| 27 Mar 2026 | KQL injection in Azure Data Explorer MCP Server (CVE-2026-33980) | pab1it0 (adx-mcp-server project) | other | tool misuse | | resolved |
| 27 Mar 2026 | Zero-click prompt injection in nanobot AI assistant email channel (CVE-2026-33654) | HKUDS | other | prompt injection | | resolved |
| 27 Mar 2026 | LibreChat MCP/agent flaws enable SSRF and OAuth token exfiltration | LibreChat | other | tool misuse | | resolved |
| 27 Mar 2026 | Prompt injection bypasses "safe command" auto-approval in multiple AI coding extensions | | coding | prompt injection | | reported |
| 27 Mar 2026 | Command injection in OpenHands git diff API allows arbitrary commands in agent sandbox | OpenHands | coding | tool misuse | | resolved |
| 23 Mar 2026 | CVE-2026-23882: Arbitrary command execution via Blinko MCP server creation | Blinko | workflow | tool misuse | | resolved |
| 22 Mar 2026 | CVE-2026-4530: SQL injection in Aix-DB text2sql agent terminology retriever | apconw | other | unknown | | reported |
| 20 Mar 2026 | CVE-2026-33010: Wildcard CORS in mcp-memory-service exposes agent memories | doobidoo | other | misconfiguration | | resolved |
| 20 Mar 2026 | Multiple CVEs in PinchTab AI agent browser control server | PinchTab | browsing | tool misuse | | confirmed |
| 20 Mar 2026 | FastGPT CI workflow flaw allows code execution and secret theft (CVE-2026-33075) | labring | workflow | supply chain | | confirmed |
| 20 Mar 2026 | Agentic tooling flaws: Claude Code trust bypass and MCP Go/Ruby SDK transport bugs | Anthropic | coding | excessive permissions | | resolved |
| 20 Mar 2026 | CVE-2026-33060: SSRF in CKAN MCP Server via unvalidated base_url parameter | ondata | workflow | prompt injection | | resolved |
| 20 Mar 2026 | Multiple Langflow vulnerabilities, including unauthenticated RCE, fixed in 1.9.0 | Langflow | workflow | excessive permissions | | resolved |
| 19 Mar 2026 | SQLBot stored prompt injection chain enables RCE (CVE-2026-32622) | DataEase | other | prompt injection | | resolved |
| 19 Mar 2026 | Discourse XSS via prompt injection in AI triage Review Queue (CVE-2026-27740) | Discourse | workflow | prompt injection | | resolved |
| 19 Mar 2026 | Command injection flaws in Microsoft Copilot and M365 Copilot allow information disclosure | Microsoft | other | unknown | | confirmed |
| 19 Mar 2026 | Rogue AI agent implicated in security incident at Meta | Meta | other | unknown | | reported |
| 16 Mar 2026 | CVE-2026-4270: AWS API MCP Server file access restriction bypass | AWS | other | excessive permissions | | resolved |
| 16 Mar 2026 | FastMCP OAuth token audience flaw (CVE-2025-69196) fixed in 2.14.2 | PrefectHQ | other | excessive permissions | | resolved |
| 16 Mar 2026 | AnythingLLM 1.11.1 and earlier: missing authentication and SQL Agent injection flaws | Mintplex Labs | workflow | tool misuse | | confirmed |
| 12 Mar 2026 | CVE-2026-32247: Cypher injection in Graphiti search filters exploitable via prompt injection | getzep | other | prompt injection | | resolved |
| 11 Mar 2026 | ha-mcp Home Assistant MCP server: SSRF and XSS flaws in beta OAuth consent form | homeassistant-ai | workflow | unknown | | resolved |
| 11 Mar 2026 | CVE-2026-31854: Cursor indirect prompt injection enables automatic command execution | Cursor | coding | prompt injection | | resolved |
| 11 Mar 2026 | CVE-2026-32128: FastGPT Python sandbox file-write guardrail bypass via fcntl stdout remap | FastGPT (labring) | coding | misconfiguration | | confirmed |
| 10 Mar 2026 | MCP Atlassian server flaws allow SSRF and arbitrary file write before v0.17.0 | sooperset | workflow | tool misuse | | resolved |
| 10 Mar 2026 | Microsoft discloses AI command injection in M365 Copilot and SSRF in Azure MCP Server | Microsoft | workflow | prompt injection | | confirmed |
| 7 Mar 2026 | WeKnora MCP tool name collision enables prompt injection and tool hijacking | Tencent | workflow | prompt injection | | resolved |
| 7 Mar 2026 | PinchTab SSRF in /download endpoint allows internal network and file access (CVE-2026-30834) | PinchTab | browsing | excessive permissions | | resolved |
| 7 Mar 2026 | mcp-memory-service exposes system details via unauthenticated health endpoint (CVE-2026-29787) | doobidoo | other | misconfiguration | | resolved |
| 6 Mar 2026 | Agentgateway MCP-to-OpenAPI request injection flaw (CVE-2026-29791) | Agentgateway | other | tool misuse | | resolved |
| 6 Mar 2026 | GitHub Copilot CLI shell tool bypass allows arbitrary code execution (CVE-2026-29783) | GitHub | coding | prompt injection | | resolved |
| 5 Mar 2026 | OpenClaw agent platform: SSRF and RCE via prompt injection (CVE-2026-28451, CVE-2026-30741) | OpenClaw | other | prompt injection | | confirmed |
| 5 Mar 2026 | Trivy VS Code extension 1.8.12 on OpenVSX compromised to exfiltrate secrets via AI agent | Aqua Security | coding | supply chain | | resolved |
| 3 Mar 2026 | CVE-2025-12345: Remote buffer overflow in LLM-Claw agent deployment function | | other | unknown | | resolved |
| 2 Mar 2026 | CVE-2026-2256: command injection in ModelScope ms-agent via prompt-derived input | ModelScope | other | prompt injection | | reported |
| 26 Feb 2026 | Agenta LLMOps platform: sandbox escape RCE and SSTI in server-side evaluators | Agenta | other | misconfiguration | | resolved |
| 26 Feb 2026 | Zed editor agent file tools symlink escape (CVE-2026-27967) | Zed Industries | coding | excessive permissions | | resolved |
| 26 Feb 2026 | Path traversal in MCP git server's git_add tool stages files outside repository | Model Context Protocol | coding | tool misuse | | resolved |
| 26 Feb 2026 | Langflow CSV Agent node RCE via prompt injection (CVE-2026-27966) | Langflow | workflow | prompt injection | | resolved |
| 25 Feb 2026 | CVE-2026-27597: Sandbox escape in Enclave AI agent JavaScript sandbox enables RCE | agentfront | coding | unknown | | resolved |
| 25 Feb 2026 | Parse Dashboard AI Agent endpoint flaws allow unauthenticated master-key database access | Parse Community | other | excessive permissions | | resolved |
| 25 Feb 2026 | LangChain SSRF redirect bypass and LangSmith Studio token-leak vulnerabilities | LangChain | workflow | data leak | | resolved |
| 21 Feb 2026 | CVE-2026-27203: Environment variable injection in eBay API MCP Server | YosefHayim (ebay-mcp open source project) | other | tool misuse | | reported |
| 19 Feb 2026 | CVE-2026-26057: Cisco Skill Scanner API server unauthenticated DoS and arbitrary file upload | Cisco | other | misconfiguration | | resolved |
| 19 Feb 2026 | Multiple OpenClaw AI assistant vulnerabilities disclosed, including prompt injection paths | OpenClaw | other | prompt injection | | resolved |
| 13 Feb 2026 | CVE-2026-26268: Cursor sandbox escape via writable .git configuration | Cursor | coding | prompt injection | | resolved |
| 13 Feb 2026 | Reflected XSS in Cloudflare agents SDK AI Playground OAuth callback (CVE-2026-1721) | Cloudflare | other | misconfiguration | | resolved |
| 11 Feb 2026 | Command injection in sf-mcp-server Salesforce MCP server (CVE-2026-26029) | akutishevsky | workflow | tool misuse | | resolved |
| 10 Feb 2026 | LangChain SSRF flaws in ChatOpenAI token counter and RecursiveUrlLoader | LangChain | workflow | tool misuse | | resolved |
| 10 Feb 2026 | FastGPT AI agent platform: unauthenticated plugin API access and SSRF flaws | labring | workflow | excessive permissions | | resolved |