| 10 Feb 2026 | Command injection flaws in GitHub Copilot and Visual Studio enable remote code execution | Microsoft | coding | unknown | | confirmed |
| 9 Feb 2026 | CVE-2026-25905: mcp-run-python sandbox escape enables MCP server hijacking | | coding | excessive permissions | | reported |
| 9 Feb 2026 | CVE-2026-1868: Template injection in GitLab AI Gateway Duo Workflow Service | GitLab | workflow | unknown | | resolved |
| 6 Feb 2026 | Microsoft AI agent tooling flaws: Semantic Kernel file write and Copilot command injection | Microsoft | coding | tool misuse | | resolved |
| 6 Feb 2026 | CVE-2026-25533: Sandbox escape in Enclave JavaScript sandbox for AI agent code | agentfront | coding | excessive permissions | | resolved |
| 6 Feb 2026 | Pydantic AI framework patches path traversal XSS and SSRF vulnerabilities | Pydantic | workflow | tool misuse | | resolved |
| 6 Feb 2026 | CVE-2026-25650: MCP Salesforce Connector leaks Salesforce auth token | smn2gnt | workflow | data leak | | resolved |
| 4 Feb 2026 | AutoGPT platform SSRF in SendDiscordFileBlock (CVE-2025-62616) | Significant Gravitas | workflow | tool misuse | | resolved |
| 4 Feb 2026 | OpenClaw path traversal in isValidMedia() enables arbitrary file read (CVE-2026-25475) | OpenClaw | other | excessive permissions | | resolved |
| 4 Feb 2026 | CVE-2026-25546: Command injection in godot-mcp MCP server enables RCE | Coding-Solo | coding | tool misuse | | resolved |
| 3 Feb 2026 | Multiple Claude Code permission and sandbox bypass vulnerabilities patched | Anthropic | coding | tool misuse | | resolved |
| 30 Jan 2026 | Prompt injection via road signs shown to hijack autonomous cars and drones | | other | prompt injection | | reported |
| 30 Jan 2026 | Moltbook, a social network for AI agents, exposes its database and agent tokens | Moltbook | other | misconfiguration | | resolved |
| 27 Jan 2026 | Hundreds of malicious skills found on the OpenClaw skill marketplace | OpenClaw | workflow | supply chain | | resolved |
| 24 Jan 2026 | Unauthenticated arbitrary file upload in Kalrav AI Agent WordPress plugin (CVE-2025-13374) | | other | excessive permissions | | reported |
| 24 Jan 2026 | ChatterMate AI chatbot XSS via chat input exposes tokens (CVE-2026-24399) | ChatterMate | customer service | data leak | | resolved |
| 23 Jan 2026 | Unauthenticated command injection RCE in Framelink Figma and Ollama MCP servers | Framelink (Figma-Context-MCP); Ollama MCP Server | other | tool misuse | | confirmed |
| 22 Jan 2026 | Three information disclosure flaws in Microsoft Copilot, Copilot Studio and M365 Copilot | Microsoft | workflow | data leak | | confirmed |
| 21 Jan 2026 | CVE-2026-22792: 5ire MCP client HTML injection enables MCP server creation and RCE | nanbingxyz | other | excessive permissions | | resolved |
| 21 Jan 2026 | Claude Code flaw let malicious repos exfiltrate Anthropic API keys (CVE-2026-21852) | Anthropic | coding | data leak | | resolved |
| 19 Jan 2026 | Two CVEs in awesome-llm-apps agents: path traversal and cross-session token leak | awesome-llm-apps project | other | data leak | | reported |
| 16 Jan 2026 | MCPJam Inspector <=1.4.2 remote code execution via crafted MCP server install request | MCPJam | coding | misconfiguration | | resolved |
| 16 Jan 2026 | CVE-2026-23523: Dive MCP host deeplink allows arbitrary command execution | OpenAgentPlatform | other | excessive permissions | | resolved |
| 14 Jan 2026 | CVE-2026-22708: Cursor agent allowlist bypass lets shell built-ins run unapproved | Cursor | coding | prompt injection | | resolved |
| 14 Jan 2026 | Sandbox escape in Enclave JavaScript sandbox for AI agents (CVE-2026-22686) | agentfront | coding | excessive permissions | | resolved |
| 12 Jan 2026 | CVE-2024-58340: ReDoS in LangChain MRKL agent output parser | LangChain | workflow | prompt injection | | reported |
| 12 Jan 2026 | OpenCode AI coding agent: unauthenticated local RCE and XSS in web UI | anomalyco | coding | misconfiguration | | resolved |
| 12 Jan 2026 | CVE-2026-22785: Code injection in orval MCP server generation from OpenAPI specs | orval-labs | coding | supply chain | | resolved |
| 12 Jan 2026 | Path traversal in Zen MCP Server allows arbitrary file reads (CVE-2025-66689) | BeehiveInnovations | coding | data leak | | resolved |
| 10 Jan 2026 | Tencent WeKnora agent flaws allow prompt-based DB access and command injection | Tencent | other | prompt injection | | resolved |
| 7 Jan 2026 | CVE-2025-67366: Path traversal via symlinks in @sylphxltd/filesystem-mcp v0.5.8 | sylphxltd | workflow | excessive permissions | | reported |
| 7 Jan 2026 | CVE-2025-9611: DNS rebinding in Microsoft Playwright MCP Server via missing Origin check | Microsoft | browsing | misconfiguration | | resolved |
| 2 Jan 2026 | CVE-2026-21445: Missing authentication on Langflow API endpoints exposes conversation data | Langflow | workflow | misconfiguration | | resolved |
| 1 Jan 2026 | Anthropic discloses fourth case of Claude accessing third-party systems without authorization | Anthropic | other | misconfiguration | | confirmed |
| 1 Dec 2025 | Anthropic reports threat actors abusing Claude for cyberattacks, weapons and surveillance | Anthropic | other | tool misuse | | confirmed |
| 15 Sept 2025 | State-sponsored group uses Claude Code to automate an espionage campaign | Anthropic | coding | tool misuse | | confirmed |
| 26 Aug 2025 | s1ngularity: compromised Nx packages use AI coding agents to steal credentials | Nx (Nrwl) | coding | supply chain | | resolved |
| 8 Aug 2025 | Stolen Salesloft Drift tokens used to pull Salesforce data from hundreds of companies | Salesloft | customer service | supply chain | | resolved |
| 28 Jul 2025 | ForcedLeak: Salesforce Agentforce leaks CRM data through a Web-to-Lead form | Salesforce | customer service | prompt injection | | resolved |
| 25 Jul 2025 | Perplexity Comet browser agent hijacked by text on a web page | Perplexity | browsing | prompt injection | | resolved |
| 18 Jul 2025 | Replit coding agent deletes a production database during a code freeze | Replit | coding | excessive permissions | | resolved |
| 13 Jul 2025 | Malicious prompt planted in Amazon Q Developer VS Code extension | Amazon | coding | supply chain | | resolved |
| 7 Jul 2025 | CurXecute: Cursor agent turned into remote code execution via MCP config | Cursor | coding | prompt injection | | resolved |
| 3 Jul 2025 | Supabase MCP server with service-role key leaks SQL data to a support ticket | Supabase | coding | excessive permissions | | resolved |
| 27 Jun 2025 | Gemini CLI tricked into silent command execution and data exfiltration | Google | coding | prompt injection | | resolved |
| 18 Jun 2025 | ShadowLeak: zero-click data theft through ChatGPT Deep Research and Gmail | OpenAI | browsing | prompt injection | | resolved |
| 1 Jun 2025 | AgentFlayer: poisoned document leaks API keys through ChatGPT Connectors | OpenAI | workflow | prompt injection | | resolved |
| 26 May 2025 | GitHub MCP server leaks private repository data via a public issue | GitHub | coding | prompt injection | | confirmed |
| 14 Apr 2025 | Anthropic MCP Inspector exposed developers to browser-based remote code execution | Anthropic | coding | misconfiguration | | resolved |
| 7 Apr 2025 | Langflow code-validation endpoint gives unauthenticated remote code execution | Langflow | workflow | misconfiguration | | resolved |