VulnWatch VulnWatch
← Back to dashboard
#

Agentic / MCP

653 entries

Every Agentic / MCP entry VulnWatch has indexed, sorted by publication date.

Subscribe to this tag's RSS feed

Unknown rss_thehackernews

OpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Face

OpenAI on Wednesday revealed that reward hacking was a key driver behind the artificial intelligence (AI)-powered hack of Hugging Face last month, adding that it found evidence of misaligned behavior...

Agentic / MCP hugging face ai agent openai
3 weeks ago
Low nvd

CVE-2026-81102: The Dash MCP server bound its listener to the loopback address but never checked the host a request named. src/mcp_serve

The Dash MCP server bound its listener to the loopback address but never checked the host a request named. src/mcp_server_dash.py constructed the server for its network mode with the interface restric...

Agentic / MCP mcp server
2.3
CVSS
3 weeks ago
High nvd

CVE-2026-81099: tiger-slack started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides. mcp/src/htt

tiger-slack started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides. mcp/src/httpServer.ts called the shared httpServerFactory helper and never set the DNS-rebi...

Agentic / MCP mcp server
7.6
CVSS
3 weeks ago
Critical nvd

CVE-2026-81098: The Telnyx MCP server exposed its HTTP transport on every interface and did not require a caller credential. packages/mc

The Telnyx MCP server exposed its HTTP transport on every interface and did not require a caller credential. packages/mcp-server/src/http.ts served MCP on the root path with a listener bound to all in...

Agentic / MCP mcp server
9.3
CVSS
3 weeks ago
Critical nvd

CVE-2026-81096: ToolUniverse ran caller-supplied Python inside a sandbox that could be escaped, on a server that required no authenticat

ToolUniverse ran caller-supplied Python inside a sandbox that could be escaped, on a server that required no authentication. The executor behind the python_code_executor tool, in python_executor_tool....

Agentic / MCP mcp server
9.3
CVSS
3 weeks ago
High nvd

CVE-2026-81095: pg-aiguide started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides. src/httpServ

pg-aiguide started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides. src/httpServer.ts called the shared httpServerFactory helper and never set the DNS-rebinding...

Agentic / MCP mcp server
7.6
CVSS
3 weeks ago
Critical nvd

CVE-2026-81094: The mcp-router CLI served its MCP aggregator on every interface and enforced authentication only when the operator asked

The mcp-router CLI served its MCP aggregator on every interface and enforced authentication only when the operator asked for it. The serve command in apps/cli/src/commands/serve.ts defaulted its host...

Agentic / MCP mcp server
9.3
CVSS
3 weeks ago
High nvd

CVE-2026-81093: The get-html-skeleton tool fetched a URL the caller supplied after checking only its syntax. The handler in src/tools/co

The get-html-skeleton tool fetched a URL the caller supplied after checking only its syntax. The handler in src/tools/common/get_html_skeleton.ts validated the url argument with isValidHttpUrl from sr...

Agentic / MCP mcp server
8.7
CVSS
3 weeks ago
Unknown rss_thehackernews

Amazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powers

Cybersecurity researchers have disclosed details of a vulnerability in Amazon Kiro, an artificial intelligence (AI)-powered, agentic integrated development environment (IDE), that could facilitate dat...

Prompt Injection Agentic / MCP prompt injection agentic
3 weeks ago
Unknown rss_securityweek

Okta Shares Surge on Strong Earnings, Growing Demand for AI Identity Security

The identity security company beat quarterly expectations and raised its outlook as enterprises face growing pressure to secure AI agents and other non-human identities. The post Okta Shares Surge on...

3 weeks ago
Critical nvd

CVE-2026-80104: DB-GPT builds the destination path for an uploaded skill from the multipart filename without constraining it to the uplo

DB-GPT builds the destination path for an uploaded skill from the multipart filename without constraining it to the upload directory. skill_upload in packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/ag...

9.3
CVSS
3 weeks ago
Medium nvd

CVE-2026-53965: The MCP PHP SDK (Composer package mcp/sdk) is the official Model Context Protocol SDK for PHP. In versions 0.5.0 through

The MCP PHP SDK (Composer package mcp/sdk) is the official Model Context Protocol SDK for PHP. In versions 0.5.0 through 0.7.0, the HTTP client transport reads a Server-Sent Events response stream inc...

Agentic / MCP model context protocol mcp server
6.9
CVSS
3 weeks ago
Unknown rss_bleepingcomputer

AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes

A newly uncovered phishing-as-a-service (PhaaS) platform called AnonyMousKIT automates the retrieval of codes used to unlock stolen Apple devices and disable the Activation Lock feature. [...]

3 weeks ago
High github

Chainlist has SSRF via MCP SSE and streamable-http transports that allows unauthenticated internal network access

### Am I affected? Only if your deployment sets `features.mcp.enabled = true` in `.chainlit/config.toml`. **MCP has been disabled by default since v2.7.0**, so most Chainlit deployments are not affec...

7.2
CVSS
3 weeks ago
Critical github

Chainlit has command injection via MCP stdio transport that allows unauthenticated remote code execution

### Am I affected? Only if your deployment sets `features.mcp.enabled = true` in `.chainlit/config.toml`. **MCP has been disabled by default since v2.7.0**, so most Chainlit deployments are not affec...

9.8
CVSS
3 weeks ago
High github

consciousness-explorer / sublinear-time-solver MCP export_state has an arbitrary file write

### Impact An arbitrary file write vulnerability (CWE-73, External Control of File Name or Path) exists in the `consciousness-explorer` component of `sublinear-time-solver`. The MCP `export_state` (an...

Agentic / MCP mcp server
7.1
CVSS
3 weeks ago
High nvd

CVE-2026-55637: genieacs-mcp is an MCP server for GenieACS written in Go. Prior to 0.3.2, the Streamable HTTP transport in cmd/server/ma

genieacs-mcp is an MCP server for GenieACS written in Go. Prior to 0.3.2, the Streamable HTTP transport in cmd/server/main.go creates an unauthenticated /mcp listener on the default MCP_LISTEN_ADDR va...

Agentic / MCP mcp server
8.8
CVSS
4 weeks ago
High github

genieacs-mcp: DNS rebinding reaches local GenieACS MCP Streamable HTTP transport

`genieacs-mcp` exposes a local Streamable HTTP MCP endpoint that accepts attacker-controlled `Host` and `Origin` headers. A malicious web page can use DNS rebinding to route browser requests to a vict...

Agentic / MCP mcp server
0.0
CVSS
4 weeks ago
High nvd

CVE-2026-55557: browse-mcp is a Playwright-based headless-browser MCP server for MCP-capable agents. Prior to 0.8.2, browser_download wr

browse-mcp is a Playwright-based headless-browser MCP server for MCP-capable agents. Prior to 0.8.2, browser_download writes a fetched response body to join(save_dir, filename) without validating the...

Prompt Injection Agentic / MCP prompt injection indirect prompt mcp server
8.6
CVSS
4 weeks ago
High github

browse-mcp has an arbitrary file write via unconfined download and state paths

### Impact `browser_download` wrote a fetched file to `join(save_dir, filename)` with no validation of `save_dir`, and `browser_save_state` / `browser_load_state` honored an explicit `path` unchanged....

Prompt Injection Agentic / MCP prompt injection indirect prompt
0.0
CVSS
4 weeks ago
Critical nvd

CVE-2026-55640: Nextcloud MCP Server is a production-ready MCP server that connects AI assistants to a Nextcloud instance. Prior to 0.11

Nextcloud MCP Server is a production-ready MCP server that connects AI assistants to a Nextcloud instance. Prior to 0.117.2, the POST /webhooks/nextcloud endpoint in nextcloud_mcp_server/vector/webhoo...

Agentic / MCP mcp server qdrant
9.1
CVSS
4 weeks ago
High nvd

CVE-2026-55582: mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, the default se

mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, the default security.yaml allows /usr/bin/git, while security.go omits ! from containsShellMet...

Agentic / MCP mcp server
8.4
CVSS
4 weeks ago
High nvd

CVE-2026-55581: mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, the default Do

mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, the default Docker security.yaml includes /bin/bash in allowed_executables, while security.go...

Agentic / MCP mcp server
8.4
CVSS
4 weeks ago
High nvd

CVE-2026-55580: mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, config.go init

mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, config.go initializes Security.Enabled to false, and when MCP_SHELL_SEC_CONFIG_FILE is unset,...

Agentic / MCP mcp server llm
8.6
CVSS
4 weeks ago
High github

utcp-http SSRF: HTTP tool invocation follows redirects without re-validating the target

## Summary `HttpCommunicationProtocol.call_tool` validates only the pre-redirect tool URL, then issues the request with redirects enabled and never re-checks where it lands. A tool whose endpoint is...

8.2
CVSS
4 weeks ago