Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Incident database

Structured records of AI agent security incidents: what happened, which vendor and agent type, the root cause, and every source we used. Filter, browse, or download as CSV.

Incidents by month, 2026 · 434 total · click a month to filter
Jan 2026: 23 incidents23JanFeb 2026: 26 incidents26FebMar 2026: 46 incidents46MarApr 2026: 46 incidents46AprMay 2026: 52 incidents52MayJun 2026: 51 incidents51JunJul 2026: 45 incidents45JulAug 2026: 82 incidents82AugSep 2026: 63 incidents63SepOct 2026: 0 incidents0OctNov 2026: 0 incidents0NovDec 2026: 0 incidents0Dec

453 incidents

Incident dateIncidentVendorAgentRoot causeSeverityStatus
27 Mar 2026KQL injection in Azure Data Explorer MCP Server (CVE-2026-33980)pab1it0 (adx-mcp-server project)othertool misuseresolved
27 Mar 2026Zero-click prompt injection in nanobot AI assistant email channel (CVE-2026-33654)HKUDSotherprompt injectionresolved
27 Mar 2026LibreChat MCP/agent flaws enable SSRF and OAuth token exfiltrationLibreChatothertool misuseresolved
27 Mar 2026Prompt injection bypasses "safe command" auto-approval in multiple AI coding extensionscodingprompt injectionreported
27 Mar 2026Command injection in OpenHands git diff API allows arbitrary commands in agent sandboxOpenHandscodingtool misuseresolved
23 Mar 2026CVE-2026-23882: Arbitrary command execution via Blinko MCP server creationBlinkoworkflowtool misuseresolved
22 Mar 2026CVE-2026-4530: SQL injection in Aix-DB text2sql agent terminology retrieverapconwotherunknownreported
20 Mar 2026CVE-2026-33010: Wildcard CORS in mcp-memory-service exposes agent memoriesdoobidooothermisconfigurationresolved
20 Mar 2026Multiple CVEs in PinchTab AI agent browser control serverPinchTabbrowsingtool misuseconfirmed
20 Mar 2026FastGPT CI workflow flaw allows code execution and secret theft (CVE-2026-33075)labringworkflowsupply chainconfirmed
20 Mar 2026Agentic tooling flaws: Claude Code trust bypass and MCP Go/Ruby SDK transport bugsAnthropiccodingexcessive permissionsresolved
20 Mar 2026CVE-2026-33060: SSRF in CKAN MCP Server via unvalidated base_url parameterondataworkflowprompt injectionresolved
20 Mar 2026Multiple Langflow vulnerabilities, including unauthenticated RCE, fixed in 1.9.0Langflowworkflowexcessive permissionsresolved
19 Mar 2026SQLBot stored prompt injection chain enables RCE (CVE-2026-32622)DataEaseotherprompt injectionresolved
19 Mar 2026Discourse XSS via prompt injection in AI triage Review Queue (CVE-2026-27740)Discourseworkflowprompt injectionresolved
19 Mar 2026Command injection flaws in Microsoft Copilot and M365 Copilot allow information disclosureMicrosoftotherunknownconfirmed
19 Mar 2026Rogue AI agent implicated in security incident at MetaMetaotherunknownreported
16 Mar 2026CVE-2026-4270: AWS API MCP Server file access restriction bypassAWSotherexcessive permissionsresolved
16 Mar 2026FastMCP OAuth token audience flaw (CVE-2025-69196) fixed in 2.14.2PrefectHQotherexcessive permissionsresolved
16 Mar 2026AnythingLLM 1.11.1 and earlier: missing authentication and SQL Agent injection flawsMintplex Labsworkflowtool misuseconfirmed
12 Mar 2026CVE-2026-32247: Cypher injection in Graphiti search filters exploitable via prompt injectiongetzepotherprompt injectionresolved
11 Mar 2026ha-mcp Home Assistant MCP server: SSRF and XSS flaws in beta OAuth consent formhomeassistant-aiworkflowunknownresolved
11 Mar 2026CVE-2026-31854: Cursor indirect prompt injection enables automatic command executionCursorcodingprompt injectionresolved
11 Mar 2026CVE-2026-32128: FastGPT Python sandbox file-write guardrail bypass via fcntl stdout remapFastGPT (labring)codingmisconfigurationconfirmed
10 Mar 2026MCP Atlassian server flaws allow SSRF and arbitrary file write before v0.17.0soopersetworkflowtool misuseresolved
10 Mar 2026Microsoft discloses AI command injection in M365 Copilot and SSRF in Azure MCP ServerMicrosoftworkflowprompt injectionconfirmed
7 Mar 2026WeKnora MCP tool name collision enables prompt injection and tool hijackingTencentworkflowprompt injectionresolved
7 Mar 2026PinchTab SSRF in /download endpoint allows internal network and file access (CVE-2026-30834)PinchTabbrowsingexcessive permissionsresolved
7 Mar 2026mcp-memory-service exposes system details via unauthenticated health endpoint (CVE-2026-29787)doobidooothermisconfigurationresolved
6 Mar 2026Agentgateway MCP-to-OpenAPI request injection flaw (CVE-2026-29791)Agentgatewayothertool misuseresolved
6 Mar 2026GitHub Copilot CLI shell tool bypass allows arbitrary code execution (CVE-2026-29783)GitHubcodingprompt injectionresolved
5 Mar 2026OpenClaw agent platform: SSRF and RCE via prompt injection (CVE-2026-28451, CVE-2026-30741)OpenClawotherprompt injectionconfirmed
5 Mar 2026Trivy VS Code extension 1.8.12 on OpenVSX compromised to exfiltrate secrets via AI agentAqua Securitycodingsupply chainresolved
3 Mar 2026CVE-2025-12345: Remote buffer overflow in LLM-Claw agent deployment functionotherunknownresolved
2 Mar 2026CVE-2026-2256: command injection in ModelScope ms-agent via prompt-derived inputModelScopeotherprompt injectionreported
26 Feb 2026Agenta LLMOps platform: sandbox escape RCE and SSTI in server-side evaluatorsAgentaothermisconfigurationresolved
26 Feb 2026Zed editor agent file tools symlink escape (CVE-2026-27967)Zed Industriescodingexcessive permissionsresolved
26 Feb 2026Path traversal in MCP git server's git_add tool stages files outside repositoryModel Context Protocolcodingtool misuseresolved
26 Feb 2026Langflow CSV Agent node RCE via prompt injection (CVE-2026-27966)Langflowworkflowprompt injectionresolved
25 Feb 2026CVE-2026-27597: Sandbox escape in Enclave AI agent JavaScript sandbox enables RCEagentfrontcodingunknownresolved
25 Feb 2026Parse Dashboard AI Agent endpoint flaws allow unauthenticated master-key database accessParse Communityotherexcessive permissionsresolved
25 Feb 2026LangChain SSRF redirect bypass and LangSmith Studio token-leak vulnerabilitiesLangChainworkflowdata leakresolved
21 Feb 2026CVE-2026-27203: Environment variable injection in eBay API MCP ServerYosefHayim (ebay-mcp open source project)othertool misusereported
19 Feb 2026CVE-2026-26057: Cisco Skill Scanner API server unauthenticated DoS and arbitrary file uploadCiscoothermisconfigurationresolved
19 Feb 2026Multiple OpenClaw AI assistant vulnerabilities disclosed, including prompt injection pathsOpenClawotherprompt injectionresolved
13 Feb 2026CVE-2026-26268: Cursor sandbox escape via writable .git configurationCursorcodingprompt injectionresolved
13 Feb 2026Reflected XSS in Cloudflare agents SDK AI Playground OAuth callback (CVE-2026-1721)Cloudflareothermisconfigurationresolved
11 Feb 2026Command injection in sf-mcp-server Salesforce MCP server (CVE-2026-26029)akutishevskyworkflowtool misuseresolved
10 Feb 2026LangChain SSRF flaws in ChatOpenAI token counter and RecursiveUrlLoaderLangChainworkflowtool misuseresolved
10 Feb 2026FastGPT AI agent platform: unauthenticated plugin API access and SSRF flawslabringworkflowexcessive permissionsresolved