Visual Studio Code | Microsoft | coding | unknown | | confirmed |
| 4 Jun 2026 | Injection flaws in Microsoft Copilot products allow info disclosure and code execution | Microsoft | other | unknown | | confirmed |
| 2 Jun 2026 | CVE-2026-42073: OpenClaude MCP OAuth state check bypass allows callback server shutdown | Gitlawb | coding | unknown | | resolved |
| 2 Jun 2026 | LibreChat MCP integration flaws leak server secrets and allow cross-agent file deletion | LibreChat | other | data leak | | resolved |
| 1 Jun 2026 | Langroid SQLChatAgent prompt injection enables RCE on database host (CVE-2026-25879) | Langroid | other | prompt injection | | resolved |
| 1 Jun 2026 | SSRF in horizon921 mcpilot 0.1.0 MCP API call endpoint (CVE-2026-10280) | horizon921 | workflow | tool misuse | | reported |
| 29 May 2026 | CVE-2026-45312: RAGFlow Jinja2 template injection enables remote code execution | InfiniFlow | workflow | prompt injection | | confirmed |
| 29 May 2026 | FastGPT SSRF and code sandbox escape flaws fixed in 4.15.0-beta1 | labring | workflow | misconfiguration | | resolved |
| 29 May 2026 | n8n-MCP flaws leak telemetry data and misroute multi-tenant n8n API calls | czlonkowski (n8n-mcp project) | workflow | data leak | | resolved |
| 29 May 2026 | CVE-2026-45555: RCE in Roslyn CodeLens MCP Server via unchecked analyzer DLL loading | MarcelRoozekrans | coding | supply chain | | resolved |
| 29 May 2026 | jqwik library contained hidden prompt injection telling AI coding agents to delete app output | jqwik | coding | prompt injection | | reported |
| 28 May 2026 | AnythingLLM agent filesystem skills allow command execution and path escape | Mintplex Labs | workflow | tool misuse | | resolved |
| 27 May 2026 | CVE-2026-44830: Nocturne Memory MCP server auth bypass exposes agent memory | Dataojitori | other | misconfiguration | | resolved |
| 27 May 2026 | Gryph AI coding agent security layer logs sensitive file content (CVE-2026-45046) | SafeDep | coding | data leak | | resolved |
| 26 May 2026 | CVE-2026-44450: Lumiverse MCP server endpoint allows authenticated remote code execution | prolix-oc | other | excessive permissions | | resolved |