VulnWatch VulnWatch
← Back to dashboard
#

Agentic / MCP

435 entries

Every Agentic / MCP entry VulnWatch has indexed, sorted by publication date.

Subscribe to this tag's RSS feed

High nvd

CVE-2026-45609: mcp-security provides Security and Authorization support for Model Context Protocol in Spring AI. Prior to 0.1.9, the mc

mcp-security provides Security and Authorization support for Model Context Protocol in Spring AI. Prior to 0.1.9, the mcp-security framework fails to implement the mandatory SSRF mitigations outlined...

SSRF Agentic / MCP model context protocol
7.2
CVSS
2 months ago
Unknown rss_thehackernews

Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit

An unknown threat actor has been observed using a large language model (LLM) agent to conduct post-compromise actions after obtaining initial access following the exploitation of a publicly-accessible...

Agentic / MCP large language model llm agent llm
2 months ago
High nvd

CVE-2026-45707: n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior

n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.51.2, when ENABLE_MULTI_TENANT=true, the HTTP transport documents that the...

Agentic / MCP mcp server
8.1
CVSS
2 months ago
Medium nvd

CVE-2026-45582: n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior

n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.51.3, the workflow telemetry sanitizer could retain partial fragments of U...

Agentic / MCP mcp server
6.5
CVSS
2 months ago
High nvd

CVE-2026-45555: Roslyn CodeLens MCP Server is a Roslyn-based MCP server providing semantic code intelligence for .NET codebases. From 0.

Roslyn CodeLens MCP Server is a Roslyn-based MCP server providing semantic code intelligence for .NET codebases. From 0.0.9 to 1.17.0, the get_diagnostics MCP tool loads and executes all DiagnosticAna...

7.8
CVSS
2 months ago
Medium github

nono: Sandbox escape on Linux via D-Bus: `systemd-run --user`

### Summary The nono Landlock/seccomp policies allow access to local Unix domain sockets (concrete and abstract). This allows an easy sandbox escape by talking to the per-user systemd dbus socket. T...

Auth Bypass Agentic / MCP claude code ai agent claude aider
6.1
CVSS
2 months ago
Unknown rss_securityweek

Raising the Cybersecurity Stakes: Ante up for the Agentic Era

CISOs are now facing machine-speed attacks and asking, “How do I agent?” The industry must provide remediation at scale. The post Raising the Cybersecurity Stakes: Ante up for the Agentic Era appeared...

2 months ago
Unknown rss_securityweek

‘SymJack’ Attack Turns AI Coding Agents Into Supply Chain Attack Delivery Systems

Malicious repositories and disguised symlinks can trick AI coding agents into silently installing attacker-controlled MCP servers capable of stealing secrets, compromising CI pipelines, and deploying...

2 months ago
Critical nvd

CVE-2026-44895: GitLab MCP Server lets an AI agent talk directly to GitLab. Prior to 0.6.0, the HTTP transport in src/transport.ts ships

GitLab MCP Server lets an AI agent talk directly to GitLab. Prior to 0.6.0, the HTTP transport in src/transport.ts ships with no authentication layer at all and a wildcard Access-Control-Allow-Origin:...

Agentic / MCP mcp server ai agent
9.2
CVSS
2 months ago
Critical nvd

CVE-2026-44450: Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the MCP server creation endpoint validates the command

Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the MCP server creation endpoint validates the command field against an allowlist of binary names but forwards the args array to the c...

Agentic / MCP mcp server
9.9
CVSS
2 months ago
Unknown rss_thehackernews

The Alert Firehose Finally Meets Its Match

Ask a cybersecurity pro about Network Detection and Response (NDR) and you might still hear "Noisy," "Too much data." But ask the teams running NDR that includes agentic AI capabilities and you'll hea...

2 months ago
High github

Network-AI: Unauthenticated Cross-Origin MCP Tool Invocation via Empty Default Secret

# Unauthenticated Cross-Origin MCP Tool Invocation via Empty Default Secret | Field | Value | | ---------------- | ----- | | Repository | Jovancoding/Network-AI | | Affected version...

Agentic / MCP mcp server
7.6
CVSS
2 months ago
Critical github

BoxLite: Permission Bypass Allows Modification of Read-Only Files

#### Summary Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted code. One of the core security featu...

Supply Chain Agentic / MCP large language model ai agent
10.0
CVSS
2 months ago
High github

MCP Server Kubernetes: Tool Access Control Bypass via Presentation-Layer Filtering Without Execution-Layer Enforcement

## Summary `mcp-server-kubernetes` exposes three environment variables (`ALLOW_ONLY_READONLY_TOOLS`, `ALLOW_ONLY_NON_DESTRUCTIVE_TOOLS`, `ALLOWED_TOOLS`) documented as access controls for restricting...

Auth Bypass Agentic / MCP mcp server ai agent gemini
8.8
CVSS
2 months ago
Unknown rss_securityweek

Ocean Emerges From Stealth With $28M for Agentic Email Security Platform

The company has developed a platform that uses specialized AI agents to inspect every incoming message. The post Ocean Emerges From Stealth With $28M for Agentic Email Security Platform appeared first...

Agentic / MCP ai agent agentic
2 months ago
Unknown rss_thehackernews

Microsoft Open-Sources RAMPART and Clarity to Secure AI Agents During Development

Microsoft has unveiled two new open-source tools called RAMPART and Clarity to assist developers in better testing the security of artificial intelligence (AI) agents. RAMPART, short for Risk Assessm...

Agentic / MCP ai agent agentic
2 months ago
Unknown rss_securityweek

AI-Powered App Attacks Are Faster, More Frequent and Harder to Stop

Digital.ai’s latest threat report warns that agentic AI has erased the distinction between emerging and primary targets, enabling attackers to strike mobile apps within hours of release across every i...

2 months ago
High github

CamoFox MCP: Unauthenticated HTTP MCP browser-control surface

# Unauthenticated HTTP MCP browser-control surface in `camofox-mcp` ## Summary `camofox-mcp` exposed a Streamable HTTP MCP endpoint at `/mcp` with rate limiting but no inbound MCP-layer authenticati...

Agentic / MCP mcp server
0.0
CVSS
2 months ago
Medium github

Apify Model Context Protocol (MCP) server: Domain Allowlist Bypass in fetch-apify-docs via String Prefix Matching

### Summary The `fetch-apify-docs` tool validates URLs against a domain allowlist using `String.startsWith()` instead of proper URL hostname comparison. This allows bypass via attacker-controlled subd...

Prompt Injection SSRF Agentic / MCP model context protocol prompt injection llm
6.1
CVSS
2 months ago
Medium github

Envoy AI Proxy - MCP Message Smuggling Vulnerability

Envoy AI Gateway was found to be affected by a protocol parser differential vulnerability due to improper implementation of the JSON-RPC 2.0 specification. Such differential causes a MCP message alter...

Agentic / MCP model context protocol mcp server anthropic
0.0
CVSS
2 months ago
High github

auth-fetch-mcp: SSRF and disk exfiltration via unvalidated auth_fetch and download_media URLs

# SSRF + disk-exfil in `download_media` and `auth_fetch` tools — ymw0407/auth-fetch-mcp ## Severity The `download_media` and `auth_fetch` MCP tools accept arbitrary URLs and reach them as the MCP ser...

Prompt Injection SSRF Agentic / MCP prompt injection mcp server replicate llm
8.2
CVSS
2 months ago
Low github

MCP Registry: OCI validator skips ownership check on upstream rate limits

# OCI ownership validation fails open on upstream rate limits, allowing attacker to claim arbitrary public OCI images under their own namespace Severity: Low (re-scored post-triage; see Maintainer tr...

3.5
CVSS
2 months ago
High github

Spring AI MCP Security: Unvalidated URL Fetching (SSRF)

### Summary The mcp-security framework fails to implement the mandatory SSRF mitigations outlined in the Model Context Protocol (MCP) [security specifications](https://modelcontextprotocol.io/docs/tu...

SSRF Agentic / MCP model context protocol mcp server
7.2
CVSS
2 months ago