Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

APIFold webhook endpoint accepts unauthenticated arbitrary JSON

APIFold's webhook endpoint fails to validate signatures or require authentication, allowing unauthenticated attackers to inject arbitrary payloads into Redis and PostgreSQL. The vulnerability was patched in commit 7f19b52280f414f57af2b79a95333d1c8fbeece5.

Disclosed 23 July 2026 · Record updated 13 September 2026

Impact

Unauthenticated network clients can inject arbitrary payloads that are subsequently served as trusted resource state to legitimate MCP clients

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-47769