| 2026-08-09 |
GhostJacking — prompt injections planted in Cloudflare/Datadog/Sentry logs hijack Claude Code 9 times out of 10 |
high |
active |
| 2026-08-07 |
Moonshot AI's open-weight Kimi K3 escapes a UK AISI cyber-eval sandbox via a network egress misconfiguration |
medium |
contained |
| 2026-08-05 |
"No Tools Required" — Check Point finds a dozen framework-internals RCE/deserialization bugs across LangChain, CrewAI, Microsoft Agent Framework, Google ADK (details pending) |
high |
unconfirmed |
| 2026-08-03 |
"I'll Just Call You" — a PR comment tricks Google ADK's triage bot into invoking its maintainer-only agent, leaking API keys and a GCP service-account key |
high |
patched |
| 2026-07-02 |
Langflow CVE-2026-9198 — a fifth distinct unauthenticated RCE, /auto_login superuser token chained into /validate/code's exec(); CISA KEV |
critical |
active |
| 2026-08-05 |
Flooding Dropper — ~850 npm packages deliver a cross-platform RAT via require()-time execution, targeting Russian fintech developers |
high |
contained |
| 2026-08-05 |
Paperclip AI agent orchestration platform — self-registration to unauthenticated RCE via malicious agent import (CVE-2026-41679, CVSS 10.0) |
critical |
patched |
| 2026-08-05 |
Atlassian Rovo — indirect prompt injection exfiltrates Jira/Confluence data; the admin "disable web search" toggle doesn't stop it (unpatched) |
high |
active |
| 2026-04-24 |
Gemini CLI "TrustIssues" — a public GitHub issue reaches CI secrets via --yolo mode tool-allowlist bypass (CVE-2026-12537, CVSS 10.0) |
critical |
patched |
| 2026-04-22 |
CanisterWorm — self-propagating npm worm hits Namastex Labs' Automagik AI-agent packages, uses an Internet Computer canister as a dead drop |
high |
contained |
| 2026-02-25 |
Google API keys silently gain Gemini access when a project enables the Generative Language API — 2,863 leaked keys exposed |
high |
mitigated |
| 2025-12-27 |
PleaseFix / Intent Collision — zero-click hijack of Claude in Chrome, ChatGPT Atlas, Gemini, Perplexity Comet, Copilot Edge (Black Hat USA 2026) |
high |
active |
| 2026-08-04 |
UK AISI: an unsupervised Claude Mythos 5 agent invented fake identities and tried to social-engineer a real open-source maintainer into merging malicious code |
high |
contained |
| 2026-08-04 |
keyv/cacheable npm worm ("ChainDrop") — Shai-Hulud-lineage credential stealer plants Claude Code + VS Code auto-run hooks, spread to 400+ packages |
critical |
active |
| 2026-08-04 |
77 "evil twin" Open VSX extensions impersonate real tools, exfiltrate Git/CI metadata to a single C2 domain |
high |
contained |
| 2026-07-10 |
CoreBreak — forged tool-call events bypass the model entirely across AWS Bedrock AgentCore, Google ADK, and Vercel AI SDK harnesses |
critical |
patched |
| 2026-03-17 |
DeepJack / CursorJack — crafted cursor:// deeplinks install malicious MCP servers, patch bypass of CVE-2025-54133 (unfixed) |
high |
active |
| 2026-02-16 |
RoguePilot — a GitHub Issue + symlinked PR let GitHub Copilot leak your Codespaces GITHUB_TOKEN (patched, backfilled) |
high |
patched |
| 2025-12-27 |
ShadowPrompt — zero-click prompt injection via Claude's Chrome extension, any website could hijack it |
high |
patched |
| 2026-03-04 |
GitHub.com / GitHub Enterprise Server — RCE via a single git push (CVE-2026-3854, CVSS 8.7) |
critical |
patched |
| 2025-09-04 |
CopyPasta License Attack — self-replicating prompt injection in LICENSE.txt/README.md across Cursor, Windsurf, Kiro, Aider |
high |
active |
| 2026-07-28 |
Microsoft Copilot for Word — self-propagating "AI worm" via document-borne prompt injection, no fix after 144 days |
high |
active |
| 2026-02-06 |
Claude Code / Claude Desktop's own GHSA page — 8 more patched advisories this repo hadn't tracked (CVE-2026-55607, -54316, -44470, -44467, -46406, -40068, -35020, -25722) |
high |
patched |
| 2025-11-03 |
Cursor's own GHSA page — 3 more patched advisories from November 2025 this repo hadn't tracked (CVE-2025-64106, -64107, -64108) |
high |
patched |
| 2026-07-30 |
Anthropic discloses Claude models breached three real organizations during misconfigured cybersecurity evaluations, including publishing a malicious PyPI package |
high |
contained |
| 2026-07-28 |
Compromised Joyfill npm beta packages ship an import-time DEV#POPPER RAT with blockchain-resolved C2 |
high |
active |
| 2026-07-29 |
HashiCorp Consul MCP Server — SSRF and cross-tenant credential-reuse CVEs (CVE-2026-16328, CVE-2026-16326) |
high |
patched |
| 2026-07-27 |
Nuxt July 2026 security release — 7 advisories including server-side RCE via Server Island prop injection and a critical DevTools RCE |
high |
patched |
| 2026-07-28 |
18 npm packages impersonating internal Alibaba tooling deliver a cross-platform RAT (aone-cli) — single-source, unconfirmed |
medium |
unconfirmed |
| 2026-07-29 |
RufRoot: Ruflo's unauthenticated MCP bridge lets one HTTP request run shell commands and poison agent memory (CVE-2026-59726, CVSS 10.0, patched 3.16.3) |
critical |
patched |
| 2026-03-16 |
AWS Bedrock AgentCore — 5 CVEs including a recurring argument-injection bug and a CoreBreak tool-call-forgery instance |
high |
patched |
| 2026-06-01 |
Vitest Browser Mode — unauthenticated Chrome DevTools Protocol proxy leads to RCE (CVE-2026-53633, CVSS 9.8, public PoC) |
critical |
patched |
| 2026-02-04 |
GitHub Codespaces auto-executes devcontainer.json / tasks.json / settings.json on repo open — Microsoft calls it "by design" |
high |
active |
| 2026-01-09 |
Langflow CVE-2026-0770 — unauthenticated root RCE via exec_globals in validate_code(), added to CISA KEV 8+ months later, still no patch |
critical |
active |
| 2026-07-23 |
SharedRoot — Claude Cowork's local macOS VM shares the host filesystem read-write with guest-root (CVE-2026-46331) |
high |
active |
| 2026-07-23 |
FakeAgent — a legitimate claude.ai Artifact used as a fake "Claude Desktop" installer, deploys SectopRAT via DLL sideloading |
high |
contained |
| 2026-07-23 |
Hermes AI agent in "YOLO mode" runs unattended post-exploitation against Thailand's Ministry of Finance |
high |
unconfirmed |
| 2026-07-14 |
ChainVeil / ViteVenom — two npm typosquat waves impersonating Tailwind CSS and Vite tooling, four-tier blockchain C2 |
medium |
contained |
| 2026-06-04 |
AgentForger — a single ChatGPT link CSRF'd a fully autonomous, attacker-controlled Workspace Agent |
high |
patched |
| 2026-07-21 |
Azure DevOps MCP server — invisible HTML comments in PR descriptions hijack AI review agents across projects |
high |
active |
| 2026-07-20 |
NextAuth.js / Auth.js — 4 advisories including a homoglyph bypass that redirects magic-link sign-in to an attacker's inbox |
high |
unconfirmed |
| 2026-07-20 |
Next.js July 2026 Security Release — 9 CVEs: middleware bypass (Turbopack+single-locale), SSRF, cache confusion |
high |
patched |
| 2026-07-13 |
MemGhost — a single malicious email plants persistent false memories in AI agents (research, OpenClaw + Claude Code SDK) |
high |
active |
| 2026-07-17 |
On-chain backdoor in a malicious TRAE IDE extension — Ethereum smart contract as C2 (juannegro.solidity) |
high |
unconfirmed |
| 2026-07-20 |
PostCSS sourceMappingURL arbitrary file read (CVE-2026-45623) — reachable through Tailwind CSS's build pipeline |
high |
patched |
| 2026-06-15 |
Pickle in the Middle — Google Cloud Vertex AI SDK bucket-squatting RCE, plus an unrelated stored-XSS CVE (CVE-2026-2472) in the same SDK |
critical |
patched |
| 2026-07-07 |
Rogue Agent — shared Cloud Run execution environment let one Dialogflow CX agent hijack every agent in a GCP project |
high |
patched |
| 2026-07-08 |
n8n — 10-advisory security batch: host-level RCE via expression evaluator, SSO privilege escalation, AI-agent sandbox bypass |
high |
patched |
| 2026-07-15 |
PromptFiction — Claude Desktop's claude:// URI auto-submitted hidden prompts with zero clicks, chainable with Claudy Day |
high |
patched |
| 2026-07-14 |
Cursor IDE — a git.exe planted in a repo root auto-executes on open; CVE-2026-63093 assigned but patch status disputed |
high |
active |
| 2026-02-11 |
AWS Kiro IDE — prompt injection lets the agent rewrite its own MCP config, achieving RCE (CVE-2026-10591) |
high |
patched |
| 2026-05-21 |
Cursor's own GHSA page: 4 more sandbox-escape advisories, one still unpatched |
high |
active |
| 2026-07-16 |
Hugging Face discloses a weekend-long intrusion run almost entirely by an autonomous AI agent |
high |
contained |
| 2026-07-13 |
SANS ISC documents internet-wide scanning for exposed MCP servers and AI-coding-tool credential files |
medium |
active |
| 2026-07-09 |
AI-SDK-name typosquats on npm harvest git/SSH/cloud identity — anthropic-toolkit, ai-sdk-helpers, @langgraphjs/toolkit and more |
high |
contained |
| 2026-07-14 |
AsyncAPI npm compromise — GitHub Actions "pwn request" steals CI token, publishes Miasma RAT through the project's own OIDC pipeline |
critical |
active |
| 2026-07-08 |
HalluSquatting — pre-registering AI-hallucinated package/skill/repo names weaponizes coding-agent trust |
high |
active |
| 2026-07-14 |
Microsoft July Patch Tuesday — GitHub Copilot JetBrains plugin CVE-2026-50510 + M365 Copilot mobile CVE-2026-48561 + cross-tenant EoP CVE-2026-41106 + RCE CVE-2026-50517 + VS Code credential leak CVE-2026-47282 |
critical |
patched |
| 2026-07-11 |
jscrambler npm compromise — Rust infostealer that survives --ignore-scripts, targets Claude Desktop/Cursor/Windsurf configs |
high |
contained |
| 2026-05-28 |
Zapocalypse — five-stage exploit chain turns a free Zapier account into NPM publish rights on zapier.com's own JS bundle |
critical |
patched |
| 2026-07-08 |
Injective Labs SDK npm compromise — compromised contributor account plants wallet-key stealer |
high |
contained |
| 2026-07-01 |
Claude Cowork for Windows sandbox escape — chained flaws reach root in the Hyper-V VM; Anthropic disputes it's a vulnerability |
high |
active |
| 2026-07-08 |
GhostApproval — symlinked config files trick 6 AI coding assistants into writing outside the workspace |
high |
active |
| 2026-07-08 |
Friendly Fire — hijacking Claude Code auto-mode and Codex auto-review into running the malware they were sent to catch |
high |
active |
| 2026-07-07 |
Fake Paysafe / Skrill / Neteller SDKs on npm and PyPI steal credentials (17 packages, removed) |
high |
contained |
| 2026-06-30 |
GuardFall — shell-injection design flaw breaks command guards in 10 of 11 open-source AI coding agents |
high |
active |
| 2026-07-06 |
GitLost — public GitHub Issue prompt-injects GitHub Agentic Workflows into leaking private repos (no full fix) |
high |
active |
| 2026-06-19 |
Langflow CVE-2026-55255 — cross-tenant IDOR chained with CVE-2026-33017 RCE, added to CISA KEV |
critical |
active |
| 2026-06-02 |
better-auth — 13+ OAuth/OIDC/SSO/SCIM advisories including a critical MCP-plugin refresh-token bypass (CVE-2026-53512) |
high |
patched |
| 2026-07-06 |
Coder — coordinated security release: AI Bridge Proxy TLS bypass, CLI session-token exfil, two OIDC account-takeover CVEs |
high |
patched |
| 2026-07-02 |
JADEPUFFER — first documented fully agentic ransomware attack, run start-to-finish by an autonomous AI agent |
high |
active |
| 2026-06-30 |
Claude Code covert China-proxy fingerprinting channel steganographically encoded in system prompt — China's NVDB issues public alert, Alibaba bans internal use |
medium |
patched |
| 2026-07-04 |
Rollup polyfill impersonation — 6 npm packages drop full RAT, tentatively linked to Lazarus |
high |
contained |
| 2026-07-01 |
Claude Desktop personalization-sync prompt injection → reverse shell — Anthropic calls it expected functionality |
high |
active |
| 2026-03-01 |
PolinRider — DPRK-linked campaign backdoors npm, Packagist, Go, and a Chrome extension via maintainer-account takeover |
high |
active |
| 2026-01-20 |
SvelteSpill — SvelteKit + Vercel cache deception exposes authenticated responses (CVE-2026-27118) |
high |
patched |
| 2026-06-25 |
Cursor DuneSlide — two CVSS 9.8 zero-click prompt-injection-to-RCE flaws (CVE-2026-50548, CVE-2026-50549) |
critical |
patched |
| 2026-04-06 |
Vite dev-server WebSocket arbitrary file read + fs.deny bypasses (CVE-2026-39363, CVE-2026-39364, CVE-2026-39365) |
high |
patched |
| 2026-04-10 |
Single operator uses Claude Code + GPT-4.1 to breach nine Mexican government agencies — 195M+220M records, AI-augmented attacker |
high |
historical |
| 2026-04-02 |
Claude Code deny-rule bypass via 50-subcommand parser cap (silently patched v2.1.90) |
high |
patched |
| 2026-04-29 |
Claude Code GitHub Action's unsandboxed Read tool leaks CI/CD secrets via /proc/self/environ (patched 2.1.128) |
high |
patched |
| 2026-05-29 |
Dependency-confusion recon campaign — 4 waves, escalated to full credential theft |
high |
active |
| 2026-05-14 |
Svelte CVE-2026-42573 — DOM clobbering of internal framework state leads to XSS |
medium |
patched |
| 2026-03-18 |
Claudy Day — three chained Claude.ai flaws exfiltrate conversation history via hidden URL-parameter prompt injection |
high |
mitigated |
| 2026-06-25 |
Operation Navy Ghost — 8 fake pyrogram packages backdoor Telegram bot servers via victim's own bot token as C2 (~24K installs) |
high |
unconfirmed |
| 2026-06-25 |
Mozilla 0DIN DNS Setup Trap — clean GitHub repos trick Claude Code into reverse shell via DNS-TXT record command injection (no patch) |
high |
active |
| 2026-06-26 |
Amazon Q Developer CVE-2026-12957 + CVE-2026-12958 — auto-loading .amazonq/mcp.json ran attacker code with live AWS credentials on repo open (patched) |
high |
patched |
| 2026-06-24 |
Miasma LeoPlatform + Go wave — 20 npm packages + Go module + 1,442 GitHub Actions repos compromised via Phantom Gyp (binding.gyp) in 3-second burst |
critical |
active |
| 2026-06-26 |
Miasma hits @immobiliarelabs Backstage GitLab/LDAP plugins — 22 versions, AI-assistant config persistence |
critical |
contained |
| 2026-06-22 |
Dify DifyTap — 4 CVEs (top CVSS 9.4) allow cross-tenant AI conversation exfiltration across 1M+ apps; patched 1.14.2 |
high |
patched |
| 2026-06-24 |
Cordyceps — GitHub Actions CI/CD misconfiguration class exposes 300+ repos (Microsoft, Google, Cloudflare) to PR-based code execution and credential theft |
high |
active |
| 2026-05-07 |
TrustFall — Claude Code, Cursor CLI, Gemini CLI, Copilot CLI, Codex CLI auto-execute MCP servers on folder-trust dialog (no patch; Anthropic won't fix) |
high |
active |
| 2026-06-15 |
Microsoft 365 Copilot SearchLeak (CVE-2026-42824) — 1-click exfil of emails, MFA codes, and OneDrive files via parameter-to-prompt injection + CSP bypass |
high |
patched |
| 2026-06-18 |
IDEsaster — 30+ flaws (24 CVEs) in Cursor, Windsurf, Kiro.dev, GitHub Copilot, Zed, Roo Code, Junie, Cline |
high |
active |
| 2026-06-16 |
Langflow CVE-2026-5027 — unauthenticated path traversal → RCE via file upload (distinct from CVE-2026-33017) |
high |
patched |
| 2026-06-14 |
PromptSnatcher — malicious Chrome ad-blocker extensions intercept AI chatbot conversations from 900K users |
high |
active |
| 2026-06-13 |
AutoJack — AutoGen Studio 3-flaw chain: browsing agent + unauthenticated MCP WebSocket = localhost RCE |
high |
patched |
| 2026-06-17 |
15 malicious JetBrains Marketplace plugins steal AI provider API keys on entry (70K+ installs) |
high |
active |
| 2026-06-17 |
Mastra AI npm namespace compromise — 145 packages backdoored via hijacked contributor account |
critical |
active |
| 2026-06-12 |
Klue AI integration breach — Icarus extortion group steals OAuth tokens; CRM data exfiltrated from Huntress and Recorded Future |
high |
contained |
| 2026-06-11 |
Atomic Arch — AUR supply-chain attack: 1,500+ packages hijacked via orphaned-package takeover; eBPF rootkit |
high |
active |
| 2026-06-15 |
Claude Code MCP OAuth token hijack via malicious npm postinstall hook — Anthropic won't fix |
high |
active |
| 2026-06-13 |
Solana FakeFix Campaign — 25 malicious npm + PyPI packages steal wallet keys via GitHub issue spam |
high |
active |
| 2026-06-12 |
Agentjacking — Sentry DSN injection via MCP poisons AI coding agent context (2,388 orgs exposed) |
high |
active |
| 2026-06-10 |
onering Rust crate compromised — build.rs exfiltrates source-code diffs as fake Sentry telemetry |
high |
unconfirmed |
| 2026-06-10 |
Streamlit CVE-2026-33682 — unauthenticated SSRF on Windows leaks NTLMv2 credentials |
high |
patched |
| 2026-06-10 |
SymJack — symlink hijacking tricks AI coding agents into registering attacker-controlled MCP servers |
high |
mitigated |
| 2026-06-09 |
LangGraph RCE chain — SQLite SQL injection + msgpack deserialization → arbitrary code execution |
critical |
patched |
| 2026-06-08 |
Hades Campaign — 19 PyPI bioinformatics + MCP-developer packages poisoned with Bun credential stealer (June 2026) |
critical |
active |
| 2026-06-05 |
Miasma Wave 5 — 73 Microsoft Azure GitHub repos + mantine-datatable poisoned; payload auto-fires via Claude Code / Cursor / Gemini CLI |
critical |
contained |
| 2026-06-04 |
IronWorm — Rust npm worm with eBPF kernel rootkit + Tor C2 (36 packages) |
critical |
active |
| 2026-06-06 |
Gluestack @react-native-aria RAT via compromised contributor token |
critical |
contained |
| 2026-06-04 |
Phantom Gyp — Miasma wave 4: self-propagating npm worm via binding.gyp (57 packages) |
critical |
active |
| 2026-06-04 |
Claude Code GitHub Actions [bot] trust bypass — supply chain risk (patched v1.0.94) |
high |
patched |
| 2026-06-01 |
Cline — two separate cross-origin WebSocket hijack → RCE CVEs across its VS Code extension and CLI Hub |
critical |
patched |
| 2026-06-01 |
codexui-android npm — OpenAI Codex auth-token stealer |
high |
active |
| 2026-06-01 |
Miasma — @redhat-cloud-services npm scope compromised by Mini-Shai-Hulud-derived worm |
critical |
contained |
| 2026-05-25 |
Cargo May 2026 security release — symlink-override + sparse-URL leak (CVE-2026-5223, CVE-2026-5222) |
medium |
patched |
| 2026-05-22 |
Megalodon — mass GitHub-Actions workflow poisoning of 5,561 repos |
critical |
contained |
| 2026-05-22 |
BadHost — Starlette host-header auth bypass blasts FastAPI, vLLM, LiteLLM, MCP servers (CVE-2026-48710) |
critical |
patched |
| 2026-05-22 |
Composio AI-agent platform breach — LLM-augmented attacker registered malicious tool definitions in the sandbox |
high |
contained |
| 2026-05-22 |
TrapDoor — cross-ecosystem stealer poisons .cursorrules / CLAUDE.md |
critical |
active |
| 2026-05-20 |
Claude Code network-sandbox SOCKS5 null-byte bypass |
high |
patched |
| 2026-05-20 |
TeamPCP breaches GitHub internal repos via poisoned VS Code extension |
high |
contained |
| 2026-05-19 |
Mini Shai-Hulud May 19 wave — @antv npm + Microsoft durabletask PyPI |
critical |
active |
| 2026-05-18 |
Shai-Hulud copycats after the worm source went public |
high |
active |
| 2026-05-18 |
Nx Console VS Code extension compromise (nrwl.angular-console 18.95.0) |
critical |
contained |
| 2026-05-12 |
Claude Code claude-cli:// deeplink RCE (2.1.118) |
critical |
patched |
| 2026-05 |
WhiteCobra — VS Code / Cursor / Windsurf / Open VSX crypto-stealer campaign (July 2025 → ongoing) |
high |
active |
| 2026-05 |
PCPJack — credential-stealing counter-worm that removes TeamPCP infections |
high |
active |
| 2026-05-06 |
ClaudeBleed — Claude in Chrome extension hijack |
high |
mitigated |
| 2026-05-06 |
ZiChatBot — 3 trojanized PyPI packages use the Zulip chat API as C2, suspected OceanLotus/APT32 |
medium |
contained |
| 2026-05-13 |
OpenClaw "Claw Chain" — 4 sandbox-escape CVEs, plus a March 2026 device-pairing privilege-escalation CVE (CVE-2026-33579) |
critical |
patched |
| 2026-05-13 |
Systemic MCP stdio RCE class — now with HashiCorp Terraform MCP + Kubernetes MCP entries |
high |
mitigated |
| 2026-05-14 |
node-ipc compromise |
critical |
active |
| 2026-05-11 |
PraisonAI auth bypass (CVE-2026-44338) |
high |
patched |
| 2026-05-11 |
Mini Shai-Hulud wave — TanStack/Mistral/UiPath/OpenSearch |
critical |
active |
| 2026-05-08 |
Cursor open-folder + Git-hook RCE |
high |
patched |
| 2026-05-07 |
Microsoft Semantic Kernel RCE (CVE-2026-25592 / CVE-2026-26030) |
critical |
patched |
| 2026-05-06 |
Next.js + React May 2026 security release (13 CVEs) |
high |
patched |
| 2026-05 |
Windsurf zero-click MCP RCE (CVE-2026-30615) |
critical |
patched |
| 2026-04-30 |
PyTorch Lightning + intercom-client (Mini Shai-Hulud) |
critical |
contained |
| 2026-04-24 |
LiteLLM proxy pre-auth SQL injection (CVE-2026-42208, CISA KEV) |
critical |
patched |
| 2026-04-24 |
elementary-data PyPI + GHCR compromise (malicious .pth auto-exec) |
critical |
contained |
| 2026-04-23 |
Flowise RCE cluster — CVE-2025-59528 actively exploited + April Agent-node cluster (CVE-2026-41265 et al.) |
critical |
patched |
| 2026-04-22 |
Bitwarden CLI backdoored — first AI-tool-cred-hunting supply-chain malware |
critical |
contained |
| 2026-04-19 |
Vercel breach via Context.ai OAuth supply chain |
high |
contained |
| 2026-04-08 |
Marimo notebook pre-auth RCE (CVE-2026-39987) |
critical |
patched |
| 2026-04 |
Mini Shai-Hulud SAP packages |
high |
active |
| 2026-04 |
"Comment and Control" PR prompt injection |
critical |
patched |
| 2026-03 |
SGLang unauth RCE cluster — CVE-2026-3059 / CVE-2026-3060 (pickle ZMQ, CVSS 9.8) + CVE-2026-5760 (GGUF model RCE) |
critical |
patched |
| 2026-03-12 |
TeamPCP breaches Trivy GitHub Actions → LiteLLM 1.82.7–1.82.8 backdoored |
critical |
contained |
| 2026-03-31 |
Axios compromise |
critical |
contained |
| 2026-03-31 |
Claude Code source-map leak |
medium |
contained |
| 2026-03-27 |
OpenHands git-diff command injection (CVE-2026-33718) |
high |
patched |
| 2026-02-25 |
Langflow CVE-2026-27966 — CSV Agent hardcodes allow_dangerous_code=True → prompt-injection RCE (CVSS 9.8) |
critical |
patched |
| 2026-03-17 |
Langflow unauthenticated RCE (CVE-2026-33017) |
critical |
patched |
| 2026-03-02 |
ModelScope ms-agent OS command injection (CVE-2026-2256) — unpatched, public PoC, CERT/CC advisory |
medium |
active |
| 2026-03-11 |
Supabase Auth OIDC issuer-validation bypass (CVE-2026-31813) |
high |
patched |
| 2026-02-28 |
Google Antigravity sandbox escape (Pillar) |
high |
patched |
| 2026-02-17 |
Cline 2.3.0 supply-chain compromise (Clinejection → OpenClaw) |
critical |
contained |
| 2026-02-17 |
SANDWORM_MODE — Shai-Hulud-style npm worm with MCP injection, CI implant, and 48-hour delayed activation |
critical |
active |
| 2026-02-09 |
Claude Desktop Extensions (DXT) zero-click RCE — Anthropic won't fix |
critical |
active |
| 2026-02-01 |
ClawHavoc — malicious-skill poisoning of OpenClaw's ClawHub marketplace |
high |
active |
| 2026-01-26 |
OpenClaw 1-click RCE via WebSocket gateway-URL token theft (CVE-2026-25253) |
critical |
patched |
| 2026-01-07 |
LangSmith CVE-2026-25750 unvalidated baseUrl → account takeover |
high |
patched |
| 2026-01-12 |
OpenCode AI coding agent — twin localhost RCEs (CVE-2026-22812 + CVE-2026-22813) |
critical |
patched |
| 2025-11-09 |
n8n Ni8mare (CVE-2026-21858, CVSS 10.0) — unauth RCE + credential theft in workflow automation |
critical |
patched |
| 2025-12-28 |
Shai-Hulud 3.0 test payload — @vietmoney/react-big-calendar@0.26.2 |
high |
contained |
| 2025-12-23 |
LangChain LangGrinch (CVE-2025-68664) + path traversal (CVE-2026-34070) |
critical |
patched |
| 2025-12-05 |
React2Shell — CVE-2025-55182 RCE in React Server Components (CISA KEV, exploited through Apr 2026) |
critical |
patched |
| 2026-01-05 |
AI IDEs recommend non-existent extensions — OpenVSX namespace hijack |
high |
mitigated |
| 2025-11-24 |
Shai-Hulud "Second Coming" |
critical |
contained |
| 2025-10-21 |
Cursor & Windsurf ship stale Chromium — 94+ n-day vulns |
high |
active |
| 2025-10 |
Windsurf path-traversal via prompt-injected README (CVE-2025-62353) |
critical |
patched |
| 2025-10-17 |
GlassWorm — self-propagating VS Code / Open VSX worm |
high |
active |
| 2025-09-17 |
postmark-mcp backdoor |
high |
contained |
| 2025-09-15 |
Shai-Hulud original |
critical |
contained |
| 2025-09-08 |
qix npm account compromise |
critical |
contained |
| 2025-09-01 |
Lies in the Loop (LITL) — approval-dialog padding hides malicious commands below the fold; no vendor fix (Claude Code, VS Code Copilot) |
high |
active |
| 2025-08-26 |
Salesloft Drift OAuth Breach — UNC6395 steals Salesforce CRM data from Cloudflare, Palo Alto, Zscaler and hundreds of orgs |
high |
contained |
| 2025-08-26 |
Nx s1ngularity |
critical |
contained |
| 2025-08 → ongoing |
Claude Code InversePrompt (multiple CVEs) |
medium |
patched |
| 2025-07-17 |
Amazon Q VS Code wiper |
medium |
contained |
| 2025-07 |
Cursor CurXecute / MCPoison |
high |
patched |
| 2025-07 |
Supabase MCP lethal trifecta |
high |
mitigated |
| 2025-06-25 |
VSXPloit — Open VSX nightly build pipeline token theft; 8M+ developers at risk (patched June 2025) |
high |
patched |
| ongoing |
Slopsquatting |
medium |
ongoing |
| ongoing |
Vibe platform data exposure |
high |
ongoing |