Monday, 14 September 2026
0 agent hacks today 8 vs yesterday (8)

Incident database

Structured records of AI agent security incidents: what happened, which vendor and agent type, the root cause, and every source we used. Filter, browse, or download as CSV.

Incidents by month, 2026 · 434 total · click a month to filter
Jan 2026: 23 incidents23JanFeb 2026: 26 incidents26FebMar 2026: 46 incidents46MarApr 2026: 46 incidents46AprMay 2026: 52 incidents52MayJun 2026: 51 incidents51JunJul 2026: 45 incidents45JulAug 2026: 82 incidents82AugSep 2026: 63 incidents63SepOct 2026: 0 incidents0OctNov 2026: 0 incidents0NovDec 2026: 0 incidents0Dec

453 incidents

Incident dateIncidentVendorAgentRoot causeSeverityStatus
10 Feb 2026Command injection flaws in GitHub Copilot and Visual Studio enable remote code executionMicrosoftcodingunknownconfirmed
9 Feb 2026CVE-2026-25905: mcp-run-python sandbox escape enables MCP server hijackingcodingexcessive permissionsreported
9 Feb 2026CVE-2026-1868: Template injection in GitLab AI Gateway Duo Workflow ServiceGitLabworkflowunknownresolved
6 Feb 2026Microsoft AI agent tooling flaws: Semantic Kernel file write and Copilot command injectionMicrosoftcodingtool misuseresolved
6 Feb 2026CVE-2026-25533: Sandbox escape in Enclave JavaScript sandbox for AI agent codeagentfrontcodingexcessive permissionsresolved
6 Feb 2026Pydantic AI framework patches path traversal XSS and SSRF vulnerabilitiesPydanticworkflowtool misuseresolved
6 Feb 2026CVE-2026-25650: MCP Salesforce Connector leaks Salesforce auth tokensmn2gntworkflowdata leakresolved
4 Feb 2026AutoGPT platform SSRF in SendDiscordFileBlock (CVE-2025-62616)Significant Gravitasworkflowtool misuseresolved
4 Feb 2026OpenClaw path traversal in isValidMedia() enables arbitrary file read (CVE-2026-25475)OpenClawotherexcessive permissionsresolved
4 Feb 2026CVE-2026-25546: Command injection in godot-mcp MCP server enables RCECoding-Solocodingtool misuseresolved
3 Feb 2026Multiple Claude Code permission and sandbox bypass vulnerabilities patchedAnthropiccodingtool misuseresolved
30 Jan 2026Prompt injection via road signs shown to hijack autonomous cars and dronesotherprompt injectionreported
30 Jan 2026Moltbook, a social network for AI agents, exposes its database and agent tokensMoltbookothermisconfigurationresolved
27 Jan 2026Hundreds of malicious skills found on the OpenClaw skill marketplaceOpenClawworkflowsupply chainresolved
24 Jan 2026Unauthenticated arbitrary file upload in Kalrav AI Agent WordPress plugin (CVE-2025-13374)otherexcessive permissionsreported
24 Jan 2026ChatterMate AI chatbot XSS via chat input exposes tokens (CVE-2026-24399)ChatterMatecustomer servicedata leakresolved
23 Jan 2026Unauthenticated command injection RCE in Framelink Figma and Ollama MCP serversFramelink (Figma-Context-MCP); Ollama MCP Serverothertool misuseconfirmed
22 Jan 2026Three information disclosure flaws in Microsoft Copilot, Copilot Studio and M365 CopilotMicrosoftworkflowdata leakconfirmed
21 Jan 2026CVE-2026-22792: 5ire MCP client HTML injection enables MCP server creation and RCEnanbingxyzotherexcessive permissionsresolved
21 Jan 2026Claude Code flaw let malicious repos exfiltrate Anthropic API keys (CVE-2026-21852)Anthropiccodingdata leakresolved
19 Jan 2026Two CVEs in awesome-llm-apps agents: path traversal and cross-session token leakawesome-llm-apps projectotherdata leakreported
16 Jan 2026MCPJam Inspector <=1.4.2 remote code execution via crafted MCP server install requestMCPJamcodingmisconfigurationresolved
16 Jan 2026CVE-2026-23523: Dive MCP host deeplink allows arbitrary command executionOpenAgentPlatformotherexcessive permissionsresolved
14 Jan 2026CVE-2026-22708: Cursor agent allowlist bypass lets shell built-ins run unapprovedCursorcodingprompt injectionresolved
14 Jan 2026Sandbox escape in Enclave JavaScript sandbox for AI agents (CVE-2026-22686)agentfrontcodingexcessive permissionsresolved
12 Jan 2026CVE-2024-58340: ReDoS in LangChain MRKL agent output parserLangChainworkflowprompt injectionreported
12 Jan 2026OpenCode AI coding agent: unauthenticated local RCE and XSS in web UIanomalycocodingmisconfigurationresolved
12 Jan 2026CVE-2026-22785: Code injection in orval MCP server generation from OpenAPI specsorval-labscodingsupply chainresolved
12 Jan 2026Path traversal in Zen MCP Server allows arbitrary file reads (CVE-2025-66689)BeehiveInnovationscodingdata leakresolved
10 Jan 2026Tencent WeKnora agent flaws allow prompt-based DB access and command injectionTencentotherprompt injectionresolved
7 Jan 2026CVE-2025-67366: Path traversal via symlinks in @sylphxltd/filesystem-mcp v0.5.8sylphxltdworkflowexcessive permissionsreported
7 Jan 2026CVE-2025-9611: DNS rebinding in Microsoft Playwright MCP Server via missing Origin checkMicrosoftbrowsingmisconfigurationresolved
2 Jan 2026CVE-2026-21445: Missing authentication on Langflow API endpoints exposes conversation dataLangflowworkflowmisconfigurationresolved
1 Jan 2026Anthropic discloses fourth case of Claude accessing third-party systems without authorizationAnthropicothermisconfigurationconfirmed
1 Dec 2025Anthropic reports threat actors abusing Claude for cyberattacks, weapons and surveillanceAnthropicothertool misuseconfirmed
15 Sept 2025State-sponsored group uses Claude Code to automate an espionage campaignAnthropiccodingtool misuseconfirmed
26 Aug 2025s1ngularity: compromised Nx packages use AI coding agents to steal credentialsNx (Nrwl)codingsupply chainresolved
8 Aug 2025Stolen Salesloft Drift tokens used to pull Salesforce data from hundreds of companiesSalesloftcustomer servicesupply chainresolved
28 Jul 2025ForcedLeak: Salesforce Agentforce leaks CRM data through a Web-to-Lead formSalesforcecustomer serviceprompt injectionresolved
25 Jul 2025Perplexity Comet browser agent hijacked by text on a web pagePerplexitybrowsingprompt injectionresolved
18 Jul 2025Replit coding agent deletes a production database during a code freezeReplitcodingexcessive permissionsresolved
13 Jul 2025Malicious prompt planted in Amazon Q Developer VS Code extensionAmazoncodingsupply chainresolved
7 Jul 2025CurXecute: Cursor agent turned into remote code execution via MCP configCursorcodingprompt injectionresolved
3 Jul 2025Supabase MCP server with service-role key leaks SQL data to a support ticketSupabasecodingexcessive permissionsresolved
27 Jun 2025Gemini CLI tricked into silent command execution and data exfiltrationGooglecodingprompt injectionresolved
18 Jun 2025ShadowLeak: zero-click data theft through ChatGPT Deep Research and GmailOpenAIbrowsingprompt injectionresolved
1 Jun 2025AgentFlayer: poisoned document leaks API keys through ChatGPT ConnectorsOpenAIworkflowprompt injectionresolved
26 May 2025GitHub MCP server leaks private repository data via a public issueGitHubcodingprompt injectionconfirmed
14 Apr 2025Anthropic MCP Inspector exposed developers to browser-based remote code executionAnthropiccodingmisconfigurationresolved
7 Apr 2025Langflow code-validation endpoint gives unauthenticated remote code executionLangflowworkflowmisconfigurationresolved