Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Reflected XSS in Cloudflare agents SDK AI Playground OAuth callback (CVE-2026-1721)

A reflected cross-site scripting flaw in the AI Playground's OAuth callback handler allowed the `error_description` query parameter to be interpolated unescaped into an inline script tag. Exploitation via a crafted link could expose a victim's stored LLM chat history and let an attacker interact with MCP servers connected to the victim's session.

Disclosed 13 February 2026 · Record updated 13 September 2026

Impact

Attackers could execute arbitrary JavaScript in a victim's session context, stealing chat message history with LLMs and acting on the victim's behalf against connected public or authenticated MCP servers.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-1721