VulnWatch VulnWatch
← Back to dashboard
#

Agentic / MCP

653 entries

Every Agentic / MCP entry VulnWatch has indexed, sorted by publication date.

Subscribe to this tag's RSS feed

Unknown rss_securityweek

When Information Becomes the Attack Surface – Understanding AI Agent Traps

From hidden content injections to cognitive state poisoning, attackers are turning trusted data sources into traps for autonomous AI. The post When Information Becomes the Attack Surface – Understandi...

2 months ago
Medium nvd

CVE-2026-57300: A missing permission check in Jenkins MCP Server Plugin 0.177.v629fdb_2557fe and earlier allows attackers with Item/Read

A missing permission check in Jenkins MCP Server Plugin 0.177.v629fdb_2557fe and earlier allows attackers with Item/Read permission to read the Pipeline replay scripts of jobs they can access.

Agentic / MCP mcp server
4.3
CVSS
2 months ago
Unknown rss_securityweek

Agentic AI Security: Wrong Context, Wrong Decisions at Machine Speed

Context is the central plank of AI in general, and agentic AI in particular. If an AI system doesn’t have the correct context, it cannot make the correct decisions. The post Agentic AI Security: Wrong...

2 months ago
Unknown rss_thehackernews

Dawn of the Apex Agentic Adversary

We are standing at the end of an era we never thought to mourn: the era of human-speed threats. For years, cybersecurity moved to a rhythm organizations could follow. A researcher found a bug, a CVE...

2 months ago
High nvd

CVE-2026-12112: A flaw was found in the foreman-mcp-server. A session management vulnerability in the MCP Server allows unauthenticated

A flaw was found in the foreman-mcp-server. A session management vulnerability in the MCP Server allows unauthenticated attackers to hijack active administrative sessions due to an improper cache of a...

7.8
CVSS
2 months ago
Medium nvd

CVE-2026-55249: @rtk-ai/rtk-rewrite transparently rewrites shell commands executed via OpenClaw's exec tool to their RTK equivalents. In

@rtk-ai/rtk-rewrite transparently rewrites shell commands executed via OpenClaw's exec tool to their RTK equivalents. In 1.0.0, the @rtk-ai/rtk-rewrite OpenClaw plugin passes attacker-controlled input...

Agentic / MCP llm agent llm
6.3
CVSS
2 months ago
Medium nvd

CVE-2026-54316: Claude Code is an agentic coding tool. From 0.2.54 until 2.1.163, because the hostname huggingface.co was pre-approved

Claude Code is an agentic coding tool. From 0.2.54 until 2.1.163, because the hostname huggingface.co was pre-approved as a bare hostname for the WebFetch tool, any path on that domain—including atta...

Agentic / MCP huggingface claude code agentic claude
6.0
CVSS
2 months ago
Unknown rss_thehackernews

Fake AI Agent Skill Passed Security Scans and Reportedly Reached 26,000 Agents

Security firm AIR built a fake AI agent skill, pushed it through a popular skill marketplace and an Instagram ad, and says it reached roughly 26,000 agents, including some on corporate accounts. Ever...

2 months ago
High nvd

CVE-2026-56274: Flowise before 3.1.2 contains multiple OS command injection vulnerabilities in the Custom MCP Server feature due to inco

Flowise before 3.1.2 contains multiple OS command injection vulnerabilities in the Custom MCP Server feature due to incomplete command-flag validation and a regex bypass in local file access restricti...

8.7
CVSS
2 months ago
Unknown rss_thehackernews

Agentic AI: The Weapon That No Longer Needs a Warrior

Every weapon begins as an extension of the hand that holds it. The spear lengthened the reach of the arm. The bow sent the point flying without the throw. The rifle placed a man's death a quarter mile...

2 months ago
High github

Budibase has an Account Impersonation Issue — Chat Identity Link Hijacking via Missing Consent & CSRF

## Title **Chat Identity Link Hijacking — Attacker Can Silently Map Their Slack/Discord Identity to Any Authenticated Budibase User's Account** ## Severity **High** — CVSS 3.1: AV:N/AC:L/PR:L/UI:R/...

7.3
CVSS
2 months ago
Medium github

Glances: XML-RPC Server Missing Host Header Validation Enables DNS Rebinding Attack

### Summary The Glances XML-RPC server (`glances -s`, implemented in `glances/server.py`) does not validate the HTTP `Host` header, leaving it vulnerable to DNS rebinding attacks. CVE-2026-32632 (pa...

Agentic / MCP mcp server
5.3
CVSS
2 months ago
Unknown rss_bleepingcomputer

Microsoft fixes AutoGen Studio flaw that enabled code execution

A vulnerability chain dubbed AutoJack in Microsoft's AutoGen Studio interface for prototyping AI agents could let attackers manipulate an agent into executing arbitrary commands on its host system sim...

Agentic / MCP ai agent autogen
3 months ago
Unknown rss_thehackernews

Researchers Detail DifyTap Flaws in Dify That Could Expose AI Chats Across Tenants

Cybersecurity researchers have disclosed details of four vulnerabilities in Dify, an open-source agentic workflow platform with more than 146,000 GitHub stars, that could allow attackers to stealthily...

Agentic / MCP agentic dify
3 months ago
Unknown rss_thehackernews

Stop Your Legacy Infrastructure from Hijacking Your AI Agents

Earlier this month, I spoke at the Gartner Security & Risk Management Summit about a blind spot most security programs are still not accounting for - how attackers are circumventing AI security pr...

3 months ago
High github

Apache Doris MCP Server is vulnerable to SQL Injection via metadata query path

Apache Doris MCP Server contains a SQL injection vulnerability in a metadata query path. A user-controlled database name is directly interpolated into a SQL query, and the query is executed without pa...

Agentic / MCP mcp server
8.1
CVSS
3 months ago
High nvd

CVE-2025-66336: Apache Doris MCP Server contains a SQL injection vulnerability in a metadata query path. A user-controlled database name

Apache Doris MCP Server contains a SQL injection vulnerability in a metadata query path. A user-controlled database name is directly interpolated into a SQL query, and the query is executed without pa...

Agentic / MCP mcp server
8.1
CVSS
3 months ago
Low nvd

CVE-2026-12774: A security vulnerability has been detected in BerriAI litellm up to 1.82.2. Affected by this vulnerability is the functi

A security vulnerability has been detected in BerriAI litellm up to 1.82.2. Affected by this vulnerability is the function _execute_with_mcp_client of the file litellm/proxy/_experimental/mcp_server/r...

SSRF Agentic / MCP mcp server litellm
2.1
CVSS
3 months ago
High github

appium-mcp: Unescaped Locator Data XSS in MCP-UI Resource (createLocatorGeneratorUI)

## Unescaped Locator Data XSS in MCP-UI Resource (createLocatorGeneratorUI) ### Summary `appium-mcp`'s `createLocatorGeneratorUI` function interpolates attacker-controlled element attributes — `text...

8.2
CVSS
3 months ago
High github

SearXNG MCP Server: DNS-resolved Private Hostname SSRF in `web_url_read`

## DNS-resolved Private Hostname SSRF in `web_url_read` ### Summary The `web_url_read` MCP tool in `mcp-searxng` is vulnerable to Server-Side Request Forgery (SSRF) via DNS rebinding bypass. The `as...

Prompt Injection SSRF Agentic / MCP prompt injection mcp server ai agent
7.1
CVSS
3 months ago
High github

SearXNG MCP Server: Unbounded Response Body Read Bypasses URL Size Limit in `web_url_read`

## Unbounded Response Body Read Bypasses URL Size Limit in `web_url_read` ### Summary The `web_url_read` MCP tool in mcp-searxng enforces its 5 MiB response-size limit exclusively by inspecting the...

Prompt Injection Agentic / MCP prompt injection mcp server ai agent ai model
7.5
CVSS
3 months ago
Medium github

Network-AI: ApprovalInbox HTTP server has no authentication — anyone can approve pending agent actions

## Summary `network-ai`'s `ApprovalInbox` (`lib/approval-inbox.ts`) is a shipped, exported, documented feature — *"a web-accessible approval queue with REST API … and SSE streaming"* (SECURITY.md). I...

5.9
CVSS
3 months ago
Medium github

dbt MCP Server: Unauthenticated OAuth Context Endpoint Leaks dbt Platform Tokens

## Unauthenticated OAuth Context Endpoint Leaks dbt Platform Tokens ### Summary The local OAuth helper FastAPI server bundled with `dbt-mcp` exposes the `GET /dbt_platform_context` endpoint without...

6.8
CVSS
3 months ago
High github

Kozou: Unauthenticated MCP HTTP server and bundled dev-stack hardening (DNS-rebinding, request-body limits, read-only reads, default network exposure)

Kozou compiles a PostgreSQL schema into an Admin UI, a REST API, and an MCP server. Several hardening gaps in the bundled HTTP surfaces and the scaffolded dev stack are fixed in **1.8.1**. ## Issues...

Agentic / MCP mcp server
0.0
CVSS
3 months ago