Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Incident database

Structured records of AI agent security incidents: what happened, which vendor and agent type, the root cause, and every source we used. Filter, browse, or download as CSV.

Incidents by month, 2026 · 434 total · click a month to filter
Jan 2026: 23 incidents23JanFeb 2026: 26 incidents26FebMar 2026: 46 incidents46MarApr 2026: 46 incidents46AprMay 2026: 52 incidents52MayJun 2026: 51 incidents51JunJul 2026: 45 incidents45JulAug 2026: 82 incidents82AugSep 2026: 63 incidents63SepOct 2026: 0 incidents0OctNov 2026: 0 incidents0NovDec 2026: 0 incidents0Dec

453 incidents

Incident dateIncidentVendorAgentRoot causeSeverityStatus
26 May 2026CVE-2026-44209: SSTI to RCE in banks LLM prompt template librarymasciothermisconfigurationresolved
26 May 2026CVE-2026-44895: GitLab MCP Server HTTP transport exposes unauthenticated RPC endpointyoda-digitalcodingmisconfigurationresolved
26 May 2026LangChain and LangSmith SDK unsafe deserialization of untrusted serialized objectsLangChainotherexcessive permissionsresolved
24 May 2026CVE-2026-9353: Prompt injection flaw in NousResearch hermes-agent Skills GuardNousResearchotherprompt injectionreported
22 May 2026Command injection flaws in Microsoft Copilot and M365 Copilot (CVE-2026-41090, CVE-2026-42827)Microsoftotherunknownconfirmed
21 May 2026Central Dogma Git mirror disables SSH host-key verification (CVE-2026-11745)LINEothermisconfigurationconfirmed
15 May 2026CVE-2026-44717: RCE in MCP Calculate Server via unsanitized eval()611711Darkothertool misuseresolved
15 May 2026CVE-2026-45401: SSRF via unvalidated redirects in Open WebUI web retrievalOpen WebUIbrowsingtool misuseresolved
15 May 2026Microsoft APM agent dependency manager: path traversal and symlink flaws (3 CVEs)Microsoftcodingsupply chainresolved
14 May 2026Hatchet cross-tenant data exposure via missing authorization (CVE-2026-42572)Hatchetworkflowmisconfigurationresolved
14 May 2026Multiple vulnerabilities disclosed in MCP Registry and rmcp Rust SDKModel Context Protocolothersupply chainresolved
13 May 2026Vercel CLI leaked auth tokens in AI-agent non-interactive command output (CVE-2026-44479)Vercelcodingdata leakresolved
13 May 2026GitHub Copilot CLI arbitrary code execution via nested bare git repository (CVE-2026-45033)GitHubcodingtool misuseresolved
12 May 2026CVE-2025-65719: Remote code execution in Kubectl MCP Server v1.1.1Open Source Kubectl MCP Server (rohitg00)otherunknownreported
12 May 2026CVE-2026-44220: ciguard symlink traversal exposes files outside scan rootJo-Jo98 (ciguard project)codingdata leakresolved
12 May 2026CVE-2026-44246: Prompt injection in nnU-Net GitHub issue-triage agent workflowMIC-DKFZworkflowprompt injectionresolved
12 May 2026Unauthenticated RCE in Code Runner MCP Server HTTP transport (CVE-2026-5029)codingexcessive permissionsreported
12 May 2026CVE-2026-42045: LobeChat artifact XSS chains to arbitrary command executionLobeHubotherprompt injectionresolved
12 May 2026JunoClaw agent platform: shell command injection and SSRF flaws (CVE-2026-43990/43993)JunoClawworkflowtool misuseresolved
12 May 2026JunoClaw agentic AI platform patches three MCP tool vulnerabilitiesJunoClawotherdata leakresolved
12 May 2026OpenAI agent swarm tied to May 2026 RubyGems supply chain attackOpenAIothersupply chainconfirmed
12 May 2026CVE-2026-42260: SSRF in Open-WebSearch MCP server URL safety checksAas-eebrowsingmisconfigurationresolved
12 May 2026Langflow path traversal in Knowledge Bases API allows arbitrary directory deletionLangflowworkflowexcessive permissionsresolved
11 May 2026CVE-2026-30635: Command injection in automagik-genie 2.5.27 MCP serverothertool misusereported
11 May 2026CVE-2026-42869: Hardcoded JWT secret in SOCFortress CoPilot allows admin token forgerySOCFortressothermisconfigurationresolved
11 May 2026CVE-2026-43901: Wireshark MCP server allows arbitrary export path via unsandboxed toolbx33661 (Wireshark-MCP project)otherexcessive permissionsconfirmed
11 May 2026CVE-2026-31246: Command injection in GPT-Pilot Executor.run() enables RCEPythagora-iocodingtool misusereported
11 May 2026CVE-2026-8319: Remote resource exhaustion in aiwaves-cn agents memory recall functionaiwaves-cnotherunknownreported
11 May 2026DeepChat CVE-2026-43899: external URL handler bypass enables code executionThinkInAIXYZothermisconfigurationresolved
8 May 2026LiteLLM MCP preview endpoints allow authenticated users to run commands on proxy hostBerriAIotherexcessive permissionsresolved
8 May 2026PromptHub SSRF via IPv6 bypass in skills fetch-remote endpoint (CVE-2026-42261)PromptHubworkflowmisconfigurationresolved
8 May 2026Multiple vulnerabilities disclosed in FastGPT AI agent platform, including sandbox RCElabringworkflowmisconfigurationconfirmed
8 May 2026PraisonAI MCP server path traversal enables arbitrary file write and code executionPraisonAIworkflowtool misuseresolved
7 May 2026Microsoft discloses multiple Copilot injection and access control CVEs (May 2026)Microsoftotherprompt injectionconfirmed
6 May 2026Multiple OpenClaw MCP and gateway vulnerabilities patched (CVE-2026-44118, -44995, -45001)OpenClawotherexcessive permissionsresolved
5 May 2026Four unpatched CVEs in Langchain-Chatchat file APIs, exploits publicchatchat-spaceotherexcessive permissionsreported
5 May 2026SQLBot Text2SQL prompt injection enables arbitrary SQL execution and RCE (CVE-2026-33324)DataEaseotherprompt injectionresolved
5 May 2026CVE-2026-35228: Oracle MCP Server Helper Tool flaw allows malicious SQL executionOracleotherunknownconfirmed
5 May 2026CVE-2026-3456: SQL injection in WordPress GeekyBot AI chatbot pluginGeekyBotcustomer serviceunknownreported
4 May 2026PPTAgent: code execution and arbitrary file write flaws patched (CVE-2026-42078/79/80)icip-casworkflowtool misuseresolved
4 May 2026CVE-2026-7729: SSRF in pixelsock directus-mcp 1.0.0 MCP interfacepixelsockworkflowtool misusereported
4 May 2026Multiple patched vulnerabilities in n8n and n8n-MCP MCP serversn8nworkflowdata leakresolved
4 May 2026Evolver AI agent engine: path traversal, command injection and prototype pollution flawsEvoMapotherunknownresolved
29 Apr 2026CVE-2026-7417: SSRF in Algovate xhs-mcp MCP server publish toolAlgovateworkflowtool misusereported
28 Apr 2026SSRF in Tencent CloudBase-MCP open-url endpoint (CVE-2026-7221)TencentCloudBasecodingtool misuseresolved
27 Apr 2026SSRF in dmitryglhf mcp-url-downloader MCP server (CVE-2026-7158)dmitryglhfbrowsingtool misusereported
27 Apr 2026SSRF in dh1011 auto-favicon MCP server tool (CVE-2026-7150)dh1011othertool misusereported
27 Apr 2026SSRF in mcp-data-vis MCP web-scraper server (CVE-2026-7146)AlejandroArciniegasbrowsingtool misusereported
27 Apr 2026SSRF in JoeCastrom mcp-chat-studio LLM Models API (CVE-2026-7147)JoeCastromotherunknownreported
24 Apr 2026LangChain SSRF protection bypasses in langchain-text-splitters and langchain-openaiLangChainothertool misuseresolved