Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

CVE-2026-75130: Context7 prompt injection via Custom AI Instructions

Context7 through version 2.1.2 contains a prompt injection vulnerability in its Custom AI Instructions feature that allows attackers to inject malicious instructions through the MCP server, enabling credential exfiltration and file deletion in connected AI coding agents.

Disclosed 18 August 2026 · Record updated 13 September 2026

Impact

Attackers can exfiltrate credentials from environment files and perform destructive file deletion on victim machines through poisoned custom instructions.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-75130