| 24 Apr 2026 | AnythingLLM stored XSS via unsanitised chart captions (CVE-2026-41318) | Mintplex Labs | other | prompt injection | | resolved |
| 23 Apr 2026 | CVE-2026-33102: Open redirect in Microsoft 365 Copilot enables privilege elevation | Microsoft | other | unknown | | confirmed |
| 23 Apr 2026 | Paperclip AI agent orchestrator: unauthenticated and agent-key RCE flaws (CVE-2026-41208/41679) | Paperclip | workflow | excessive permissions | | resolved |
| 23 Apr 2026 | CVE-2026-41349: OpenClaw agentic consent bypass via config.patch | OpenClaw | other | excessive permissions | | resolved |
| 21 Apr 2026 | CVE-2026-40608: Unbounded request body crashes Next AI Draw.io MCP sidecar | DayuanJiang | other | misconfiguration | | resolved |
| 21 Apr 2026 | Path traversal in excel-mcp-server allows unauthenticated remote arbitrary file access | haris-musa | workflow | misconfiguration | | resolved |
| 21 Apr 2026 | Flowise pre-3.1.0: RCE via prompt injection in CSV/Airtable agents and MCP adapter | FlowiseAI | workflow | prompt injection | | resolved |
| 20 Apr 2026 | Two remotely exploitable flaws disclosed in ericc-ch copilot-api up to 0.7.0 | ericc-ch | coding | misconfiguration | | reported |
| 17 Apr 2026 | FastGPT NoSQL injection flaws allow authentication bypass and account takeover | labring | other | unknown | | resolved |
| 17 Apr 2026 | Claude Code flaws: Windows config hijack and symlink sandbox escape | Anthropic | coding | prompt injection | | resolved |
| 17 Apr 2026 | mcp-neo4j-cypher read-only bypass via APOC procedures (CVE-2026-35402) | neo4j-contrib | other | excessive permissions | | resolved |
| 17 Apr 2026 | CVE-2026-6494: Log injection in Ansible Automation Platform MCP server | Red Hat | workflow | unknown | | confirmed |
| 17 Apr 2026 | CVE-2025-66335: SQL injection flaw in Apache Doris MCP Server before 0.6.1 | Apache | other | tool misuse | | resolved |
| 16 Apr 2026 | CVE-2026-39313: unbounded request body in mcp-framework enables remote DoS | QuantGeekDev | other | supply chain | | resolved |
| 15 Apr 2026 | CVE-2026-30624: Remote code execution in Agent Zero MCP server configuration | Agent Zero | other | tool misuse | | reported |
| 15 Apr 2026 | CVE-2026-30616: Remote code execution in Jaaz 1.0.30 MCP STDIO command handling | Jaaz | other | tool misuse | | reported |
| 15 Apr 2026 | CVE-2026-30615: Prompt injection in Windsurf enables RCE via malicious MCP server registration | Windsurf | coding | prompt injection | | reported |
| 15 Apr 2026 | Splunk MCP Server app logs session and authorization tokens in clear text (CVE-2026-20205) | Splunk | workflow | data leak | | resolved |
| 15 Apr 2026 | Argument injection in mcp-server-kubernetes port_forward tool (CVE-2026-39884) | Flux159 | workflow | tool misuse | | resolved |
| 15 Apr 2026 | CVE-2026-30625: Remote code execution in Upsonic MCP task creation | Upsonic | workflow | tool misuse | | reported |
| 14 Apr 2026 | CVE-2026-23653: Command injection in GitHub Copilot and Visual Studio Code | Microsoft | coding | tool misuse | | confirmed |
| 13 Apr 2026 | CVE-2026-34476: SSRF via SW-URL header in Apache SkyWalking MCP | Apache Software Foundation | other | tool misuse | | resolved |
| 11 Apr 2026 | aws-mcp-server command injection flaws allow unauthenticated remote code execution | aws-mcp-server | workflow | tool misuse | | reported |
| 10 Apr 2026 | FastGPT AI agent platform: unauthenticated SSRF and cross-tenant access control flaws | labring | workflow | excessive permissions | | resolved |
| 10 Apr 2026 | CVE-2026-35651: ANSI escape injection in OpenClaw approval prompts | OpenClaw | coding | prompt injection | | resolved |
| 9 Apr 2026 | AGiXT path traversal in essential_abilities allows arbitrary file access (CVE-2026-39981) | AGiXT | workflow | excessive permissions | | resolved |
| 9 Apr 2026 | Command injection in awwaiid mcp-server-taskwarrior up to 1.0.1 (CVE-2026-5833) | awwaiid | workflow | tool misuse | | resolved |
| 9 Apr 2026 | LangChain prompt-template validation flaw and LangChain-ChatChat MCP RCE disclosed | LangChain | other | tool misuse | | confirmed |
| 9 Apr 2026 | Apollo MCP Server DNS rebinding flaw allows local tool invocation (CVE-2026-35577) | Apollo GraphQL | workflow | misconfiguration | | resolved |
| 8 Apr 2026 | FrontMCP SSRF and local file read via unrestricted OpenAPI $ref dereferencing (CVE-2026-39885) | agentfront | other | misconfiguration | | resolved |
| 8 Apr 2026 | CVE-2026-34724: Zammad server-side template injection enables RCE via AI Agent | Zammad | customer service | unknown | | resolved |
| 7 Apr 2026 | DNS rebinding flaw in MCP Java SDK allows remote tool calls (CVE-2026-35568) | Model Context Protocol | other | misconfiguration | | resolved |
| 6 Apr 2026 | CVE-2026-5607: SSRF in imprvhub mcp-browser-agent up to 0.8.0 | imprvhub | browsing | tool misuse | | reported |
| 6 Apr 2026 | CVE-2026-35394: mobile-mcp URL tool allows arbitrary Android intent execution | Mobile Next | workflow | tool misuse | | resolved |
| 5 Apr 2026 | CVE-2026-5584: Remote code injection in agenticSeek PyInterpreter.execute | Fosowl | coding | tool misuse | | reported |
| 3 Apr 2026 | Multiple critical vulnerabilities in PraisonAI multi-agent framework (8 CVEs) | PraisonAI | workflow | tool misuse | | resolved |
| 3 Apr 2026 | CVE-2025-64340: Command injection in FastMCP install commands on Windows | PrefectHQ | coding | tool misuse | | resolved |
| 2 Apr 2026 | SSRF vulnerability in a11y-mcp MCP server (CVE-2026-5323) | priyankark | other | tool misuse | | resolved |
| 2 Apr 2026 | FastMCP flaws before 3.2.0: authenticated SSRF and OAuth confused deputy | PrefectHQ | other | tool misuse | | resolved |
| 31 Mar 2026 | CVE-2026-4399: Prompt injection in 1millionbot Millie chatbot | 1millionbot | customer service | prompt injection | | reported |
| 31 Mar 2026 | LangChain path traversal in prompt loading allows arbitrary file read (CVE-2026-34070) | LangChain | other | data leak | | resolved |
| 31 Mar 2026 | FastGPT SSRF flaws in HTTP and MCP tools endpoints (CVE-2026-34162/34163) | labring | workflow | misconfiguration | | resolved |
| 31 Mar 2026 | Nhost CLI MCP server lacked authentication and CORS enforcement (CVE-2026-34200) | Nhost | coding | misconfiguration | | resolved |
| 31 Mar 2026 | Origin-validation flaws in official MCP Java and Go SDKs allow cross-site access | Model Context Protocol | other | misconfiguration | | resolved |
| 31 Mar 2026 | CVE-2026-34451: Path validation flaw in Anthropic TypeScript SDK memory tool | Anthropic | other | prompt injection | | resolved |
| 31 Mar 2026 | Giskard library flaw: ChatWorkflow.chat renders input as Jinja2 template enabling RCE | Giskard | other | misconfiguration | | resolved |
| 31 Mar 2026 | CVE-2026-29870: Path traversal enables arbitrary file write in agentic-context-engine | agentic-context-engine project | other | tool misuse | | reported |
| 30 Mar 2026 | Unauthenticated MCP endpoint in Nginx UI allows full nginx takeover (CVE-2026-33032) | Nginx UI | workflow | misconfiguration | | confirmed |
| 28 Mar 2026 | CVE-2026-5002: Prompt injection in localGPT LLM prompt handler | PromtEngineer | other | prompt injection | | reported |
| 27 Mar 2026 | Path traversal in @mobilenext/mobile-mcp MCP server (CVE-2026-33989) | Mobile Next | workflow | tool misuse | | resolved |