| 26 May 2026 | CVE-2026-44209: SSTI to RCE in banks LLM prompt template library | masci | other | misconfiguration | | resolved |
| 26 May 2026 | CVE-2026-44895: GitLab MCP Server HTTP transport exposes unauthenticated RPC endpoint | yoda-digital | coding | misconfiguration | | resolved |
| 26 May 2026 | LangChain and LangSmith SDK unsafe deserialization of untrusted serialized objects | LangChain | other | excessive permissions | | resolved |
| 24 May 2026 | CVE-2026-9353: Prompt injection flaw in NousResearch hermes-agent Skills Guard | NousResearch | other | prompt injection | | reported |
| 22 May 2026 | Command injection flaws in Microsoft Copilot and M365 Copilot (CVE-2026-41090, CVE-2026-42827) | Microsoft | other | unknown | | confirmed |
| 21 May 2026 | Central Dogma Git mirror disables SSH host-key verification (CVE-2026-11745) | LINE | other | misconfiguration | | confirmed |
| 15 May 2026 | CVE-2026-44717: RCE in MCP Calculate Server via unsanitized eval() | 611711Dark | other | tool misuse | | resolved |
| 15 May 2026 | CVE-2026-45401: SSRF via unvalidated redirects in Open WebUI web retrieval | Open WebUI | browsing | tool misuse | | resolved |
| 15 May 2026 | Microsoft APM agent dependency manager: path traversal and symlink flaws (3 CVEs) | Microsoft | coding | supply chain | | resolved |
| 14 May 2026 | Hatchet cross-tenant data exposure via missing authorization (CVE-2026-42572) | Hatchet | workflow | misconfiguration | | resolved |
| 14 May 2026 | Multiple vulnerabilities disclosed in MCP Registry and rmcp Rust SDK | Model Context Protocol | other | supply chain | | resolved |
| 13 May 2026 | Vercel CLI leaked auth tokens in AI-agent non-interactive command output (CVE-2026-44479) | Vercel | coding | data leak | | resolved |
| 13 May 2026 | GitHub Copilot CLI arbitrary code execution via nested bare git repository (CVE-2026-45033) | GitHub | coding | tool misuse | | resolved |
| 12 May 2026 | CVE-2025-65719: Remote code execution in Kubectl MCP Server v1.1.1 | Open Source Kubectl MCP Server (rohitg00) | other | unknown | | reported |
| 12 May 2026 | CVE-2026-44220: ciguard symlink traversal exposes files outside scan root | Jo-Jo98 (ciguard project) | coding | data leak | | resolved |
| 12 May 2026 | CVE-2026-44246: Prompt injection in nnU-Net GitHub issue-triage agent workflow | MIC-DKFZ | workflow | prompt injection | | resolved |
| 12 May 2026 | Unauthenticated RCE in Code Runner MCP Server HTTP transport (CVE-2026-5029) | | coding | excessive permissions | | reported |
| 12 May 2026 | CVE-2026-42045: LobeChat artifact XSS chains to arbitrary command execution | LobeHub | other | prompt injection | | resolved |
| 12 May 2026 | JunoClaw agent platform: shell command injection and SSRF flaws (CVE-2026-43990/43993) | JunoClaw | workflow | tool misuse | | resolved |
| 12 May 2026 | JunoClaw agentic AI platform patches three MCP tool vulnerabilities | JunoClaw | other | data leak | | resolved |
| 12 May 2026 | OpenAI agent swarm tied to May 2026 RubyGems supply chain attack | OpenAI | other | supply chain | | confirmed |
| 12 May 2026 | CVE-2026-42260: SSRF in Open-WebSearch MCP server URL safety checks | Aas-ee | browsing | misconfiguration | | resolved |
| 12 May 2026 | Langflow path traversal in Knowledge Bases API allows arbitrary directory deletion | Langflow | workflow | excessive permissions | | resolved |
| 11 May 2026 | CVE-2026-30635: Command injection in automagik-genie 2.5.27 MCP server | | other | tool misuse | | reported |
| 11 May 2026 | CVE-2026-42869: Hardcoded JWT secret in SOCFortress CoPilot allows admin token forgery | SOCFortress | other | misconfiguration | | resolved |
| 11 May 2026 | CVE-2026-43901: Wireshark MCP server allows arbitrary export path via unsandboxed tool | bx33661 (Wireshark-MCP project) | other | excessive permissions | | confirmed |
| 11 May 2026 | CVE-2026-31246: Command injection in GPT-Pilot Executor.run() enables RCE | Pythagora-io | coding | tool misuse | | reported |
| 11 May 2026 | CVE-2026-8319: Remote resource exhaustion in aiwaves-cn agents memory recall function | aiwaves-cn | other | unknown | | reported |
| 11 May 2026 | DeepChat CVE-2026-43899: external URL handler bypass enables code execution | ThinkInAIXYZ | other | misconfiguration | | resolved |
| 8 May 2026 | LiteLLM MCP preview endpoints allow authenticated users to run commands on proxy host | BerriAI | other | excessive permissions | | resolved |
| 8 May 2026 | PromptHub SSRF via IPv6 bypass in skills fetch-remote endpoint (CVE-2026-42261) | PromptHub | workflow | misconfiguration | | resolved |
| 8 May 2026 | Multiple vulnerabilities disclosed in FastGPT AI agent platform, including sandbox RCE | labring | workflow | misconfiguration | | confirmed |
| 8 May 2026 | PraisonAI MCP server path traversal enables arbitrary file write and code execution | PraisonAI | workflow | tool misuse | | resolved |
| 7 May 2026 | Microsoft discloses multiple Copilot injection and access control CVEs (May 2026) | Microsoft | other | prompt injection | | confirmed |
| 6 May 2026 | Multiple OpenClaw MCP and gateway vulnerabilities patched (CVE-2026-44118, -44995, -45001) | OpenClaw | other | excessive permissions | | resolved |
| 5 May 2026 | Four unpatched CVEs in Langchain-Chatchat file APIs, exploits public | chatchat-space | other | excessive permissions | | reported |
| 5 May 2026 | SQLBot Text2SQL prompt injection enables arbitrary SQL execution and RCE (CVE-2026-33324) | DataEase | other | prompt injection | | resolved |
| 5 May 2026 | CVE-2026-35228: Oracle MCP Server Helper Tool flaw allows malicious SQL execution | Oracle | other | unknown | | confirmed |
| 5 May 2026 | CVE-2026-3456: SQL injection in WordPress GeekyBot AI chatbot plugin | GeekyBot | customer service | unknown | | reported |
| 4 May 2026 | PPTAgent: code execution and arbitrary file write flaws patched (CVE-2026-42078/79/80) | icip-cas | workflow | tool misuse | | resolved |
| 4 May 2026 | CVE-2026-7729: SSRF in pixelsock directus-mcp 1.0.0 MCP interface | pixelsock | workflow | tool misuse | | reported |
| 4 May 2026 | Multiple patched vulnerabilities in n8n and n8n-MCP MCP servers | n8n | workflow | data leak | | resolved |
| 4 May 2026 | Evolver AI agent engine: path traversal, command injection and prototype pollution flaws | EvoMap | other | unknown | | resolved |
| 29 Apr 2026 | CVE-2026-7417: SSRF in Algovate xhs-mcp MCP server publish tool | Algovate | workflow | tool misuse | | reported |
| 28 Apr 2026 | SSRF in Tencent CloudBase-MCP open-url endpoint (CVE-2026-7221) | TencentCloudBase | coding | tool misuse | | resolved |
| 27 Apr 2026 | SSRF in dmitryglhf mcp-url-downloader MCP server (CVE-2026-7158) | dmitryglhf | browsing | tool misuse | | reported |
| 27 Apr 2026 | SSRF in dh1011 auto-favicon MCP server tool (CVE-2026-7150) | dh1011 | other | tool misuse | | reported |
| 27 Apr 2026 | SSRF in mcp-data-vis MCP web-scraper server (CVE-2026-7146) | AlejandroArciniegas | browsing | tool misuse | | reported |
| 27 Apr 2026 | SSRF in JoeCastrom mcp-chat-studio LLM Models API (CVE-2026-7147) | JoeCastrom | other | unknown | | reported |
| 24 Apr 2026 | LangChain SSRF protection bypasses in langchain-text-splitters and langchain-openai | LangChain | other | tool misuse | | resolved |