VulnWatch VulnWatch
← Back to dashboard
#

Agentic / MCP

653 entries

Every Agentic / MCP entry VulnWatch has indexed, sorted by publication date.

Subscribe to this tag's RSS feed

Unknown rss_securityweek

‘SymJack’ Attack Turns AI Coding Agents Into Supply Chain Attack Delivery Systems

Malicious repositories and disguised symlinks can trick AI coding agents into silently installing attacker-controlled MCP servers capable of stealing secrets, compromising CI pipelines, and deploying...

3 months ago
Critical nvd

CVE-2026-44895: GitLab MCP Server lets an AI agent talk directly to GitLab. Prior to 0.6.0, the HTTP transport in src/transport.ts ships

GitLab MCP Server lets an AI agent talk directly to GitLab. Prior to 0.6.0, the HTTP transport in src/transport.ts ships with no authentication layer at all and a wildcard Access-Control-Allow-Origin:...

Agentic / MCP mcp server ai agent
9.2
CVSS
3 months ago
Critical nvd

CVE-2026-44450: Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the MCP server creation endpoint validates the command

Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the MCP server creation endpoint validates the command field against an allowlist of binary names but forwards the args array to the c...

Agentic / MCP mcp server
9.9
CVSS
3 months ago
Unknown rss_thehackernews

The Alert Firehose Finally Meets Its Match

Ask a cybersecurity pro about Network Detection and Response (NDR) and you might still hear "Noisy," "Too much data." But ask the teams running NDR that includes agentic AI capabilities and you'll hea...

3 months ago
High github

Network-AI: Unauthenticated Cross-Origin MCP Tool Invocation via Empty Default Secret

# Unauthenticated Cross-Origin MCP Tool Invocation via Empty Default Secret | Field | Value | | ---------------- | ----- | | Repository | Jovancoding/Network-AI | | Affected version...

Agentic / MCP mcp server
7.6
CVSS
4 months ago
Critical github

BoxLite: Permission Bypass Allows Modification of Read-Only Files

#### Summary Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted code. One of the core security featu...

Supply Chain Agentic / MCP large language model ai agent
10.0
CVSS
4 months ago
High github

MCP Server Kubernetes: Tool Access Control Bypass via Presentation-Layer Filtering Without Execution-Layer Enforcement

## Summary `mcp-server-kubernetes` exposes three environment variables (`ALLOW_ONLY_READONLY_TOOLS`, `ALLOW_ONLY_NON_DESTRUCTIVE_TOOLS`, `ALLOWED_TOOLS`) documented as access controls for restricting...

Auth Bypass Agentic / MCP mcp server ai agent gemini
8.8
CVSS
4 months ago
Unknown rss_securityweek

Ocean Emerges From Stealth With $28M for Agentic Email Security Platform

The company has developed a platform that uses specialized AI agents to inspect every incoming message. The post Ocean Emerges From Stealth With $28M for Agentic Email Security Platform appeared first...

Agentic / MCP ai agent agentic
4 months ago
Unknown rss_thehackernews

Microsoft Open-Sources RAMPART and Clarity to Secure AI Agents During Development

Microsoft has unveiled two new open-source tools called RAMPART and Clarity to assist developers in better testing the security of artificial intelligence (AI) agents. RAMPART, short for Risk Assessm...

Agentic / MCP ai agent agentic
4 months ago
Unknown rss_securityweek

AI-Powered App Attacks Are Faster, More Frequent and Harder to Stop

Digital.ai’s latest threat report warns that agentic AI has erased the distinction between emerging and primary targets, enabling attackers to strike mobile apps within hours of release across every i...

4 months ago
High github

CamoFox MCP: Unauthenticated HTTP MCP browser-control surface

# Unauthenticated HTTP MCP browser-control surface in `camofox-mcp` ## Summary `camofox-mcp` exposed a Streamable HTTP MCP endpoint at `/mcp` with rate limiting but no inbound MCP-layer authenticati...

Agentic / MCP mcp server
0.0
CVSS
4 months ago
Medium github

Apify Model Context Protocol (MCP) server: Domain Allowlist Bypass in fetch-apify-docs via String Prefix Matching

### Summary The `fetch-apify-docs` tool validates URLs against a domain allowlist using `String.startsWith()` instead of proper URL hostname comparison. This allows bypass via attacker-controlled subd...

Prompt Injection SSRF Agentic / MCP model context protocol prompt injection llm
6.1
CVSS
4 months ago
Medium github

Envoy AI Proxy - MCP Message Smuggling Vulnerability

Envoy AI Gateway was found to be affected by a protocol parser differential vulnerability due to improper implementation of the JSON-RPC 2.0 specification. Such differential causes a MCP message alter...

Agentic / MCP model context protocol mcp server anthropic
0.0
CVSS
4 months ago
High github

auth-fetch-mcp: SSRF and disk exfiltration via unvalidated auth_fetch and download_media URLs

# SSRF + disk-exfil in `download_media` and `auth_fetch` tools — ymw0407/auth-fetch-mcp ## Severity The `download_media` and `auth_fetch` MCP tools accept arbitrary URLs and reach them as the MCP ser...

Prompt Injection SSRF Agentic / MCP prompt injection mcp server replicate llm
8.2
CVSS
4 months ago
Low github

MCP Registry: OCI validator skips ownership check on upstream rate limits

# OCI ownership validation fails open on upstream rate limits, allowing attacker to claim arbitrary public OCI images under their own namespace Severity: Low (re-scored post-triage; see Maintainer tr...

3.5
CVSS
4 months ago
High github

Spring AI MCP Security: Unvalidated URL Fetching (SSRF)

### Summary The mcp-security framework fails to implement the mandatory SSRF mitigations outlined in the Model Context Protocol (MCP) [security specifications](https://modelcontextprotocol.io/docs/tu...

SSRF Agentic / MCP model context protocol mcp server
7.2
CVSS
4 months ago
High github

Microsoft APM: Symlinks under `.apm/prompts/` and `.apm/agents/` are dereferenced during `apm install`, copying host-local file contents into the project tree

## Summary Two primitive integrators in `apm-cli` enumerate package files with bare `Path.glob()` / `Path.rglob()` calls and read each match with `Path.read_text()`, transparently following symbolic...

Supply Chain Agentic / MCP windsurf ai agent copilot claude cursor
7.4
CVSS
4 months ago
Medium nvd

CVE-2026-46383: Microsoft APM is an open-source, community-driven dependency manager for AI agents. Prior to 0.13.0, Microsoft APM conta

Microsoft APM is an open-source, community-driven dependency manager for AI agents. Prior to 0.13.0, Microsoft APM contains a Windows-specific archive extraction boundary failure in the legacy-bundle...

5.5
CVSS
4 months ago
High nvd

CVE-2026-45539: Microsoft APM is an open-source, community-driven dependency manager for AI agents. From 0.5.4 to 0.12.4, two primitive

Microsoft APM is an open-source, community-driven dependency manager for AI agents. From 0.5.4 to 0.12.4, two primitive integrators in apm-cli enumerate package files with bare Path.glob() / Path.rglo...

7.4
CVSS
4 months ago
High nvd

CVE-2026-44641: Microsoft APM is an open-source, community-driven dependency manager for AI agents. Prior to 0.8.12, Microsoft APM norma

Microsoft APM is an open-source, community-driven dependency manager for AI agents. Prior to 0.8.12, Microsoft APM normalizes marketplace plugins by copying plugin components referenced in plugin.json...

7.1
CVSS
4 months ago
Low nvd

CVE-2026-44428: The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. Prior to 1.7.6, the

The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. Prior to 1.7.6, the client-side and server-side GitHub OIDC flow is bound only to a global audience...

Agentic / MCP mcp server
2.1
CVSS
4 months ago
Unknown nvd

CVE-2026-44427: The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. From 1.1.0 to 1.7.4

The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. From 1.1.0 to 1.7.4, the TrailingSlashMiddleware in internal/api/server.go is vulnerable to an open...

Agentic / MCP mcp server
4 months ago
Low nvd

CVE-2026-45781: The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. Prior to 1.7.9, OCI

The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. Prior to 1.7.9, OCI ownership validation skips label-match check when upstream OCI registry returns...

Agentic / MCP mcp server
3.5
CVSS
4 months ago