VulnWatch VulnWatch
← Back to dashboard
#

Agentic / MCP

653 entries

Every Agentic / MCP entry VulnWatch has indexed, sorted by publication date.

Subscribe to this tag's RSS feed

Unknown rss_thehackernews

CISO's Expert Guide to Agentic Pentesting for Websites

Attackers now weaponize new vulnerabilities in about five days (Mandiant, part of Google Cloud). The median organization takes 43 days to patch one (Verizon DBIR 2026). A new free guide explains how a...

Agentic / MCP ai agent agentic
5 days ago
Unknown rss_securityweek

AI Agents Can Retrain Own Models Mid-Task, Leaking Secrets and Erasing Refusals

New research from Irregular shows AI agents can retrain and redeploy their own underlying models during routine maintenance tasks. The post AI Agents Can Retrain Own Models Mid-Task, Leaking Secrets a...

5 days ago
Medium nvd

CVE-2026-64684: RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.1.0, the rmcp crate's StreamableHttpClientTransp

RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.1.0, the rmcp crate's StreamableHttpClientTransport in crates/rmcp/src/transport/common/reqwest/streamable_http_client.rs builds...

Agentic / MCP model context protocol
6.8
CVSS
5 days ago
High github

RMCP: Unauthenticated permanent session-table leak in rmcp Streamable HTTP server transport leads to remote denial-of-service

### Summary An unauthenticated remote attacker can leak one entry per HTTP request out of the in-memory session table of `LocalSessionManager` by sending a well-formed JSON-RPC `POST` that is *not* a...

Agentic / MCP mcp server
7.5
CVSS
5 days ago
High github

RMCP: Missing Resource Field Validation in OAuth Protected Resource Metadata Discovery

### Summary The `rmcp` library does not validate the `resource` parameter in OAuth Protected Resource metadata (RFC 9728), allowing a malicious MCP server to redirect OAuth flows to a legitimate autho...

Agentic / MCP mcp server
8.2
CVSS
5 days ago
Unknown rss_bleepingcomputer

Spain's data agency gets first report of AI-powered data breach

The Spanish Data Protection Agency (AEPD) was notified of an attack allegedly carried out with an AI agent powered by a known large language model (LLM). [...]

Data Leakage Agentic / MCP large language model ai agent llm
6 days ago
Unknown rss_securityweek

First Agentic AI Data Breach Reported to Spanish Regulator

Spanish regulators say an AI agent chained together a successful login, vulnerability discovery, and access to personal data in a potential milestone for autonomous cyberattacks. The post First Agenti...

6 days ago
High nvd

CVE-2026-63128: RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.0.0, the rmcp crate's stateful Streamable HTTP s

RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.0.0, the rmcp crate's stateful Streamable HTTP server in crates/rmcp/src/transport/streamable_http_server/tower.rs allows an una...

Agentic / MCP model context protocol
7.5
CVSS
6 days ago
High nvd

CVE-2026-63127: RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.0.0, the rmcp crate's OAuth implementation in cr

RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.0.0, the rmcp crate's OAuth implementation in crates/rmcp/src/transport/auth.rs omits the RFC 9728 resource field from ResourceS...

Agentic / MCP model context protocol mcp server
8.2
CVSS
6 days ago
Critical github

@zereight/mcp-gitlab: Unauthenticated arbitrary file read via `upload_markdown` enables PAT exfiltration and full account takeover

### Summary The SSE transport mode (`SSE=true`) exposes all MCP tools without any authentication. The `upload_markdown` tool reads arbitrary files from the server's local filesystem via an unsanitize...

9.8
CVSS
6 days ago
Unknown rss_securityweek

AIUC Raises $40 Million to Certify Enterprise AI Agents

The company provides a standard for AI systems, testing them against risks such as jailbreaks, prompt injections, and unauthorized actions. The post AIUC Raises $40 Million to Certify Enterprise AI Ag...

Prompt Injection Agentic / MCP prompt injection jailbreak ai agent
6 days ago
Critical nvd

CVE-2026-61560: `@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Prior to version 2.1.27, the SSE transport mode (`

`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Prior to version 2.1.27, the SSE transport mode (`SSE=true`) exposes all MCP tools without any authentication. The `upload_markdow...

Agentic / MCP model context protocol
9.8
CVSS
6 days ago
Critical nvd

CVE-2026-61568: `@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Versions prior to 2.1.30 expose the Streamable HTT

`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Versions prior to 2.1.30 expose the Streamable HTTP MCP endpoint without an effective Host or Origin allowlist. A malicious web pa...

Agentic / MCP model context protocol
9.6
CVSS
6 days ago
Critical nvd

CVE-2026-61559: `@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Starting in version 0.0.1 and prior to version 2.1

`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Starting in version 0.0.1 and prior to version 2.1.27, when the environment variable `ENABLE_DYNAMIC_API_URL=true` is set, the ser...

Agentic / MCP model context protocol
9.6
CVSS
6 days ago
Critical github

@zereight/mcp-gitlab Vulnerable to Server-Side Request Forgery

# Server-Side Request Forgery via X-GitLab-API-URL Header Allows Credential Theft ## Affected - **Repository:** `zereight/gitlab-mcp` - **Affected versions:** All versions through commit `74a8c83` -...

9.6
CVSS
6 days ago
Critical github

@zereight/mcp-gitlab: DNS rebinding reaches local Streamable HTTP MCP transport

`@zereight/mcp-gitlab` exposes its Streamable HTTP MCP endpoint without an effective Host or Origin allowlist. A malicious web page can use DNS rebinding to route browser requests to a victim's local...

Agentic / MCP mcp server
9.6
CVSS
6 days ago
High github

@zereight/mcp-gitlab has multiple safety-control bypasses: execute_graphql read-only + allow-list bypass, unauthenticated transports, session-exhaustion DoS

### Summary @zereight/mcp-gitlab exposes GitLab to an LLM agent while relying on read-only mode, a project allow-list, and transport auth as its safety controls. Five defects defeat those controls. Un...

Prompt Injection Agentic / MCP prompt injection replicate llm agent llm
8.1
CVSS
6 days ago
High nvd

CVE-2026-58485: mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through

mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through SearXNG. Prior to 1.7.1, web_url_read receives its caller-controlled URL through...

Agentic / MCP model context protocol mcp server
7.1
CVSS
1 week ago
High nvd

CVE-2026-58483: mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through

mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through SearXNG. Prior to 1.7.1, web_url_read in src/index.ts passes a caller-supplied U...

Agentic / MCP model context protocol
7.5
CVSS
1 week ago
Medium nvd

CVE-2026-57442: MCPVault is a lightweight Model Context Protocol server for safe access to files in an Obsidian vault. Prior to 0.11.5,

MCPVault is a lightweight Model Context Protocol server for safe access to files in an Obsidian vault. Prior to 0.11.5, PathFilter in src/pathfilter.ts uses root-anchored deny-list patterns, so nested...

Agentic / MCP model context protocol ai agent
6.9
CVSS
1 week ago
High nvd

CVE-2026-57441: MCPVault is a lightweight Model Context Protocol server for safe access to files in an Obsidian vault. Prior to 0.11.4,

MCPVault is a lightweight Model Context Protocol server for safe access to files in an Obsidian vault. Prior to 0.11.4, PathFilter in src/pathfilter.ts compiles restricted-directory patterns case-sens...

Agentic / MCP model context protocol ai agent
8.4
CVSS
1 week ago
Medium nvd

CVE-2026-54689: mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through

mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through SearXNG. Prior to 1.2.0, the web_url_read URL policy in src/url-reader.ts can be...

Agentic / MCP model context protocol mcp server
6.3
CVSS
1 week ago
Medium nvd

CVE-2026-54688: mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through

mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through SearXNG. Prior to 1.2.0, web_url_read passes a caller-supplied URL to the server...

Agentic / MCP model context protocol ai agent
6.5
CVSS
1 week ago
High nvd

CVE-2026-54549: Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.115, th

Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.115, the upload_ad_image tool in meta_ads_mcp/core/ads.py passes an attacker-controlled...

SSRF Agentic / MCP model context protocol
8.3
CVSS
1 week ago
High nvd

CVE-2026-54547: Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.115, Au

Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.115, AuthInjectionMiddleware in meta_ads_mcp/core/http_auth_integration.py rejects HTTP...

Agentic / MCP model context protocol
7.4
CVSS
1 week ago