VulnWatch VulnWatch
← Back to dashboard
#

Agentic / MCP

653 entries

Every Agentic / MCP entry VulnWatch has indexed, sorted by publication date.

Subscribe to this tag's RSS feed

Unknown rss_thehackernews

Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug

HashiCorp, Veeam, and the Django Software Foundation have patched 11 vulnerabilities across Terraform MCP Server, Veeam Service Provider Console, and Django. The three most serious: An unauthenti...

Agentic / MCP mcp server
1 month ago
Unknown rss_securityweek

AI Agents Targeted Real People and Projects During Cybersecurity Tests

AI Security Institute reports Anthropic and OpenAI models going rogue against real people, organizations, and open source projects. The post AI Agents Targeted Real People and Projects During Cybersec...

Agentic / MCP anthropic ai agent openai
1 month ago
Unknown rss_bleepingcomputer

OpenAI, Anthropic AI agents targeted real people and systems in cyber tests

OpenAI and Anthropic have confirmed that their AI models were involved in separate, newly disclosed third-party cybersecurity testing incidents that resulted in a real website being breached and socia...

Agentic / MCP anthropic ai agent ai model openai
1 month ago
High nvd

CVE-2026-69263: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the mitigation

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the mitigation for CVE-2025-8943 blocked -y and --yes flags on npx, but packages/components/nod...

Agentic / MCP large language model mcp server
8.7
CVSS
1 month ago
High github

Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable blocklist (Unauthenticated RCE)

## Summary The mitigation shipped for CVE-2025-8943 blocks the `-y` and `--yes` flags on `npx` to stop auto-installation of arbitrary packages. That flag filter works. The environment-variable check...

0.0
CVSS
1 month ago
Critical github

Flowise RCE via SQLite Record Manager Node

============================================================================= Security Advisory...

0.0
CVSS
1 month ago
High github

Flowise: SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses

## Summary Flowise's HTTP security module (`httpSecurity.ts`) fails to normalize IPv4-mapped IPv6 addresses (e.g., `::ffff:127.0.0.1`, `::ffff:169.254.169.254`) before checking them against the deny...

0.0
CVSS
1 month ago
Critical github

Flowise Sandbox Escape to RCE

============================================================================= Security Advisory...

Remote Code Execution Agentic / MCP large language model function calling openai gpt-4 gpt-5 groq llm
0.0
CVSS
1 month ago
Critical github

Flowise RCE via TypeORM DataSource

============================================================================= Security Advisory...

0.0
CVSS
1 month ago
Unknown rss_bleepingcomputer

Varonis Agent IBAC keeps AI agents within their intended boundaries

AI agents need broad access to be useful, but traditional access controls cannot determine whether an action aligns with a user's intent. Varonis explains how Agent IBAC detects intent drift and enfor...

1 month ago
Unknown rss_securityweek

Obsidian Security Raises $85 Million at $1.1 Billion Valuation

Obsidian Security has developed a platform for governing AI agents across third-party applications. The post Obsidian Security Raises $85 Million at $1.1 Billion Valuation appeared first on SecurityWe...

1 month ago
Unknown rss_thehackernews

Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent

Google deleted three AI agent workflows from its Agent Development Kit (ADK) Python repository. Pillar Security showed that a public GitHub issue could manipulate a triage agent into triggering a priv...

1 month ago
Unknown rss_securityweek

Gemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pull Request Tampering

A crafted prompt to a low-privilege Google ADK agent could be used to pass a malicious hand-off comment to a privileged agent. The post Gemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pul...

Agentic / MCP agent-to-agent gemini
1 month ago
High nvd

CVE-2026-66065: Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to

Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to constrain behavior. Versions prior to 0.42.1 have an incomplete denylist. Severa...

8.4
CVSS
1 month ago
High nvd

CVE-2026-18655: Improper restriction of intended endpoints in the RabbitMQ broker connection tools of the Amazon MQ MCP Server (awslabs.

Improper restriction of intended endpoints in the RabbitMQ broker connection tools of the Amazon MQ MCP Server (awslabs.amazon-mq-mcp-server) before 2.0.24 may allow a remote unauthenticated actor (vi...

Prompt Injection Agentic / MCP prompt injection mcp server
7.1
CVSS
1 month ago
Medium nvd

CVE-2026-54785: gemini-bridge is a lightweight MCP server bridging AI agents to Google's Gemini AI via the official CLI. From 1.0.0 unti

gemini-bridge is a lightweight MCP server bridging AI agents to Google's Gemini AI via the official CLI. From 1.0.0 until 1.3.1, consult_gemini_with_files in inline mode read any file path supplied in...

Agentic / MCP mcp server ai agent gemini
6.2
CVSS
1 month ago
Medium github

@dynatrace-oss/dynatrace-mcp-server has a workflow template injection via create_workflow_for_notification

### Summary A template injection vulnerability in the `create_workflow_for_notification` tool lets a caller embed Jinja2 expressions that the Dynatrace workflow engine evaluates at runtime, exfiltrati...

4.2
CVSS
1 month ago
Critical nvd

CVE-2026-12940: IBM Langflow OSS 1.0.0 through 1.10.1  are vulnerable to unauthenticated remote code execution via environment variable

IBM Langflow OSS 1.0.0 through 1.10.1  are vulnerable to unauthenticated remote code execution via environment variable injection in the MCP (Model Context Protocol) stdio launcher. The vulnerability...

Remote Code Execution Agentic / MCP model context protocol langflow
9.8
CVSS
1 month ago
Critical github

Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)

## Summary `image.download` fetches a URL and writes the response to disk. It does not use the central path guard (`validate_path_with_env_config`, which confines writes to `FLYTO_SANDBOX_DIR`); inst...

10.0
CVSS
1 month ago
High github

MCP Ruby SDK: Ruby SSE Session Poisoning

### Summary **Vulnerability**: Missing Session Ownership Validation in the Ruby MCP SDK's Streamable and SSE HTTP transport implementation. Any attacker with a stolen session ID can execute tools with...

Agentic / MCP mcp server
0.0
CVSS
1 month ago
Medium github

MCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhaustion (DoS)

## Summary The stdio transports in `MCP::Server::Transports::StdioTransport` and `MCP::Client::Stdio` read newline-delimited JSON-RPC frames using `IO#gets` with no `limit` argument. CRuby's `IO#gets...

Agentic / MCP mcp server
6.2
CVSS
1 month ago
Medium github

MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protection

## Summary `MCP::Server::Transports::StreamableHTTPTransport` (the Rack-mountable Streamable HTTP transport in the `mcp` gem) processes every incoming JSON-RPC request without ever inspecting the HTT...

Agentic / MCP mcp server
0.0
CVSS
1 month ago
Unknown rss_securityweek

DataBahn Raises $40 Million for Agentic Data Pipeline Management

The company will accelerate investments in R&D and product innovation to expand its agentic data control plane. The post DataBahn Raises $40 Million for Agentic Data Pipeline Management appeared f...

1 month ago
Unknown rss_securityweek

Discern Security Raises $13 Million in Series A Funding

The company will invest in accelerating the development and adoption of its agentic platform. The post Discern Security Raises $13 Million in Series A Funding appeared first on SecurityWeek.

1 month ago
Unknown rss_securityweek

Cantina Emerges From Stealth With $8 Million in Funding

The startup’s community-powered agentic security platform helps proactively identify, prioritize, and remediate vulnerabilities. The post Cantina Emerges From Stealth With $8 Million in Funding appear...

1 month ago