VulnWatch VulnWatch
← Back to dashboard
#

Agentic / MCP

653 entries

Every Agentic / MCP entry VulnWatch has indexed, sorted by publication date.

Subscribe to this tag's RSS feed

High github

Docker MCP Gateway: Argument injection via OCI image label YAML

## Summary A maliciously crafted OCI image label can inject arbitrary arguments into the `docker run` command line constructed by the MCP Gateway. An attacker who controls an image that the victim re...

0.0
CVSS
3 months ago
High nvd

CVE-2026-48989: Windows-MCP is an open-source project that integrates AI agents with Windows. In versions prior to 0.7.5, certain HTTP m

Windows-MCP is an open-source project that integrates AI agents with Windows. In versions prior to 0.7.5, certain HTTP modes exposed the MCP control plane without authentication while enabling wildcar...

8.9
CVSS
3 months ago
Critical nvd

CVE-2026-48814: Network-AI is a TypeScript/Node.js multi-agent orchestrator. In versions 5.7.1 and earlier, the MCP SSE server allows un

Network-AI is a TypeScript/Node.js multi-agent orchestrator. In versions 5.7.1 and earlier, the MCP SSE server allows unauthenticated cross-origin MCP tool invocation due to an empty default secret. T...

9.1
CVSS
3 months ago
Medium nvd

CVE-2026-20265: In Splunk AI Toolkit versions below 5.7.4, a low-privileged user that does not hold the "admin" or "power" Splunk roles

In Splunk AI Toolkit versions below 5.7.4, a low-privileged user that does not hold the "admin" or "power" Splunk roles could cause the Splunk AI Toolkit to make outbound requests over HTTP to a serve...

4.3
CVSS
3 months ago
High github

OpenClaw: MCP Streamable HTTP redirects could forward configured custom headers to another origin

### Summary OpenClaw supports remote MCP Streamable HTTP servers with operator-configured custom headers. In affected releases, those headers could be forwarded when the MCP endpoint responded with a...

Agentic / MCP mcp server
7.1
CVSS
3 months ago
Unknown rss_securityweek

1Password Acquires Apono in Reported $250M-$300M Deal

Apono specializes in just-in-time access governance technology for humans, machines, and AI agents. The post 1Password Acquires Apono in Reported $250M-$300M Deal appeared first on SecurityWeek.

3 months ago
Unknown rss_securityweek

Tenet Security Emerges From Stealth With $6 Million Seed Funding

Tenet aims to detect and stop dangerous AI agentic behavior in real time. The post Tenet Security Emerges From Stealth With $6 Million Seed Funding appeared first on SecurityWeek.

Agentic / MCP ai agent agentic
3 months ago
3 months ago
Medium github

Duplicate Advisory: MCP Streamable HTTP redirects could forward configured custom headers to another origin

## Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-rjxq-qqhf-8hwh. This link is maintained to preserve external references. ## Original Description OpenClaw befo...

7.1
CVSS
3 months ago
Medium nvd

CVE-2026-53840: OpenClaw before 2026.5.12 contains an information disclosure vulnerability in streamable-http MCP servers that forwards

OpenClaw before 2026.5.12 contains an information disclosure vulnerability in streamable-http MCP servers that forwards operator-configured custom headers during cross-origin redirects. Attackers cont...

6.0
CVSS
3 months ago
Unknown rss_securityweek

Magnitude Emerges From Stealth Mode With $10 Million in Funding

The company is enhancing third-party risk management (TPRM) through autonomous AI agents. The post Magnitude Emerges From Stealth Mode With $10 Million in Funding appeared first on SecurityWeek.

3 months ago
Unknown rss_securityweek

NewCore Emerges From Stealth Mode With $66 Million in Funding

The startup has built a security-first identity platform to protect humans, machines, and AI agents. The post NewCore Emerges From Stealth Mode With $66 Million in Funding appeared first on SecurityWe...

3 months ago
Critical github

MCP Toolbox for Databases has an Origin Validation Error

The Model Context Protocol has a security warning advising servers to validate the "Origin" header on all incoming connections to prevent DNS rebinding attacks. Prior to the v0.25.0 release, users had...

Auth Bypass Agentic / MCP model context protocol
0.0
CVSS
3 months ago
Critical nvd

CVE-2026-11624: The Model Context Protocol has a security warning advising servers to validate the "Origin" header on all incoming conne

The Model Context Protocol has a security warning advising servers to validate the "Origin" header on all incoming connections to prevent DNS rebinding attacks. Prior to the v0.25.0 release, users had...

Auth Bypass Agentic / MCP model context protocol
9.4
CVSS
3 months ago
High nvd

CVE-2026-50287: AgenticMail gives AI agents real email addresses and phone numbers. Prior to version 0.9.27, @agenticmail/mcp exposes a

AgenticMail gives AI agents real email addresses and phone numbers. Prior to version 0.9.27, @agenticmail/mcp exposes a Streamable HTTP transport when started with --http or MCP_HTTP=1. In that mode,...

Agentic / MCP ai agent agentic
8.7
CVSS
3 months ago
Unknown rss_thehackernews

LangGraph Flaw Chain Exposes Self-Hosted AI Agents to Remote Code Execution

Cybersecurity researchers have disclosed details of three now-patched security flaws impacting LangGraph, including a critical vulnerability chain that could result in remote code execution. LangGrap...

Remote Code Execution Agentic / MCP langchain ai agent agentic
3 months ago
Medium nvd

CVE-2026-47250: mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster management. Prior to version 3.7.0, the

mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster management. Prior to version 3.7.0, the kubectl_generic tool in mcp-server-kubernetes passes user-supplied flags directl...

Auth Bypass Agentic / MCP model context protocol mcp server ai agent
6.1
CVSS
3 months ago
High nvd

CVE-2026-46519: mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster management. Prior to version 3.6.0, mcp-

mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster management. Prior to version 3.6.0, mcp-server-kubernetes exposes three environment variables (ALLOW_ONLY_READONLY_TOOLS...

Auth Bypass Agentic / MCP model context protocol
8.8
CVSS
3 months ago
Unknown rss_thehackernews

New Attacks Trick OpenClaw AI Agent Into Running Code and Leaking Secrets

Two security teams have shown, in separate research published this week, that OpenClaw, the popular self-hosted AI agent, can be driven to run attacker-controlled code or hand over sensitive data thro...

3 months ago
Critical github

Meta Ads MCP: Unauthenticated HTTP MCP Tool Execution Leaks Operator Meta Access Token

# Unauthenticated HTTP MCP Tool Execution Leaks Operator Meta Access Token | Field | Value | | ---------------- | ----- | | Repository | pipeboard-co/meta-ads-mcp | | Affected versio...

9.1
CVSS
3 months ago
Unknown rss_thehackernews

ThreatsDay Bulletin: Worm Code Leaked, AI Agent Phished, Claude Code Patch + 28 New Stories

It's been one of those weeks. You expect the usual noise: recycled malware, sloppy attacks, another easy target getting hit. Instead, there's a supply chain attack kit in a public repo, a $5,000-a-mon...

Supply Chain Agentic / MCP claude code ai agent claude
3 months ago
Medium github

Claude Code Action: Malicious MCP Server Configuration in PRs Enables Remote Code Execution and Secret Exfiltration

Due to the combination of checking out PR head branches (attacker-controlled), reading `.mcp.json` from the working directory via default setting sources, and unconditionally enabling all project MCP...

Remote Code Execution Agentic / MCP claude code mcp server anthropic claude
0.0
CVSS
3 months ago
Unknown rss_bleepingcomputer

OpenClaw AI agent found falling for phishing attacks, spills user data

Phishing simulation on an OpenClaw email agent with various configuration profiles showed that it was susceptible to tactics commonly used to compromise human users. [...]

3 months ago
Unknown rss_securityweek

New Platform Uses Cryptographic Invisibility to Protect AI-Built Applications

Atsign’s AI Architect applies cryptographic protections to agentic software development, aiming to prevent attackers from exploiting vulnerabilities by making application identities effectively invisi...

3 months ago