Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Agentgateway MCP-to-OpenAPI request injection flaw (CVE-2026-29791)

Agentgateway, an open source data plane for agentic AI connectivity, failed to sanitize path, query, and header values when converting MCP tools/call requests into OpenAPI requests in versions prior to 0.12.0. The issue was patched in version 0.12.0.

Disclosed 6 March 2026 · Record updated 13 September 2026

Impact

Unsanitized input values in MCP tool call conversion to OpenAPI requests in Agentgateway versions before 0.12.0.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-29791