Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Incident database

Structured records of AI agent security incidents: what happened, which vendor and agent type, the root cause, and every source we used. Filter, browse, or download as CSV.

Incidents by month, 2026 · 434 total · click a month to filter
Jan 2026: 23 incidents23JanFeb 2026: 26 incidents26FebMar 2026: 46 incidents46MarApr 2026: 46 incidents46AprMay 2026: 52 incidents52MayJun 2026: 51 incidents51JunJul 2026: 45 incidents45JulAug 2026: 82 incidents82AugSep 2026: 63 incidents63SepOct 2026: 0 incidents0OctNov 2026: 0 incidents0NovDec 2026: 0 incidents0Dec

453 incidents

Incident dateIncidentVendorAgentRoot causeSeverityStatus
24 Apr 2026AnythingLLM stored XSS via unsanitised chart captions (CVE-2026-41318)Mintplex Labsotherprompt injectionresolved
23 Apr 2026CVE-2026-33102: Open redirect in Microsoft 365 Copilot enables privilege elevationMicrosoftotherunknownconfirmed
23 Apr 2026Paperclip AI agent orchestrator: unauthenticated and agent-key RCE flaws (CVE-2026-41208/41679)Paperclipworkflowexcessive permissionsresolved
23 Apr 2026CVE-2026-41349: OpenClaw agentic consent bypass via config.patchOpenClawotherexcessive permissionsresolved
21 Apr 2026CVE-2026-40608: Unbounded request body crashes Next AI Draw.io MCP sidecarDayuanJiangothermisconfigurationresolved
21 Apr 2026Path traversal in excel-mcp-server allows unauthenticated remote arbitrary file accessharis-musaworkflowmisconfigurationresolved
21 Apr 2026Flowise pre-3.1.0: RCE via prompt injection in CSV/Airtable agents and MCP adapterFlowiseAIworkflowprompt injectionresolved
20 Apr 2026Two remotely exploitable flaws disclosed in ericc-ch copilot-api up to 0.7.0ericc-chcodingmisconfigurationreported
17 Apr 2026FastGPT NoSQL injection flaws allow authentication bypass and account takeoverlabringotherunknownresolved
17 Apr 2026Claude Code flaws: Windows config hijack and symlink sandbox escapeAnthropiccodingprompt injectionresolved
17 Apr 2026mcp-neo4j-cypher read-only bypass via APOC procedures (CVE-2026-35402)neo4j-contribotherexcessive permissionsresolved
17 Apr 2026CVE-2026-6494: Log injection in Ansible Automation Platform MCP serverRed Hatworkflowunknownconfirmed
17 Apr 2026CVE-2025-66335: SQL injection flaw in Apache Doris MCP Server before 0.6.1Apacheothertool misuseresolved
16 Apr 2026CVE-2026-39313: unbounded request body in mcp-framework enables remote DoSQuantGeekDevothersupply chainresolved
15 Apr 2026CVE-2026-30624: Remote code execution in Agent Zero MCP server configurationAgent Zeroothertool misusereported
15 Apr 2026CVE-2026-30616: Remote code execution in Jaaz 1.0.30 MCP STDIO command handlingJaazothertool misusereported
15 Apr 2026CVE-2026-30615: Prompt injection in Windsurf enables RCE via malicious MCP server registrationWindsurfcodingprompt injectionreported
15 Apr 2026Splunk MCP Server app logs session and authorization tokens in clear text (CVE-2026-20205)Splunkworkflowdata leakresolved
15 Apr 2026Argument injection in mcp-server-kubernetes port_forward tool (CVE-2026-39884)Flux159workflowtool misuseresolved
15 Apr 2026CVE-2026-30625: Remote code execution in Upsonic MCP task creationUpsonicworkflowtool misusereported
14 Apr 2026CVE-2026-23653: Command injection in GitHub Copilot and Visual Studio CodeMicrosoftcodingtool misuseconfirmed
13 Apr 2026CVE-2026-34476: SSRF via SW-URL header in Apache SkyWalking MCPApache Software Foundationothertool misuseresolved
11 Apr 2026aws-mcp-server command injection flaws allow unauthenticated remote code executionaws-mcp-serverworkflowtool misusereported
10 Apr 2026FastGPT AI agent platform: unauthenticated SSRF and cross-tenant access control flawslabringworkflowexcessive permissionsresolved
10 Apr 2026CVE-2026-35651: ANSI escape injection in OpenClaw approval promptsOpenClawcodingprompt injectionresolved
9 Apr 2026AGiXT path traversal in essential_abilities allows arbitrary file access (CVE-2026-39981)AGiXTworkflowexcessive permissionsresolved
9 Apr 2026Command injection in awwaiid mcp-server-taskwarrior up to 1.0.1 (CVE-2026-5833)awwaiidworkflowtool misuseresolved
9 Apr 2026LangChain prompt-template validation flaw and LangChain-ChatChat MCP RCE disclosedLangChainothertool misuseconfirmed
9 Apr 2026Apollo MCP Server DNS rebinding flaw allows local tool invocation (CVE-2026-35577)Apollo GraphQLworkflowmisconfigurationresolved
8 Apr 2026FrontMCP SSRF and local file read via unrestricted OpenAPI $ref dereferencing (CVE-2026-39885)agentfrontothermisconfigurationresolved
8 Apr 2026CVE-2026-34724: Zammad server-side template injection enables RCE via AI AgentZammadcustomer serviceunknownresolved
7 Apr 2026DNS rebinding flaw in MCP Java SDK allows remote tool calls (CVE-2026-35568)Model Context Protocolothermisconfigurationresolved
6 Apr 2026CVE-2026-5607: SSRF in imprvhub mcp-browser-agent up to 0.8.0imprvhubbrowsingtool misusereported
6 Apr 2026CVE-2026-35394: mobile-mcp URL tool allows arbitrary Android intent executionMobile Nextworkflowtool misuseresolved
5 Apr 2026CVE-2026-5584: Remote code injection in agenticSeek PyInterpreter.executeFosowlcodingtool misusereported
3 Apr 2026Multiple critical vulnerabilities in PraisonAI multi-agent framework (8 CVEs)PraisonAIworkflowtool misuseresolved
3 Apr 2026CVE-2025-64340: Command injection in FastMCP install commands on WindowsPrefectHQcodingtool misuseresolved
2 Apr 2026SSRF vulnerability in a11y-mcp MCP server (CVE-2026-5323)priyankarkothertool misuseresolved
2 Apr 2026FastMCP flaws before 3.2.0: authenticated SSRF and OAuth confused deputyPrefectHQothertool misuseresolved
31 Mar 2026CVE-2026-4399: Prompt injection in 1millionbot Millie chatbot1millionbotcustomer serviceprompt injectionreported
31 Mar 2026LangChain path traversal in prompt loading allows arbitrary file read (CVE-2026-34070)LangChainotherdata leakresolved
31 Mar 2026FastGPT SSRF flaws in HTTP and MCP tools endpoints (CVE-2026-34162/34163)labringworkflowmisconfigurationresolved
31 Mar 2026Nhost CLI MCP server lacked authentication and CORS enforcement (CVE-2026-34200)Nhostcodingmisconfigurationresolved
31 Mar 2026Origin-validation flaws in official MCP Java and Go SDKs allow cross-site accessModel Context Protocolothermisconfigurationresolved
31 Mar 2026CVE-2026-34451: Path validation flaw in Anthropic TypeScript SDK memory toolAnthropicotherprompt injectionresolved
31 Mar 2026Giskard library flaw: ChatWorkflow.chat renders input as Jinja2 template enabling RCEGiskardothermisconfigurationresolved
31 Mar 2026CVE-2026-29870: Path traversal enables arbitrary file write in agentic-context-engineagentic-context-engine projectothertool misusereported
30 Mar 2026Unauthenticated MCP endpoint in Nginx UI allows full nginx takeover (CVE-2026-33032)Nginx UIworkflowmisconfigurationconfirmed
28 Mar 2026CVE-2026-5002: Prompt injection in localGPT LLM prompt handlerPromtEngineerotherprompt injectionreported
27 Mar 2026Path traversal in @mobilenext/mobile-mcp MCP server (CVE-2026-33989)Mobile Nextworkflowtool misuseresolved