VulnWatch VulnWatch
← Back to dashboard
#

Agentic / MCP

653 entries

Every Agentic / MCP entry VulnWatch has indexed, sorted by publication date.

Subscribe to this tag's RSS feed

Medium nvd

CVE-2026-47769: APIFold reads an OpenAPI 3.x or Swagger 2.x specification and generates a live, production-ready MCP server endpoint. Pr

APIFold reads an OpenAPI 3.x or Swagger 2.x specification and generates a live, production-ready MCP server endpoint. Prior to commit 7f19b52280f414f57af2b79a95333d1c8fbeece5, the `/webhooks/:serverSl...

Agentic / MCP mcp server
5.3
CVSS
1 month ago
Medium nvd

CVE-2026-65698: Void through 1.3.4 contains a path traversal vulnerability in the AI agent file-reading tools that allows network-adjace

Void through 1.3.4 contains a path traversal vulnerability in the AI agent file-reading tools that allows network-adjacent attackers to read arbitrary host files outside the open workspace by injectin...

6.0
CVSS
1 month ago
High nvd

CVE-2026-16584: Improper handling of an initialization failure in AWS API MCP Server from 0.2.13 through 1.3.46 might allow an actor to

Improper handling of an initialization failure in AWS API MCP Server from 0.2.13 through 1.3.46 might allow an actor to bypass the user-configured security policy and execute AWS API operations that t...

Agentic / MCP mcp server
7.3
CVSS
1 month ago
Unknown rss_securityweek

OpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers Forge an AI Insider

AgentForger allows an attacker to create, insert and remotely control an invisible autonomous AI agent inside a victim organization. The post OpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers F...

Agentic / MCP ai agent chatgpt openai
1 month ago
Unknown rss_thehackernews

ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories

Most of this week's trouble came dressed as something useful. A package stole data. A fake extension opened remote access. A safety app became spyware. An image gave hidden orders to an AI agent. Oth...

Prompt Injection Agentic / MCP prompt injection ai agent
1 month ago
Unknown rss_thehackernews

Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files

Cybersecurity researchers have uncovered a sandbox escape vulnerability in Anthropic's Claude Cowork that makes it possible to break out of the confines of a Linux virtual machine (VM) within which th...

Agentic / MCP anthropic ai agent claude
1 month ago
Medium osv

LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback

### Impact LiteLLM's MCP Streamable HTTP endpoint could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token. The MCP auth handler supported OA...

4.0
CVSS
1 month ago
Medium osv

LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback

### Impact LiteLLM's MCP Streamable HTTP endpoint could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token. The MCP auth handler supported OA...

4.0
CVSS
1 month ago
Medium github

n8n: Member-Level Users Can Execute Other Users' MCP Server Trigger Workflows via Missing OAuth Authorization Check

## Impact The OAuth 2.1 consent and token-issuance flow introduced in n8n 2.27.0 does not verify that the authenticated user has access to the workflow referenced as the OAuth resource. A member-level...

Agentic / MCP mcp server
0.0
CVSS
1 month ago
Medium github

n8n: Path-Confinement Bypass in computer-use search_files Allows Reading Files Outside the Base Directory

## Impact The component `@n8n/computer-use` file-search tool confined searches to a configured base directory. A crafted search pattern could bypass the confinement check and expand to locations outs...

0.0
CVSS
1 month ago
High github

n8n: "Allowed HTTP Request Domains" Restriction Bypass via AI Agents MCP Connector

## Impact The AI Agents feature did not enforce the "Allowed HTTP Request Domains" restriction configured on credentials. As a result, a member-level user who had been granted use-only access to a sha...

0.0
CVSS
1 month ago
High github

n8n: AI Agents Project Viewer Privilege Escalation via run_node_tool

## Impact In n8n's AI Agents feature, a user with the read-only Project Viewer role could escalate their privileges by chatting with an agent that has node tools enabled. The agent's node-execution to...

0.0
CVSS
2 months ago
High github

Duplicate Advisory: AI Agents Project Viewer Privilege Escalation via run_node_tool

## Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-x5vx-c2c8-m3w9. This link is maintained to preserve external references. ## Original Description n8n versions...

0.0
CVSS
2 months ago
Medium github

Duplicate Advisory: Member-Level Users Can Execute Other Users' MCP Server Trigger Workflows via Missing OAuth Authorization Check

## Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-q5xf-xhwf-cwqf. This link is maintained to preserve external references. ## Original Description n8n before...

Agentic / MCP mcp server
0.0
CVSS
2 months ago
Medium nvd

CVE-2026-65594: n8n before 2.29.8 and 2.30.x before 2.30.1 (affected from 2.27.0, when the OAuth 2.1 consent and token-issuance flow was

n8n before 2.29.8 and 2.30.x before 2.30.1 (affected from 2.27.0, when the OAuth 2.1 consent and token-issuance flow was introduced) does not verify that the authenticated user has access to the workf...

Agentic / MCP mcp server
5.1
CVSS
2 months ago
High nvd

CVE-2026-65015: n8n versions before 2.30.1 contain a privilege escalation vulnerability in the AI Agents feature where the node-executio

n8n versions before 2.30.1 contain a privilege escalation vulnerability in the AI Agents feature where the node-execution tool lacks proper authorization checks. A Project Viewer user can escalate pri...

7.2
CVSS
2 months ago
Medium nvd

CVE-2026-44192: A flaw was found in the Ansible Lightspeed Model Context Protocol (MCP) server. This vulnerability, known as path traver

A flaw was found in the Ansible Lightspeed Model Context Protocol (MCP) server. This vulnerability, known as path traversal, allows an attacker to manipulate an AI agent through indirect prompt inject...

Prompt Injection Agentic / MCP model context protocol prompt injection indirect prompt ai agent
6.6
CVSS
2 months ago
Unknown rss_bleepingcomputer

CISA orders urgent action on actively exploited Langflow RCE flaw

The Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday ordered U.S. government agencies to prioritize patching an actively exploited vulnerability in the Langflow visual framework for...

2 months ago
Unknown rss_thehackernews

Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents

A single invisible comment in an Azure DevOps pull request can turn a reviewer's own AI coding agent against them, driving it into projects the attacker has no rights to reach and quietly leaking what...

Agentic / MCP mcp server
2 months ago
Critical nvd

CVE-2026-47708: MCP-for-Stata is an MCP server for Stata to integrate Stata into an agent. Prior to version 1.17.3, the `log_file_name`

MCP-for-Stata is an MCP server for Stata to integrate Stata into an agent. Prior to version 1.17.3, the `log_file_name` parameter in the `stata_do` API and CLI is directly interpolated into a Stata co...

Agentic / MCP mcp server
9.3
CVSS
2 months ago
Unknown rss_thehackernews

AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code

Hidden text on a web page was enough to make Kiro, AWS's agentic coding IDE, rewrite its own configuration file and run an attacker's code on a developer's machine, with no approval step able to stop...

2 months ago
Unknown rss_thehackernews

Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs

An Android app that can draw over other windows and write to shared storage can slip instructions to the AI agent driving that phone, in text no human eye will ever see. Two more steps, and the same a...

2 months ago
High nvd

CVE-2026-57495: AgenticMail gives AI agents real email addresses and phone numbers. In @agenticmail/claudecode prior to version 0.2.39,

AgenticMail gives AI agents real email addresses and phone numbers. In @agenticmail/claudecode prior to version 0.2.39, @agenticmail/codex prior to version 0.1.33, @agenticmail/core prior to version 0...

Prompt Injection Agentic / MCP prompt injection indirect prompt claude code ai agent agentic claude
8.2
CVSS
2 months ago
High nvd

CVE-2026-57494: AgenticMail gives AI agents real email addresses and phone numbers. In @agenticmail/api prior to version 0.9.64, a low-p

AgenticMail gives AI agents real email addresses and phone numbers. In @agenticmail/api prior to version 0.9.64, a low-privileged authenticated AgenticMail agent can enumerate another agent's pending/...

7.1
CVSS
2 months ago
High nvd

CVE-2026-47255: AgenticMail gives AI agents real email addresses and phone numbers. @agenticmail/api prior to version 0.9.32 and @agenti

AgenticMail gives AI agents real email addresses and phone numbers. @agenticmail/api prior to version 0.9.32 and @agenticmail/core prior to version 0.9.10 had weakness related to validation and and bi...

Agentic / MCP ai agent agentic
8.2
CVSS
2 months ago