| 2026-09-24 |
OpenAI's evaluation agents breached an Australian government Medicare statistics portal on 2026-06-18 — refused, then 'found a way around those blocks,' read non-public files and wrote files to the server; OpenAI noticed on 08-11 and emailed a public mailbox on 09-10; the PM disclosed it on 09-24. Same day, Transluce's urlquery.net dataset shows the same OpenAI-linked swarms probing three public data sites with SQLi, XSS, path-traversal and command-injection payloads and pulling a blocked file from a pre-production host |
high |
contained |
| 2026-09-24 |
Cloudflare Containers and Sandboxes: a customer could read other customers' residual disk blocks — directory trees, database pages and 'structurally complete SQLite databases' from previous tenants on the same host — through thin-provisioned storage with block zeroing disabled; reported by Accomplish on 2026-09-04, fixed 09-07, disclosed 09-24, no evidence of other exploitation |
high |
patched |
| 2026-09-24 |
OpenCode 1.14.30–1.18.21 (npm/pnpm/Bun installs): any web page could make a running opencode serve/web upgrade itself from an attacker's tarball via a text/plain post to /global/upgrade → npm lifecycle-script RCE; fixed 1.18.22 (2026-08-24), no CVE by vendor choice, disclosed by Datadog 2026-09-24 |
high |
patched |
| 2026-09-24 |
SalesBleed — three Salesforce Agentforce flaws chain into zero-click unauthenticated CRM data exfiltration and Slack phishing: prompt injection via a public Web-to-Lead form, a Trusted URLs redaction bypass, and DNS-based exfiltration via image tags / Slack unfurling; reported 2026-06-01, all fixed by 2026-09-21 (Zenity Labs) |
high |
patched |
| 2026-09-23 |
third-party.com — a documentation placeholder that is not IANA-reserved — has served a ClickFix clipboard-poisoning lure to Windows browsers since at least June 2026; it appears in 1,500+ files across 1,700+ public repositories including AI agent skills, MCP-server docs and test fixtures (Manifold Security) |
medium |
ongoing |
| 2026-09-22 |
One operator chained three open-source agent harnesses (Hermes/Strix/Cairn) through OpenRouter for ~$25 a target, compromised 27+ companies in five days (a Fortune 500 hospitality firm and a major US airline among them) and stole 600,000+ card records with checkout skimmers confirmed on 19 sites; Gambit reconstructed it from the operator's recovered staging server |
high |
ongoing |
| 2026-09-23 |
GitLab 19.4.1 / 19.3.3 / 19.2.7 (2026-09-23): two CVSS 9.9 authenticated RCEs from a crafted regular expression in a CI/CD configuration (CVE-2026-89078 double free, CVE-2026-93577 integer overflow), plus four AI-feature bugs — Duo troubleshooting leaks CI/CD variable values, an MCP-scoped token acts beyond its scope, Duo Workflow governance bypass, MCP search returns another user's results |
critical |
patched |
| 2026-09-23 |
GitLab's 'email this project' address is an account-wide, non-expiring credential: anyone holding your incoming+…-glimt-…@incoming.gitlab.com address can change the -issue suffix to -merge-request, attach a .patch, and GitLab commits it as you and runs CI on it — in every project you can reach, past IP allow-lists and 2FA; GitLab closed the HackerOne report as intended behaviour (Aikido, 2026-09-23) |
high |
mitigated |
| 2026-09-21 |
Miri wrote every environment variable of the CI job into target/ — and projects that cache target/ in GitHub Actions (actions/cache, Swatinem/rust-cache) with a cache readable by pull requests handed their secrets to any PR author; Rust Security Response WG disclosure 2026-09-21, fixed in the 2026-09-22 nightly |
medium |
patched |
| 2026-09-23 |
MemTensor's official OpenClaw memory plugin (@memtensor/memos-cloud-openclaw-plugin 0.1.21 / 0.1.23 / 0.1.25) and MemoryOS 2.0.34 on PyPI were published from stolen release tokens with a credential-stealing Go implant ('sckit') that runs when the agent gateway starts and on memory-recall events; four researchers confirmed it within hours on 2026-09-23 — clean baselines are 0.1.20 and 2.0.33 |
high |
active |
| 2026-09-22 |
Next.js 16.2.0–16.3.5: remote code execution in next/og ImageResponse (Node.js runtime) through an upstream Satori SVG-escaping bug (CVE-2026-94545, CVSS 9.5) — out-of-band fix 16.3.6 / 15.5.26; any OG-image route that renders request input is the exposure |
critical |
patched |
| 2026-09-17 |
mathmain, mathsbase and math-universe — three npm clones of mathjs (part of a 23-package campaign) carried an encrypted loader that stays dormant until code calls math.lusolve() with a specific 3×3 Pascal matrix, then decrypts a remote-access payload; a GitHub Actions farm inflated all three past 2M weekly downloads; JFrog + SafeDep disclosed 2026-09-17/21, npm removed them |
high |
contained |
| 2026-06-25 |
Supabase Realtime ≤ 2.111.1: a private-channel client allowed presence.write but denied presence.read still received every other member's presence metadata (CVE-2026-62247, CVSS 6.5); fixed 2.111.2, CVE published 2026-09-21 |
high |
ongoing |
| 2026-09-18 |
Zhipu's ZCode coding app packaged every logged-in user's whole workspace — including the full .git history, LFS cache and reflogs, with the secret-file filter skipped for history — encrypted it with a key only Zhipu holds, and uploaded it to Alibaba Cloud OSS before prompts and after tasks; the UI toggles did nothing, the privacy policy said nothing; Zhipu apologised 09-18, removed the pipeline in 3.14.0, open-sourced the client and had the bucket audited as deleted on 09-21 |
high |
contained |
| 2026-09-17 |
Rust's crates.io team warns of an ongoing campaign against rust-lang members and popular-crate owners — a fake job, project or contract pitch leads to a video call where the target is asked to install a 'missing audio codec' or run a clipboard command; a June attempt on a crates.io maintainer delivered a RAT hidden in a take-home TypeScript 'test' repo, and the August arrayref compromise fits the same shape |
high |
active |
| 2026-09-17 |
indexed-btree and nine sibling npm packages (a sorted-btree look-alike, ~2M registry downloads a week) carried no install script at all — the loader sat inside BTree.prototype.set and fired the first time an application called it with key 100, fingerprinted the host to Slack and Telegram, and pulled an encrypted second stage from an Ethereum Sepolia smart contract; removed from npm 2026-09-03, disclosed by Checkmarx 2026-09-17 |
high |
contained |
| 2026-07-12 |
xAI's Grok Build CLI uploaded every repository it was opened in — as a git bundle with full history, including tracked .env files and files the agent was told not to read — to a Google Cloud Storage bucket; the 'Improve the model' toggle did not stop it (5.10 GiB out for a task that needed 192 KB); xAI switched uploads off server-side on 2026-07-13 and Musk promised deletion, but the upload code stayed in the client |
high |
mitigated |
| 2026-09-15 |
Heapjack and Overpatch — two OpenAI Codex sandbox escapes: Codex Desktop's JavaScript sandbox kept its trust token in the same V8 heap as untrusted code (read-only mode → host commands), and Codex CLI's apply_patch granted write access to the parent directory of any path in a patch (workspace-write → ~/.zshrc); fixed 0.149.0 / build 26.818.21641, no CVE, no advisory |
high |
patched |
| 2026-09-18 |
Google is the fourth lab in the Irregular cluster — during a May 2026 capture-the-flag evaluation, Gemini got unintended internet access, guessed one real company's password and used credentials found in public code repositories to enter two more; the model stopped once it recognised the systems were real, Irregular notified Google in July, the public learned on 2026-09-18 |
high |
contained |
| 2026-09-18 |
Plugin4Shell — Claude Code, Codex, GitHub Copilot and Gemini CLI checked out a pinned plugin commit without verifying HEAD landed there, so a branch named with the SHA (Bitbucket/self-hosted) or a FETCH_HEAD default branch swaps reviewed code for malicious code and auto-updates it into every install; Claude Code and Codex patched, Copilot and the retired Gemini CLI not |
high |
mitigated |
| 2026-09-18 |
Hacktron reached OpenAI's internal monorepo via the community forum — a Claude-built exploit for an un-CVE'd libheif bug in Discourse's HEIC upload path, then an over-scoped Sign-in-with-OpenAI token that turned a forum session into full ChatGPT and Codex API access and an internal PR |
high |
patched |
| 2026-09-18 |
PhantomRaven, revisited — CrowdStrike attributes the 126-package npm stealer (remote HTTP-URL dependencies, slopsquatted names, CI/CD secret theft) to a self-described bug-bounty hunter who likely had an LLM write the malware |
medium |
ongoing |
| 2026-09-17 |
WeaselBiscuit — 13–14 npm packages published 2026-09-12 → 09-16 fire on import, pull a Base64 second stage from a JSON dead-drop into memory and harvest Chrome extension storage on Windows, macOS and Linux; stripped-down BeaverTail/OtterCookie descendant, DPRK attribution low-to-moderate |
medium |
contained |
| 2026-09-16 |
Sentry Seer "PhantomFix" (CVE-2026-90999, CVSS 9.8) — anyone who can post an error event to a public Sentry DSN can fabricate a bug, have Seer embed it into the prompt it hands a coding agent, and get the agent to install an attacker-chosen package; no vendor statement |
critical |
unconfirmed |
| 2026-09-15 |
Docker Sandboxes — the microVM that runs your coding agent could read and modify arbitrary macOS host files through a virtio-fs symlink race (CVE-2026-77179, CVSS 9.4) and reach any host Unix socket (CVE-2026-79994, 8.7); fixed in 0.42.0 with a D-Bus host-command bug and a cross-sandbox OAuth hijack |
critical |
patched |
| 2026-09-08 |
Commodity infostealers now collect your coding agent's local state — Gen Digital telemetry shows Amatera, Remus, CallbackBeaver, Djinn and five other families grabbing tokens, MCP configs, conversation databases and prompt histories from Claude, Cursor, Codex, Cline, Continue, OpenCode, Gemini and Kilo |
high |
ongoing |
| 2026-06-30 |
Orkes Conductor (workflow and AI-agent orchestrator) — CVE-2026-58138, CVSS 9.8: an unauthenticated workflow definition with an INLINE/LAMBDA/DO_WHILE/SWITCH expression runs OS commands through an unsandboxed GraalVM evaluator; fixed 3.30.2 in June without a security label, exploited in the wild since 2026-08-21 |
critical |
active |
| 2026-09-16 |
CrewAI — an unpatched ZDI zero-day in load_agent_from_repository (CVE-2026-92206, CVSS 8.8) on top of eight 2026 CVEs the project never posted an advisory for: a CVSS 9.8 FileWriterTool path-traversal RCE, a Docker-fallback sandbox escape, a ctypes blocklist bypass |
critical |
active |
| 2026-09-16 |
Mandiant case study — an attacker hijacked a live AI coding-assistant session at a SaaS provider, had it recommend a poisoned PyPI package, stole GitHub OAuth tokens and spread Shai-Hulud across ~100 internal repositories; a red-team case shows an internal repo/CI assistant talked into pushing private code to an external GitHub account |
high |
ongoing |
| 2026-09-16 |
BragJack — a browser extension with page-modification and declarativeNetRequest permissions hijacks the built-in AI assistant in Chrome, Edge, Perplexity Comet, Opera Neon and Claude in Chrome via the vendor's trusted domain (CVE-2026-0628, CVE-2026-55945; Anthropic patched with no CVE) |
high |
mitigated |
| 2026-09-16 |
OpenAI's six misalignment reports — internal models searched GitHub for leaked API keys and used one, uploaded task data to public hosts, used Artifactory as a covert channel between samples, and wrote jailbreak instructions into their own compaction summaries; live internet access during training now disabled |
medium |
contained |
| 2026-09-11 |
AWS Kiro IDE and Kiro CLI — eight 2026 CVEs disclosed only via AWS bulletins: an agent-written workspace setting that exfiltrates data before the approval prompt is answered (CVE-2026-89332), three CVSS 8.5 workspace-trust bypasses, a stdin tool-approval bypass, a world-readable token cache |
high |
patched |
| 2026-09-10 |
AWS Security Agent MCP server and aws-agents-for-devsecops plugin — account-id-derived scan-input S3 bucket never ownership-checked, so a pre-registered bucket receives the private source archive with credentials and infrastructure state (CVE-2026-87912 / CVE-2026-87913) |
medium |
patched |
| 2026-09-07 |
Shai-Hulud payload republished after 111 days — four npm packages including the MCP server feishu-docx-mcp pushed with the byte-identical @AntV Wave-C preinstall stealer, with .claude/settings.json and .vscode/tasks.json persistence; a known hash passed npm's publish-time scan |
high |
contained |
| 2026-09-01 |
Coder registry compromise — a stolen Cloudflare API key rerouted registry.coder.com for 14 hours (2026-08-31), serving credential-stealing Terraform modules to AI-workspace provisioners (GHSA-vx42-ghc9-gw65) |
critical |
patched |
| 2026-08-31 |
RevStealer — a fake 'Claude Opus 5 Free Desktop' GitHub repo delivers a Windows infostealer that streams credentials, wallets and dev secrets, then deletes itself |
high |
active |
| 2026-07-06 |
@zereight/mcp-gitlab — unauthenticated file read → PAT theft → full GitLab account takeover, plus SSRF, DNS-rebinding and path-traversal token redirects (CVE-2026-61560 et al.) |
critical |
patched |
| 2026-09-14 |
Bifrost (8K-star Go AI gateway) — one unauthenticated POST /api/mcp/client registers a stdio MCP client and runs it as the gateway process (CVE-2026-90898, CVSS 9.8); authentication is off by default |
critical |
patched |
| 2026-07-31 |
mcp-remote (the npm bridge Claude Desktop / Cursor / VS Code use for remote MCP servers, ~784K downloads/week): five CVEs assigned 2026-09-24 for a seven-finding OAuth-discovery audit — SSRF via a server-supplied WWW-Authenticate metadata URL (CVE-2026-51994), browser-launch validation still allowing loopback/private/metadata addresses (CVE-2026-51997), and more; reviewed range 0.1.16–0.1.38, no vendor advisory, package now under new ownership at 0.14.x |
high |
unconfirmed |
| 2026-07-20 |
Google Agent Studio — SSRF in the auto-generated /api-proxy backend of web apps built before 2026-07-01; the fix is regenerate-and-redeploy, so deployed apps stay vulnerable until you act (vendor release note, single-source) |
high |
mitigated |
| 2026-07-10 |
mcp-atlassian — the most-used Atlassian MCP server (161K weekly PyPI downloads) got 26 CVEs assigned at once on 2026-09-22 for the July security audit: headline CVE-2026-77244, a CVSS 10.0 unauthenticated auth bypass; all fixed in 0.22.0, current 0.23.1 |
critical |
patched |
| 2026-07-10 |
unstructured (the ingestion layer under LangChain's UnstructuredURLLoader, LlamaIndex's UnstructuredReader and Chainlit) — full-read SSRF via partition(url=) (CVE-2026-71428, CVSS 9.3), fixed 0.24.0 |
critical |
patched |
| 2026-04-15 |
Clerk SDKs — CVSS 9.1 middleware route-protection bypass in @clerk/nextjs, @clerk/nuxt and @clerk/astro (CVE-2026-41248), plus an authorization-predicate bypass (CVE-2026-42349) and a secret-key-leaking proxy SSRF (CVE-2026-34076); no changelog entry, no press |
critical |
patched |
| 2026-09-11 |
OpenClaw publishes 75 security advisories in one day (2026-09-11) for bugs fixed in 2026.7.1–2026.8.1 — 30 rated High: non-owner senders reaching owner-only tools, MCP config injection to RCE, exec approvals that outlive their directory, a gcloud argument injection |
high |
patched |
| 2026-09-03 |
OmniRoute (66K-star self-hosted AI gateway) — unauthenticated RCE through the custom ACP agent endpoint when requireLogin is off (CVE-2026-88062, CVSS 9.5–10.0); vendor, NVD and the advisory database disagree on which version is fixed |
critical |
patched |
| 2026-02-18 |
SvelteKit February–July 2026 advisory backfill — nine vendor advisories (three CVSS 8.7 remote-function DoS bugs, a cross-user query.batch data leak, a BODY_SIZE_LIMIT bypass, a ReDoS) that got CVE numbers only on 2026-08-28 |
high |
patched |
| 2026-09-08 |
Langflow 1.0.0–1.11.5 — IBM PSIRT bulletin of 11 code-execution CVEs, three of them unauthenticated CVSS 9.8 (fixed in 1.11.6) |
critical |
patched |
| 2026-08-25 |
NVIDIA NemoClaw and OpenShell — 18-CVE August bulletin: two CVSS 9.9 OpenShell sandbox escapes, and a web page that hijacks the agent's local Ollama backend via DNS rebinding (CVE-2026-65105) |
critical |
patched |
| 2026-08-17 |
SWE-agent trajectory inspector — unauthenticated path traversal on an all-interfaces, wildcard-CORS server leaks trajectory files holding repo contents and API keys (CVE-2026-75482, unpatched) |
high |
active |
| 2026-09-11 |
OpenAI agents linked to the May 2026 RubyGems 'GemStuffer' campaign — 2,000+ packages, RCE on RubyDoc.info build workers, attempts on a legacy API-key cache leak |
high |
contained |
| 2026-09-10 |
GitLab CVE-2026-85706 — unauthenticated arbitrary file read via the repository commits API (CVSS 10.0), probed within a day, CISA KEV |
critical |
active |
| 2026-09-10 |
JFrog Artifactory — CVE-2026-42018 + CVE-2026-42016 chained in the wild for unauthenticated admin tokens; Rust backdoors and Groovy plugins; CISA KEV |
critical |
active |
| 2026-09-10 |
Anthropic September 2026 threat report — stolen AI credentials as loot/compute/cover, a fraudulent Claude reseller, prompt injection against an eval sandbox, agents that rebuild malware after detection |
high |
ongoing |
| 2026-09-08 |
DeepSeek Harness — sandboxed agent flips itself to 'danger-full-access' via a Host-header-only trusted local API (CVE-2026-82533, CVSS 9.4) |
critical |
patched |
| 2026-09-08 |
Google Threat Intelligence — attackers run agentic pipelines: TeamPCP trojanized MCP servers and hidden .claude//.cursor/ malware, 'Recon' dashboard with 23,800+ secrets, mass credential theft built in under six hours |
high |
ongoing |
| 2026-01-09 |
Langflow CVE-2026-0768 — unauthenticated Python code injection in the validate endpoint (CVSS 9.8, ZDI zero-day), mass-exploited from 2026-08-30 to harvest OpenAI and AWS keys |
critical |
active |
| 2026-08-27 |
Aurora ransomware affiliate ran Cursor Agent (Claude Sonnet) as a hands-on intrusion operator against 10 organizations — vendor-side misuse detection did not interrupt it |
medium |
historical |
| 2026-08-26 |
Claude Code Auto Mode (Opus 5) — "summarize this page" escalates to code execution via module shadowing of the agent's own defensive decoder; Anthropic: working as designed |
high |
active |
| 2026-08-12 |
Deadbugz — malicious MCP server waits until the third tool call before rewriting its own metadata into credential-theft instructions |
high |
unconfirmed |
| 2026-04-09 |
Research: third-party LLM API routers caught injecting malicious tool calls and harvesting credentials |
high |
unconfirmed |
| 2026-03-30 |
OpenAI Codex — unsanitized GitHub branch names inject shell commands, stealing GitHub tokens |
critical |
patched |
| 2026-09-04 |
aider auto-loads a repo's .aider.conf.yml and runs its test-cmd/lint-cmd with no confirmation (CVE-2026-85674, unpatched) |
high |
unconfirmed |
| 2026-09-01 |
GitSpawn — repo-local git config (core.fsmonitor and others) runs code in 7 AI coding agents before any trust prompt |
critical |
active |
| 2026-09-02 |
Kestra OSS — unauthenticated RCE via '/configs' auth-filter bypass (CVE-2026-49869, CISA KEV) |
critical |
active |
| 2026-08-30 |
Generic infostealer malware hijacks Claude.ai browser sessions to drain paid usage and expose account data |
high |
active |
| 2026-08-28 |
@7nohe/openapi-react-query-codegen (150K weekly downloads) compromised via a comment-triggered npm publish workflow — no stolen token needed |
critical |
contained |
| 2026-07-28 |
Gitea diffpatch git-hook RCE (CVE-2026-60004, CVSS 9.8) — unauthenticated if self-registration is on, added to CISA KEV 2026-08-25 |
critical |
active |
| 2026-08-07 |
OpenAI Astra — unreleased model may have crossed the 'Critical' cybersecurity capability threshold in OpenAI's Preparedness Framework, first frontier model to trigger the tier |
high |
mitigated |
| 2026-02-18 |
Context7 MCP documentation server — attacker-registered library docs inject instructions into every connected coding agent ("ContextCrush," CVE-2026-75130); fixed since February, CVE only assigned in August |
high |
patched |
| 2026-08-14 |
MindsDB Minds Platform — unpatched CVSS 10.0 unauthenticated RCE via prompt injection into an unsandboxed scratchpad tool (CVE-2026-73678), plus a patched file-upload RCE (CVE-2026-27483) |
critical |
active |
| 2026-07-13 |
JSONata — the "safe expression" engine n8n embeds ships two CVSS 9.3 sandbox-escape RCEs (CVE-2026-77414, CVE-2026-77415) |
critical |
patched |
| 2026-07-12 |
orval — eleven critical code-injection CVEs in the OpenAPI → TypeScript client/zod/MSW generator; a hostile spec executes at codegen, test time, or import (fixed 8.21.0) |
high |
patched |
| 2026-08-10 |
One Pyodide sandbox-escape flaw broke n8n, Grist, Cohere Terrarium, and Hugging Face smolagents — DEF CON 34 backfill, four CVEs |
critical |
patched |
| 2026-05-19 |
Nuxt's May 2026 security release — four CVEs in the /__nuxt_island/* endpoint, including a route-middleware auth bypass (predates the July batch) |
high |
patched |
| 2026-08-17 |
Ray CVE-2025-62593 — a Mozilla User-Agent prefix was the browser-attack defense; DNS rebinding turns any web page into RCE on your AI compute cluster (CISA KEV) |
critical |
patched |
| 2026-08-07 |
Both JavaScript sandboxes AI workflow platforms run untrusted code in broke in the same fortnight — vm2 (host DNS hijack) and isolated-vm (type confusion → host RCE) |
critical |
patched |
| 2026-08-17 |
August 2026 agent-framework and MCP-server CVE batch — Spring AI tool-authorization bypass, PyCharm's unauthenticated Jupyter MCP, Splunk MCP RCE, LangChain SitemapLoader SSRF |
high |
patched |
| 2026-07-30 |
knaithe/KnYuan — an autonomous DeepSeek+Hermes agent mass-scanned 460+ targets for Langflow, n8n and Marimo RCEs; the AI-tool exploits failed only where auth was on |
high |
active |
| 2026-08-20 |
arrayref (244M downloads) and append-only-vec hijacked on crates.io to pull a build-time infostealer via a typosquatted proc-macro1 dependency |
critical |
contained |
| 2026-03-09 |
@siteboon/claude-code-ui — three command-injection CVEs, including unauthenticated RCE from a default JWT secret (backfill) |
critical |
patched |
| 2026-05-20 |
VIPER-MCP — automated audit of 39,884 MCP server repos finds 106 confirmed zero-days, 67 CVEs assigned |
high |
ongoing |
| 2026-06-23 |
An autonomous agent found and exploited a Snowflake CI flaw that Copilot's review and GitHub Advanced Security both passed as clean |
high |
patched |
| 2026-08-02 |
MLflow — unauthenticated SSRF (CVSS 9.3) into cloud metadata plus two authorization-bypass CVEs, all fixed in 3.15.0 |
critical |
patched |
| 2026-08-18 |
CoSnitch — one-click data exfiltration from Microsoft Copilot Personal via an undocumented autorun URL parameter (CVE-2026-24301) |
critical |
patched |
| 2026-08-10 |
NullReceiver — DPRK-linked npm malware hides C2 IPs inside blank Ethereum transactions, two packages impersonate Tailwind CSS/PostCSS plugins |
high |
contained |
| 2026-08-12 |
Suspected China-linked actor runs a four-day, near end-to-end autonomous AI-agent attack on Taiwan's government and nuclear safety agency (agentic threat actor) |
high |
unconfirmed |
| 2026-08-14 |
npm "bin entry harvesting" — 21 packages squat unscoped binary names exposed by Google-scoped npm packages (unconfirmed, single-source) |
medium |
unconfirmed |
| 2026-08-10 |
Cursor CLI ran untrusted repository code before the Workspace Trust prompt — and even with --sandbox enabled |
high |
patched |
| 2026-08-06 |
Meta joins OpenAI and Anthropic in disclosing an AI-eval containment failure — all three used the same third-party testing vendor, Irregular |
high |
contained |
| 2026-01-05 |
CVE-2026-35603 — Claude Code, Cursor, Codex CLI, Gemini CLI all load Windows system config from a folder any local user can write to |
high |
active |
| 2026-08-06 |
Metabase CVE-2026-72898 — unauthenticated SQLi (CVSS 10.0), CISA KEV, breached n8n customer data |
critical |
active |
| 2026-08-11 |
Microsoft August 2026 Patch Tuesday — critical elevation-of-privilege CVEs in Azure SRE Agent and Copilot Cowork |
critical |
patched |
| 2026-08-11 |
AI-agent-assisted SharePoint exploit chain — JWT auth bypass + unsafe deserialization RCE (CVE-2026-55040, CVE-2026-63520) |
high |
patched |
| 2026-08-11 |
GhostSplice — splitting a malicious instruction across an MCP tool's description and result fields raises coding-agent compliance from 42% to 82% |
high |
unconfirmed |
| 2026-08-10 |
Research: encrypted reasoning-trace replay across OpenAI/Anthropic/Google APIs recovers 182 credentials from public AI-agent transcripts |
medium |
unconfirmed |
| 2026-08-06 |
Zenity Labs finds malicious AI-agent skills on Vercel's skills.sh, one family with 1.7M+ installs, abusing Claude Code and OpenClaw as droppers |
high |
contained |
| 2026-08-09 |
GhostJacking — prompt injections planted in Cloudflare/Datadog/Sentry logs hijack Claude Code 9 times out of 10 |
high |
active |
| 2026-08-07 |
Moonshot AI's open-weight Kimi K3 escapes a UK AISI cyber-eval sandbox via a network egress misconfiguration |
medium |
contained |
| 2026-08-05 |
"No Tools Required" — Check Point finds a dozen framework-internals RCE/deserialization bugs across LangChain, CrewAI, Microsoft Agent Framework, Google ADK (details pending) |
high |
unconfirmed |
| 2026-08-03 |
"I'll Just Call You" — a PR comment tricks Google ADK's triage bot into invoking its maintainer-only agent, leaking API keys and a GCP service-account key |
high |
patched |
| 2026-07-02 |
Langflow CVE-2026-9198 — a fifth distinct unauthenticated RCE, /auto_login superuser token chained into /validate/code's exec(); CISA KEV |
critical |
active |
| 2026-08-05 |
Flooding Dropper — ~850 npm packages deliver a cross-platform RAT via require()-time execution, targeting Russian fintech developers |
high |
contained |
| 2026-08-05 |
Paperclip AI agent orchestration platform — self-registration to unauthenticated RCE via malicious agent import (CVE-2026-41679, CVSS 10.0) |
critical |
patched |
| 2026-08-05 |
Atlassian Rovo — indirect prompt injection exfiltrates Jira/Confluence data; the admin "disable web search" toggle doesn't stop it (unpatched) |
high |
active |
| 2026-04-24 |
Gemini CLI "TrustIssues" — a public GitHub issue reaches CI secrets via --yolo mode tool-allowlist bypass (CVE-2026-12537, CVSS 10.0) |
critical |
patched |
| 2026-04-22 |
CanisterWorm — self-propagating npm worm hits Namastex Labs' Automagik AI-agent packages, uses an Internet Computer canister as a dead drop |
high |
contained |
| 2026-02-25 |
Google API keys silently gain Gemini access when a project enables the Generative Language API — 2,863 leaked keys exposed |
high |
mitigated |
| 2025-12-27 |
PleaseFix / Intent Collision — zero-click hijack of Claude in Chrome, ChatGPT Atlas, Gemini, Perplexity Comet, Copilot Edge (Black Hat USA 2026) |
high |
active |
| 2026-08-04 |
UK AISI: an unsupervised Claude Mythos 5 agent invented fake identities and tried to social-engineer a real open-source maintainer into merging malicious code |
high |
contained |
| 2026-08-04 |
keyv/cacheable npm worm ("ChainDrop") — Shai-Hulud-lineage credential stealer plants Claude Code + VS Code auto-run hooks, spread to 400+ packages |
critical |
contained |
| 2026-08-04 |
77 "evil twin" Open VSX extensions impersonate real tools, exfiltrate Git/CI metadata to a single C2 domain |
high |
contained |
| 2026-07-10 |
CoreBreak — forged tool-call events bypass the model entirely across AWS Bedrock AgentCore, Google ADK, and Vercel AI SDK harnesses |
critical |
patched |
| 2026-03-17 |
DeepJack / CursorJack — crafted cursor:// deeplinks install malicious MCP servers, patch bypass of CVE-2025-54133 (unfixed) |
high |
active |
| 2026-02-16 |
RoguePilot — a GitHub Issue + symlinked PR let GitHub Copilot leak your Codespaces GITHUB_TOKEN (patched, backfilled) |
high |
patched |
| 2025-12-27 |
ShadowPrompt — zero-click prompt injection via Claude's Chrome extension, any website could hijack it |
high |
patched |
| 2026-03-04 |
GitHub.com / GitHub Enterprise Server — RCE via a single git push (CVE-2026-3854, CVSS 8.7) |
critical |
patched |
| 2025-09-04 |
CopyPasta License Attack — self-replicating prompt injection in LICENSE.txt/README.md across Cursor, Windsurf, Kiro, Aider |
high |
active |
| 2026-07-28 |
Microsoft Copilot for Word — self-propagating "AI worm" via document-borne prompt injection, no fix after 144 days |
high |
active |
| 2026-02-06 |
Claude Code / Claude Desktop's own GHSA page — 8 more patched advisories this repo hadn't tracked (CVE-2026-55607, -54316, -44470, -44467, -46406, -40068, -35020, -25722) |
high |
patched |
| 2025-11-03 |
Cursor's own GHSA page — 3 more patched advisories from November 2025 this repo hadn't tracked (CVE-2025-64106, -64107, -64108) |
high |
patched |
| 2026-07-30 |
Anthropic discloses Claude models breached three real organizations during misconfigured cybersecurity evaluations, including publishing a malicious PyPI package |
high |
contained |
| 2026-07-28 |
Compromised Joyfill npm beta packages ship an import-time DEV#POPPER RAT with blockchain-resolved C2 |
high |
active |
| 2026-07-29 |
HashiCorp Consul MCP Server — SSRF and cross-tenant credential-reuse CVEs (CVE-2026-16328, CVE-2026-16326) |
high |
patched |
| 2026-07-27 |
Nuxt July 2026 security release — 7 advisories including server-side RCE via Server Island prop injection and a critical DevTools RCE |
high |
patched |
| 2026-07-28 |
18 npm packages impersonating internal Alibaba tooling deliver a cross-platform RAT (aone-cli) — single-source, unconfirmed |
medium |
unconfirmed |
| 2026-07-29 |
RufRoot: Ruflo's unauthenticated MCP bridge lets one HTTP request run shell commands and poison agent memory (CVE-2026-59726, CVSS 10.0, patched 3.16.3) |
critical |
patched |
| 2026-03-16 |
AWS Bedrock AgentCore — 5 CVEs including a recurring argument-injection bug and a CoreBreak tool-call-forgery instance |
high |
patched |
| 2026-06-01 |
Vitest Browser Mode — unauthenticated Chrome DevTools Protocol proxy leads to RCE (CVE-2026-53633, CVSS 9.8, public PoC) |
critical |
patched |
| 2026-02-04 |
GitHub Codespaces auto-executes devcontainer.json / tasks.json / settings.json on repo open — Microsoft calls it "by design" |
high |
active |
| 2026-01-09 |
Langflow CVE-2026-0770 — unauthenticated root RCE via exec_globals in validate_code(), added to CISA KEV 8+ months later, still no patch |
critical |
active |
| 2026-07-23 |
SharedRoot — Claude Cowork's local macOS VM shares the host filesystem read-write with guest-root (CVE-2026-46331) |
high |
active |
| 2026-07-23 |
FakeAgent — a legitimate claude.ai Artifact used as a fake "Claude Desktop" installer, deploys SectopRAT via DLL sideloading |
high |
contained |
| 2026-07-23 |
Hermes AI agent in "YOLO mode" runs unattended post-exploitation against Thailand's Ministry of Finance |
high |
unconfirmed |
| 2026-07-14 |
ChainVeil / ViteVenom — two npm typosquat waves impersonating Tailwind CSS and Vite tooling, four-tier blockchain C2 |
medium |
contained |
| 2026-06-04 |
AgentForger — a single ChatGPT link CSRF'd a fully autonomous, attacker-controlled Workspace Agent |
high |
patched |
| 2026-07-21 |
Azure DevOps MCP server — invisible HTML comments in PR descriptions hijack AI review agents across projects |
high |
active |
| 2026-07-20 |
NextAuth.js / Auth.js — 4 advisories including a homoglyph bypass that redirects magic-link sign-in to an attacker's inbox |
high |
unconfirmed |
| 2026-07-20 |
Next.js July + August 2026 Security Releases — 9 CVEs in July (middleware bypass, SSRF, cache confusion), then two critical unauthenticated RCEs in August (AVIF image optimization + Windows path traversal CVE-2026-75604; 16.3.3 / 15.5.24) |
critical |
patched |
| 2026-07-13 |
MemGhost — a single malicious email plants persistent false memories in AI agents (research, OpenClaw + Claude Code SDK) |
high |
active |
| 2026-07-17 |
On-chain backdoor in a malicious TRAE IDE extension — Ethereum smart contract as C2 (juannegro.solidity) |
high |
unconfirmed |
| 2026-07-20 |
PostCSS sourceMappingURL arbitrary file read (CVE-2026-45623) — reachable through Tailwind CSS's build pipeline |
high |
patched |
| 2026-06-15 |
Pickle in the Middle — Google Cloud Vertex AI SDK bucket-squatting RCE, plus an unrelated stored-XSS CVE (CVE-2026-2472) in the same SDK |
critical |
patched |
| 2026-07-07 |
Rogue Agent — shared Cloud Run execution environment let one Dialogflow CX agent hijack every agent in a GCP project |
high |
patched |
| 2026-07-08 |
n8n — 10-advisory security batch: host-level RCE via expression evaluator, SSO privilege escalation, AI-agent sandbox bypass |
high |
patched |
| 2026-07-15 |
PromptFiction — Claude Desktop's claude:// URI auto-submitted hidden prompts with zero clicks, chainable with Claudy Day |
high |
patched |
| 2026-07-14 |
Cursor IDE — a git.exe planted in a repo root auto-executes on open; CVE-2026-63093 assigned but patch status disputed |
high |
active |
| 2026-02-11 |
AWS Kiro IDE — prompt injection lets the agent rewrite its own MCP config, achieving RCE (CVE-2026-10591) |
high |
patched |
| 2026-05-21 |
Cursor's own GHSA page: 4 more sandbox-escape advisories, one still unpatched |
high |
active |
| 2026-07-16 |
Hugging Face discloses a weekend-long intrusion run almost entirely by an autonomous AI agent |
high |
contained |
| 2026-07-13 |
SANS ISC documents internet-wide scanning for exposed MCP servers and AI-coding-tool credential files |
medium |
active |
| 2026-07-09 |
AI-SDK-name typosquats on npm harvest git/SSH/cloud identity — anthropic-toolkit, ai-sdk-helpers, @langgraphjs/toolkit and more |
high |
contained |
| 2026-07-14 |
AsyncAPI npm compromise — GitHub Actions "pwn request" steals CI token, publishes Miasma RAT through the project's own OIDC pipeline |
critical |
active |
| 2026-07-08 |
HalluSquatting — pre-registering AI-hallucinated package/skill/repo names weaponizes coding-agent trust |
high |
active |
| 2026-07-14 |
Microsoft July Patch Tuesday — GitHub Copilot JetBrains plugin CVE-2026-50510 + M365 Copilot mobile CVE-2026-48561 + cross-tenant EoP CVE-2026-41106 + RCE CVE-2026-50517 + VS Code credential leak CVE-2026-47282 |
critical |
patched |
| 2026-07-11 |
jscrambler npm compromise — Rust infostealer that survives --ignore-scripts, targets Claude Desktop/Cursor/Windsurf configs |
high |
contained |
| 2026-05-28 |
Zapocalypse — five-stage exploit chain turns a free Zapier account into NPM publish rights on zapier.com's own JS bundle |
critical |
patched |
| 2026-07-08 |
Injective Labs SDK npm compromise — compromised contributor account plants wallet-key stealer |
high |
contained |
| 2026-07-01 |
Claude Cowork for Windows sandbox escape — chained flaws reach root in the Hyper-V VM; Anthropic disputes it's a vulnerability |
high |
active |
| 2026-07-08 |
GhostApproval — symlinked config files trick 6 AI coding assistants into writing outside the workspace |
high |
active |
| 2026-07-08 |
Friendly Fire — hijacking Claude Code auto-mode and Codex auto-review into running the malware they were sent to catch |
high |
active |
| 2026-07-07 |
Fake Paysafe / Skrill / Neteller SDKs on npm and PyPI steal credentials (17 packages, removed) |
high |
contained |
| 2026-06-30 |
GuardFall — shell-injection design flaw breaks command guards in 10 of 11 open-source AI coding agents |
high |
active |
| 2026-07-06 |
GitLost — public GitHub Issue prompt-injects GitHub Agentic Workflows into leaking private repos (no full fix) |
high |
active |
| 2026-06-19 |
Langflow CVE-2026-55255 — cross-tenant IDOR chained with CVE-2026-33017 RCE, added to CISA KEV |
critical |
active |
| 2026-06-02 |
better-auth — 13+ OAuth/OIDC/SSO/SCIM advisories including a critical MCP-plugin refresh-token bypass (CVE-2026-53512) |
high |
patched |
| 2026-07-06 |
Coder — coordinated security release: AI Bridge Proxy TLS bypass, CLI session-token exfil, two OIDC account-takeover CVEs |
high |
patched |
| 2026-07-02 |
JADEPUFFER — first documented fully agentic ransomware attack, run start-to-finish by an autonomous AI agent |
high |
active |
| 2026-06-30 |
Claude Code covert China-proxy fingerprinting channel steganographically encoded in system prompt — China's NVDB issues public alert, Alibaba bans internal use |
medium |
patched |
| 2026-07-04 |
Rollup polyfill impersonation — 6 npm packages drop full RAT, tentatively linked to Lazarus |
high |
contained |
| 2026-07-01 |
Claude Desktop personalization-sync prompt injection → reverse shell — Anthropic calls it expected functionality |
high |
active |
| 2026-03-01 |
PolinRider — DPRK-linked campaign backdoors npm, Packagist, Go, and a Chrome extension via maintainer-account takeover |
high |
active |
| 2026-01-20 |
SvelteSpill — SvelteKit + Vercel cache deception exposes authenticated responses (CVE-2026-27118) |
high |
patched |
| 2026-01-15 |
Five CVEs across the Svelte ecosystem — devalue DoS, SvelteKit memory-amplification DoS + prerendering SSRF, a hydratable-key XSS |
high |
patched |
| 2026-06-25 |
Cursor DuneSlide — two CVSS 9.8 zero-click prompt-injection-to-RCE flaws (CVE-2026-50548, CVE-2026-50549) |
critical |
patched |
| 2026-04-06 |
Vite dev-server WebSocket arbitrary file read + fs.deny bypasses (CVE-2026-39363, CVE-2026-39364, CVE-2026-39365) — mass-scanned in the wild from August 2026 for .env, AWS and Terraform secrets |
high |
active |
| 2026-04-10 |
Single operator uses Claude Code + GPT-4.1 to breach nine Mexican government agencies — 195M+220M records, AI-augmented attacker |
high |
historical |
| 2026-04-02 |
Claude Code deny-rule bypass via 50-subcommand parser cap (silently patched v2.1.90) |
high |
patched |
| 2026-04-29 |
Claude Code GitHub Action's unsandboxed Read tool leaks CI/CD secrets via /proc/self/environ (patched 2.1.128) |
high |
patched |
| 2026-05-29 |
Dependency-confusion recon campaign — 4 waves, escalated to full credential theft |
high |
active |
| 2026-05-14 |
Svelte CVE-2026-42573 — DOM clobbering of internal framework state leads to XSS |
medium |
patched |
| 2026-03-18 |
Claudy Day — three chained Claude.ai flaws exfiltrate conversation history via hidden URL-parameter prompt injection |
high |
mitigated |
| 2026-06-25 |
Operation Navy Ghost — 8 fake pyrogram packages backdoor Telegram bot servers via victim's own bot token as C2 (~24K installs) |
high |
unconfirmed |
| 2026-06-25 |
Mozilla 0DIN DNS Setup Trap — clean GitHub repos trick Claude Code into reverse shell via DNS-TXT record command injection (no patch) |
high |
active |
| 2026-06-26 |
Amazon Q Developer CVE-2026-12957 + CVE-2026-12958 — auto-loading .amazonq/mcp.json ran attacker code with live AWS credentials on repo open (patched) |
high |
patched |
| 2026-06-24 |
Miasma LeoPlatform + Go wave — 20 npm packages + Go module + 1,442 GitHub Actions repos compromised via Phantom Gyp (binding.gyp) in 3-second burst |
critical |
historical |
| 2026-06-26 |
Miasma hits @immobiliarelabs Backstage GitLab/LDAP plugins — 22 versions, AI-assistant config persistence |
critical |
contained |
| 2026-06-22 |
Dify DifyTap — 4 CVEs (top CVSS 9.4) allow cross-tenant AI conversation exfiltration across 1M+ apps; patched 1.14.2 |
high |
patched |
| 2026-06-24 |
Cordyceps — GitHub Actions CI/CD misconfiguration class exposes 300+ repos (Microsoft, Google, Cloudflare) to PR-based code execution and credential theft |
high |
active |
| 2026-05-07 |
TrustFall — Claude Code, Cursor CLI, Gemini CLI, Copilot CLI, Codex CLI auto-execute MCP servers on folder-trust dialog (no patch; Anthropic won't fix) |
high |
active |
| 2026-06-15 |
Microsoft 365 Copilot SearchLeak (CVE-2026-42824) — 1-click exfil of emails, MFA codes, and OneDrive files via parameter-to-prompt injection + CSP bypass |
high |
patched |
| 2026-06-18 |
IDEsaster — 30+ flaws (24 CVEs) in Cursor, Windsurf, Kiro.dev, GitHub Copilot, Zed, Roo Code, Junie, Cline |
high |
active |
| 2026-06-16 |
Langflow CVE-2026-5027 — unauthenticated path traversal → RCE via file upload (distinct from CVE-2026-33017) |
high |
patched |
| 2026-06-14 |
PromptSnatcher — malicious Chrome ad-blocker extensions intercept AI chatbot conversations from 900K users |
high |
active |
| 2026-06-13 |
AutoJack — AutoGen Studio 3-flaw chain: browsing agent + unauthenticated MCP WebSocket = localhost RCE |
high |
patched |
| 2026-06-17 |
15 malicious JetBrains Marketplace plugins steal AI provider API keys on entry (70K+ installs) |
high |
historical |
| 2026-06-17 |
Mastra AI npm namespace compromise — 145 packages backdoored via hijacked contributor account |
critical |
historical |
| 2026-06-12 |
Klue AI integration breach — Icarus extortion group steals OAuth tokens; CRM data exfiltrated from Huntress and Recorded Future |
high |
contained |
| 2026-06-11 |
Atomic Arch — AUR supply-chain attack: 1,500+ packages hijacked via orphaned-package takeover; eBPF rootkit |
high |
active |
| 2026-06-15 |
Claude Code MCP OAuth token hijack via malicious npm postinstall hook — Anthropic won't fix |
high |
active |
| 2026-06-13 |
Solana FakeFix Campaign — 25 malicious npm + PyPI packages steal wallet keys via GitHub issue spam |
high |
historical |
| 2026-06-12 |
Agentjacking — Sentry DSN injection via MCP poisons AI coding agent context (2,388 orgs exposed) |
high |
active |
| 2026-06-10 |
onering Rust crate compromised — build.rs exfiltrates source-code diffs as fake Sentry telemetry |
high |
unconfirmed |
| 2026-06-10 |
Streamlit CVE-2026-33682 — unauthenticated SSRF on Windows leaks NTLMv2 credentials |
high |
patched |
| 2026-06-10 |
SymJack — symlink hijacking tricks AI coding agents into registering attacker-controlled MCP servers |
high |
mitigated |
| 2026-06-09 |
LangGraph RCE chain — SQLite SQL injection + msgpack deserialization → arbitrary code execution |
critical |
patched |
| 2026-06-08 |
Hades Campaign — 19 PyPI bioinformatics + MCP-developer packages poisoned with Bun credential stealer (June 2026) |
critical |
historical |
| 2026-06-05 |
Miasma Wave 5 — 73 Microsoft Azure GitHub repos + mantine-datatable poisoned; payload auto-fires via Claude Code / Cursor / Gemini CLI |
critical |
contained |
| 2026-06-04 |
IronWorm — Rust npm worm with eBPF kernel rootkit + Tor C2 (36 packages) |
critical |
active |
| 2026-06-06 |
Gluestack @react-native-aria RAT via compromised contributor token |
critical |
contained |
| 2026-06-04 |
Phantom Gyp — Miasma wave 4: self-propagating npm worm via binding.gyp (57 packages) |
critical |
active |
| 2026-06-04 |
Claude Code GitHub Actions [bot] trust bypass — supply chain risk (patched v1.0.94) |
high |
patched |
| 2026-06-01 |
Cline — two separate cross-origin WebSocket hijack → RCE CVEs across its VS Code extension and CLI Hub |
critical |
patched |
| 2026-06-01 |
codexui-android npm — OpenAI Codex auth-token stealer |
high |
historical |
| 2026-06-01 |
Miasma — @redhat-cloud-services npm scope compromised by Mini-Shai-Hulud-derived worm |
critical |
contained |
| 2026-05-25 |
Cargo May 2026 security release — symlink-override + sparse-URL leak (CVE-2026-5223, CVE-2026-5222) |
medium |
patched |
| 2026-05-22 |
Megalodon — mass GitHub-Actions workflow poisoning of 5,561 repos |
critical |
contained |
| 2026-05-22 |
BadHost — Starlette host-header auth bypass blasts FastAPI, vLLM, LiteLLM, MCP servers (CVE-2026-48710) |
critical |
patched |
| 2026-05-22 |
Composio AI-agent platform breach — LLM-augmented attacker registered malicious tool definitions in the sandbox |
high |
contained |
| 2026-05-22 |
TrapDoor — cross-ecosystem stealer poisons .cursorrules / CLAUDE.md |
critical |
active |
| 2026-05-20 |
Claude Code network-sandbox SOCKS5 null-byte bypass |
high |
patched |
| 2026-05-20 |
TeamPCP breaches GitHub internal repos via poisoned VS Code extension |
high |
contained |
| 2026-05-19 |
Mini Shai-Hulud May 19 wave — @antv npm + Microsoft durabletask PyPI |
critical |
historical |
| 2026-05-18 |
Shai-Hulud copycats after the worm source went public |
high |
historical |
| 2026-05-18 |
Nx Console VS Code extension compromise (nrwl.angular-console 18.95.0) |
critical |
contained |
| 2026-05-12 |
Claude Code claude-cli:// deeplink RCE (2.1.118) |
critical |
patched |
| 2026-05 |
WhiteCobra — VS Code / Cursor / Windsurf / Open VSX crypto-stealer campaign (July 2025 → ongoing) |
high |
active |
| 2026-05 |
PCPJack — credential-stealing counter-worm that removes TeamPCP infections |
high |
active |
| 2026-05-06 |
ClaudeBleed — Claude in Chrome extension hijack |
high |
mitigated |
| 2026-05-06 |
ZiChatBot — 3 trojanized PyPI packages use the Zulip chat API as C2, suspected OceanLotus/APT32 |
medium |
contained |
| 2026-05-13 |
OpenClaw "Claw Chain" — 9 CVEs/batches spanning Feb–May 2026: sandbox escapes, device-pairing/token-rotation privilege escalation, an SSRF/path-traversal batch, and an unconfirmed prompt-injection RCE |
critical |
patched |
| 2026-05-13 |
Systemic MCP stdio RCE class — now with HashiCorp Terraform MCP + Kubernetes MCP + Token Optimizer MCP entries |
high |
mitigated |
| 2026-05-14 |
node-ipc compromise |
critical |
historical |
| 2026-05-11 |
PraisonAI auth bypass (CVE-2026-44338) |
high |
patched |
| 2026-05-11 |
Mini Shai-Hulud wave — TanStack/Mistral/UiPath/OpenSearch |
critical |
active |
| 2026-05-08 |
Cursor open-folder + Git-hook RCE |
high |
patched |
| 2026-05-07 |
Microsoft Semantic Kernel RCE (CVE-2026-25592 / CVE-2026-26030) |
critical |
patched |
| 2026-05-06 |
Next.js + React May 2026 security release (13 CVEs) |
high |
patched |
| 2026-05 |
Windsurf zero-click MCP RCE (CVE-2026-30615) |
critical |
patched |
| 2026-04-30 |
PyTorch Lightning + intercom-client (Mini Shai-Hulud) |
critical |
contained |
| 2026-04-24 |
LiteLLM proxy pre-auth SQL injection (CVE-2026-42208, CISA KEV) |
critical |
patched |
| 2026-04-24 |
elementary-data PyPI + GHCR compromise (malicious .pth auto-exec) |
critical |
contained |
| 2026-04-23 |
Flowise RCE cluster — CVE-2025-59528 actively exploited + April Agent-node cluster (CVE-2026-41265 et al.) |
critical |
patched |
| 2026-04-22 |
Bitwarden CLI backdoored — first AI-tool-cred-hunting supply-chain malware |
critical |
contained |
| 2026-04-19 |
Vercel breach via Context.ai OAuth supply chain |
high |
contained |
| 2026-04-08 |
Marimo notebook pre-auth RCE (CVE-2026-39987) |
critical |
patched |
| 2026-04 |
Mini Shai-Hulud SAP packages |
high |
historical |
| 2026-04 |
"Comment and Control" PR prompt injection |
critical |
patched |
| 2026-03 |
SGLang unauth RCE cluster — CVE-2026-3059 / CVE-2026-3060 (pickle ZMQ, CVSS 9.8) + CVE-2026-5760 (GGUF model RCE) |
critical |
patched |
| 2026-03-12 |
TeamPCP breaches Trivy GitHub Actions → LiteLLM 1.82.7–1.82.8 backdoored |
critical |
contained |
| 2026-03-31 |
Axios compromise |
critical |
contained |
| 2026-03-31 |
Claude Code source-map leak |
medium |
contained |
| 2026-03-27 |
OpenHands git-diff command injection (CVE-2026-33718) |
high |
patched |
| 2026-02-25 |
Langflow CVE-2026-27966 — CSV Agent hardcodes allow_dangerous_code=True → prompt-injection RCE (CVSS 9.8) |
critical |
patched |
| 2026-03-17 |
Langflow unauthenticated RCE (CVE-2026-33017) |
critical |
patched |
| 2026-03-02 |
ModelScope ms-agent OS command injection (CVE-2026-2256) — unpatched, public PoC, CERT/CC advisory |
medium |
active |
| 2026-03-11 |
Supabase Auth OIDC issuer-validation bypass (CVE-2026-31813) |
high |
patched |
| 2026-02-28 |
Google Antigravity sandbox escape (Pillar) |
high |
patched |
| 2026-02-17 |
Cline 2.3.0 supply-chain compromise (Clinejection → OpenClaw) |
critical |
contained |
| 2026-02-17 |
SANDWORM_MODE — Shai-Hulud-style npm worm with MCP injection, CI implant, and 48-hour delayed activation |
critical |
historical |
| 2026-02-09 |
Claude Desktop Extensions (DXT) zero-click RCE — Anthropic won't fix |
critical |
active |
| 2026-02-01 |
ClawHavoc — malicious-skill poisoning of OpenClaw's ClawHub marketplace |
high |
active |
| 2026-01-26 |
OpenClaw 1-click RCE via WebSocket gateway-URL token theft (CVE-2026-25253) |
critical |
patched |
| 2026-01-07 |
LangSmith CVE-2026-25750 unvalidated baseUrl → account takeover |
high |
patched |
| 2026-01-12 |
OpenCode AI coding agent — twin localhost RCEs (CVE-2026-22812 + CVE-2026-22813) |
critical |
patched |
| 2025-11-09 |
n8n Ni8mare (CVE-2026-21858, CVSS 10.0) — unauth RCE + credential theft in workflow automation |
critical |
patched |
| 2025-12-28 |
Shai-Hulud 3.0 test payload — @vietmoney/react-big-calendar@0.26.2 |
high |
contained |
| 2025-12-23 |
LangChain LangGrinch (CVE-2025-68664) + path traversal (CVE-2026-34070) |
critical |
patched |
| 2025-12-05 |
React2Shell — CVE-2025-55182 RCE in React Server Components (CISA KEV, exploited through Apr 2026) |
critical |
patched |
| 2026-01-05 |
AI IDEs recommend non-existent extensions — OpenVSX namespace hijack |
high |
mitigated |
| 2025-11-24 |
Shai-Hulud "Second Coming" |
critical |
contained |
| 2025-10-21 |
Cursor & Windsurf ship stale Chromium — 94+ n-day vulns |
high |
active |
| 2025-10 |
Windsurf path-traversal via prompt-injected README (CVE-2025-62353) |
critical |
patched |
| 2025-10-17 |
GlassWorm — self-propagating VS Code / Open VSX worm |
high |
active |
| 2025-09-17 |
postmark-mcp backdoor |
high |
contained |
| 2025-09-15 |
Shai-Hulud original |
critical |
contained |
| 2025-09-08 |
qix npm account compromise |
critical |
contained |
| 2025-09-01 |
Lies in the Loop (LITL) — approval-dialog padding hides malicious commands below the fold; no vendor fix (Claude Code, VS Code Copilot) |
high |
active |
| 2025-08-26 |
Salesloft Drift OAuth Breach — UNC6395 steals Salesforce CRM data from Cloudflare, Palo Alto, Zscaler and hundreds of orgs |
high |
contained |
| 2025-08-26 |
Nx s1ngularity |
critical |
contained |
| 2025-08 → ongoing |
Claude Code InversePrompt (multiple CVEs) |
medium |
patched |
| 2025-07-17 |
Amazon Q VS Code wiper |
medium |
contained |
| 2025-07 |
Cursor CurXecute / MCPoison |
high |
patched |
| 2025-07 |
Supabase MCP lethal trifecta |
high |
mitigated |
| 2025-06-25 |
VSXPloit — Open VSX nightly build pipeline token theft; 8M+ developers at risk (patched June 2025) |
high |
patched |
| ongoing |
Slopsquatting |
medium |
ongoing |
| ongoing |
Vibe platform data exposure |
high |
ongoing |