VulnWatch VulnWatch
← Back to dashboard
#

Agentic / MCP

435 entries

Every Agentic / MCP entry VulnWatch has indexed, sorted by publication date.

Subscribe to this tag's RSS feed

Unknown rss_bleepingcomputer

Shadow AI agents are multiplying. Here's how to find and secure them.

Shadow AI agents are rapidly spreading across enterprise platforms, often without IT or security visibility. Nudge Security explains how organizations can discover, assess, and govern AI agents before...

1 week ago
Low nvd

CVE-2026-17433: A vulnerability was detected in nanocoai NanoClaw up to 2.0.64. This impacts the function createChatSdkBridge.setup of t

A vulnerability was detected in nanocoai NanoClaw up to 2.0.64. This impacts the function createChatSdkBridge.setup of the file src/channels/chat-sdk-bridge.ts of the component MCP Server Approval. Pe...

Agentic / MCP mcp server
1.9
CVSS
1 week ago
High github

AWS Bedrock AgentCore: Improper neutralization of argument delimiters in the Python SDK install_packages()

### Summary The AWS Bedrock AgentCore Python SDK (bedrock-agentcore) provides tools for building AI agents, including a Code Interpreter client that installs Python packages into a managed sandbox. A...

7.3
CVSS
2 weeks ago
High github

AWS API MCP Server Security Policy Bypass via Startup Initialization Failure

## Summary The AWS API MCP Server is an open source Model Context Protocol (MCP) server that enables AI assistants to interact with AWS services and resources through AWS CLI commands. It provides pro...

Auth Bypass Agentic / MCP model context protocol mcp server
7.0
CVSS
2 weeks ago
High github

Budibase: Chat-Link Handoff Identity Confusion (Same-Tenant Account-Link CSRF)

### Summary The Budibase AI chat-link handoff flow (`GET/POST /api/chat-links/:instance/:token/handoff`) binds an **external chat identity** (Slack/Discord/MS Teams/Telegram) to a **Budibase user acc...

7.7
CVSS
2 weeks ago
Unknown rss_bleepingcomputer

Hermes AI agent used to automate attack on Thai Finance Ministry

A threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance. [...]

2 weeks ago
High nvd

CVE-2026-66027: Suna before 0.9.102 contains a broken access control vulnerability in the message queue API that allows authenticated at

Suna before 0.9.102 contains a broken access control vulnerability in the message queue API that allows authenticated attackers to access and manipulate queue resources belonging to other users by exp...

8.7
CVSS
2 weeks ago
Unknown rss_thehackernews

Seeing AI Agents Is Not Enough. Security Teams Must Enforce What They Can Do

AI agent security is moving through a familiar maturity curve: adoption, then visibility, and finally, control. But what we've collectively discovered is that enforcing least privilege for AI agents i...

2 weeks ago
Unknown rss_securityweek

Industry Reactions to OpenAI Models Hacking Hugging Face: Feedback Friday

Industry professionals debate whether it represents a lab containment failure or an unprecedented agentic capability milestone. The post Industry Reactions to OpenAI Models Hacking Hugging Face: Feedb...

Agentic / MCP hugging face agentic openai
2 weeks ago
Unknown rss_thehackernews

Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry

Someone installed a popular AI assistant on a rented server, switched off the setting that makes it ask permission before running risky commands, and pointed it at Thailand's Ministry of Finance, whic...

2 weeks ago
Medium nvd

CVE-2026-47769: APIFold reads an OpenAPI 3.x or Swagger 2.x specification and generates a live, production-ready MCP server endpoint. Pr

APIFold reads an OpenAPI 3.x or Swagger 2.x specification and generates a live, production-ready MCP server endpoint. Prior to commit 7f19b52280f414f57af2b79a95333d1c8fbeece5, the `/webhooks/:serverSl...

Agentic / MCP mcp server
5.3
CVSS
2 weeks ago
Medium nvd

CVE-2026-65698: Void through 1.3.4 contains a path traversal vulnerability in the AI agent file-reading tools that allows network-adjace

Void through 1.3.4 contains a path traversal vulnerability in the AI agent file-reading tools that allows network-adjacent attackers to read arbitrary host files outside the open workspace by injectin...

6.0
CVSS
2 weeks ago
High nvd

CVE-2026-16584: Improper handling of an initialization failure in AWS API MCP Server from 0.2.13 through 1.3.46 might allow an actor to

Improper handling of an initialization failure in AWS API MCP Server from 0.2.13 through 1.3.46 might allow an actor to bypass the user-configured security policy and execute AWS API operations that t...

Agentic / MCP mcp server
7.3
CVSS
2 weeks ago
Unknown rss_securityweek

OpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers Forge an AI Insider

AgentForger allows an attacker to create, insert and remotely control an invisible autonomous AI agent inside a victim organization. The post OpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers F...

Agentic / MCP ai agent chatgpt openai
2 weeks ago
Unknown rss_thehackernews

ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories

Most of this week's trouble came dressed as something useful. A package stole data. A fake extension opened remote access. A safety app became spyware. An image gave hidden orders to an AI agent. Oth...

Prompt Injection Agentic / MCP prompt injection ai agent
2 weeks ago
Unknown rss_thehackernews

Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files

Cybersecurity researchers have uncovered a sandbox escape vulnerability in Anthropic's Claude Cowork that makes it possible to break out of the confines of a Linux virtual machine (VM) within which th...

Agentic / MCP anthropic ai agent claude
2 weeks ago
Medium osv

LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback

### Impact LiteLLM's MCP Streamable HTTP endpoint could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token. The MCP auth handler supported OA...

4.0
CVSS
2 weeks ago
Medium osv

LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback

### Impact LiteLLM's MCP Streamable HTTP endpoint could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token. The MCP auth handler supported OA...

4.0
CVSS
2 weeks ago
Medium github

n8n: Member-Level Users Can Execute Other Users' MCP Server Trigger Workflows via Missing OAuth Authorization Check

## Impact The OAuth 2.1 consent and token-issuance flow introduced in n8n 2.27.0 does not verify that the authenticated user has access to the workflow referenced as the OAuth resource. A member-level...

Agentic / MCP mcp server
0.0
CVSS
2 weeks ago
Medium github

n8n: Path-Confinement Bypass in computer-use search_files Allows Reading Files Outside the Base Directory

## Impact The component `@n8n/computer-use` file-search tool confined searches to a configured base directory. A crafted search pattern could bypass the confinement check and expand to locations outs...

0.0
CVSS
2 weeks ago
High github

n8n: "Allowed HTTP Request Domains" Restriction Bypass via AI Agents MCP Connector

## Impact The AI Agents feature did not enforce the "Allowed HTTP Request Domains" restriction configured on credentials. As a result, a member-level user who had been granted use-only access to a sha...

0.0
CVSS
2 weeks ago
High github

n8n: AI Agents Project Viewer Privilege Escalation via run_node_tool

## Impact In n8n's AI Agents feature, a user with the read-only Project Viewer role could escalate their privileges by chatting with an agent that has node tools enabled. The agent's node-execution to...

0.0
CVSS
2 weeks ago
High github

Duplicate Advisory: AI Agents Project Viewer Privilege Escalation via run_node_tool

## Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-x5vx-c2c8-m3w9. This link is maintained to preserve external references. ## Original Description n8n versions...

0.0
CVSS
2 weeks ago
Medium github

Duplicate Advisory: Member-Level Users Can Execute Other Users' MCP Server Trigger Workflows via Missing OAuth Authorization Check

## Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-q5xf-xhwf-cwqf. This link is maintained to preserve external references. ## Original Description n8n before...

Agentic / MCP mcp server
0.0
CVSS
2 weeks ago
Medium nvd

CVE-2026-65594: n8n before 2.29.8 and 2.30.x before 2.30.1 (affected from 2.27.0, when the OAuth 2.1 consent and token-issuance flow was

n8n before 2.29.8 and 2.30.x before 2.30.1 (affected from 2.27.0, when the OAuth 2.1 consent and token-issuance flow was introduced) does not verify that the authenticated user has access to the workf...

Agentic / MCP mcp server
5.1
CVSS
2 weeks ago