VulnWatch VulnWatch
← Back to dashboard
#

Agentic / MCP

435 entries

Every Agentic / MCP entry VulnWatch has indexed, sorted by publication date.

Subscribe to this tag's RSS feed

Unknown rss_bleepingcomputer

CISA orders feds to prioritize patching Langflow auth bypass flaw

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) gave federal agencies until Friday to patch an actively exploited vulnerability in the Langflow visual framework for building AI agents...

4 weeks ago
High github

@better-auth/oauth-provider's OAuth authorization-code grant allows concurrent redemption when two token requests race the find-then-delete primitive

### Am I affected? Users are affected if all of the following are true: - Their project depends on `@better-auth/oauth-provider` at a version `>= 1.6.0, < 1.6.11`, or uses the embedded plugin in `be...

8.1
CVSS
1 month ago
High github

Better Auth has stored XSS in the auth-server origin via javascript: redirect_uri in oidc-provider and mcp

### Am I affected? Check each condition. Users are affected when all of the first three hold. - Their application enables the `oidc-provider` plugin or the `mcp` plugin from `better-auth/plugins`. T...

Agentic / MCP mcp server
7.7
CVSS
1 month ago
Medium github

@aborruso/ckan-mcp-server: SSRF via base_url allows access to internal networks (Potential fix bypass of CVE-2026-33060)

### Summary A known vulnerability CVE-2026-33060 indicated tools including ckan_package_search and sparql_query that accept a base_url parameter had the risk of making HTTP requests to arbitrary endpo...

5.7
CVSS
1 month ago
Unknown rss_thehackernews

Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo Data

A public issue can trick GitHub Agentic Workflows into leaking the contents of an organization's private repositories, researchers at Noma Security have shown. The attacker needs only to open a norma...

1 month ago
Unknown rss_thehackernews

⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and More

A streaming box should not need a threat model. Neither should a username field, a demo repo, a reset flow, or a browser permission prompt. That is the irritating part this week: the risky pieces were...

1 month ago
Unknown rss_securityweek

Prompt Injection Attacks Trick AI Agents Into Making Crypto Payments

Researchers uncovered two campaigns embedding indirect prompt injections in malicious websites to exploit autonomous AI agents browsing the web. The post Prompt Injection Attacks Trick AI Agents Into...

Prompt Injection Agentic / MCP prompt injection indirect prompt ai agent
1 month ago
High nvd

CVE-2026-44934: A information disclosure when DEBUG loglevel is set in SUSE Rancher AI Agent 1.0 before 1.0.2 could leak API keys or LLM

A information disclosure when DEBUG loglevel is set in SUSE Rancher AI Agent 1.0 before 1.0.2 could leak API keys or LLM response text with potential sensitive data into logfiles, allowing local attac...

7.0
CVSS
1 month ago
Unknown rss_thehackernews

SkillCloak Lets Malicious AI Agent Skills Evade Static Scanners with Self-Extracting Packing

Scanners meant to catch malicious add-on "skills" for AI coding agents can be fooled by a few simple changes that leave the malware working, according to a new study from researchers at the Hong Kong...

1 month ago
Unknown rss_bleepingcomputer

JadePuffer ransomware used AI agent to automate entire attack

Researchers identified what they believe is the first documented case of a ransomware operation, JadePuffer, conducted entirely by a large language model (LLM) agent. [...]

Agentic / MCP large language model ai agent llm
1 month ago
High nvd

CVE-2026-13341: A vulnerability exists in the Kong Konnect Model Context Protocol (MCP) server prior to version 1.0.0, which could allow

A vulnerability exists in the Kong Konnect Model Context Protocol (MCP) server prior to version 1.0.0, which could allow a remote attacker to perform an indirect prompt injection attack and execute un...

Prompt Injection Agentic / MCP model context protocol prompt injection indirect prompt
7.4
CVSS
1 month ago
Unknown rss_securityweek

Agentic AI Used to Conduct Ransomware Attack via Langflow

Attack demonstrates how LLM agents can combine known exploitation techniques with real-time reasoning to automate complex, multi-stage intrusions. The post Agentic AI Used to Conduct Ransomware Attack...

Agentic / MCP llm agent langflow agentic llm
1 month ago
Critical nvd

CVE-2026-52830: fast-mcp-telegram is a Telegram MCP Server. Prior to 0.19.1, fast-mcp-telegram validates HTTP Bearer tokens by joining t

fast-mcp-telegram is a Telegram MCP Server. Prior to 0.19.1, fast-mcp-telegram validates HTTP Bearer tokens by joining the raw token string into a session-file path. The verifier rejects the exact res...

Agentic / MCP mcp server
9.4
CVSS
1 month ago
High github

Grackle: Fail-open authorization in the MCP tool layer lets scoped agents perform cross-task and cross-session mutations (IDOR)

## Summary Authorization for scoped (agent) MCP callers is enforced **inline, per tool**, and is applied inconsistently — several mutating tools silently omit the ancestry/workspace check that their...

0.0
CVSS
1 month ago
High github

Langroid: Path traversal in the file tools allows read/write outside configured current directory

### Summary Langroid's `ReadFileTool` and `WriteFileTool` appear to treat `curr_dir` as the intended working-directory boundary for file operations. However, the tools only change the process working...

Agentic / MCP llm agent agentic llm
7.1
CVSS
1 month ago
Critical github

mcp-memory-service: Missing Authentication on Document API Endpoints Allows Unauthenticated Memory Read/Write/Delete

## Missing Authentication on Document API Endpoints Allows Unauthenticated Memory Read/Write/Delete ### Summary All HTTP routes under `/api/documents/*` in `mcp-memory-service` are served without an...

Prompt Injection Auth Bypass Agentic / MCP prompt injection transformers huggingface ai agent pytorch
9.8
CVSS
1 month ago
Unknown rss_thehackernews

Identity Lifecycle Management Wasn't Built for AI Agents 

Identity lifecycle management was architected around a person with an employment record, a manager, and a departure date. AI agents have none of those. As autonomous principals proliferate across ente...

1 month ago
Unknown rss_securityweek

‘BioShocking’ Attack Tricks AI Browsers Into Stealing Credentials

Researchers show how context manipulation can cause agentic browsers to abandon safety guardrails and exfiltrate sensitive credentials. The post ‘BioShocking’ Attack Tricks AI Browsers Into Stealing C...

1 month ago
Unknown rss_thehackernews

AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack

Security firm Sysdig says it has found what it believes is the first ransomware attack run from start to finish by an AI agent. Its Threat Research Team calls the operator JADEPUFFER and says a large...

Remote Code Execution Agentic / MCP large language model langflow ai agent
1 month ago
High github

Apify Model Context Protocol (MCP) server: Actor MCP path authority injection leaks Apify token

## Actor MCP path authority injection leaks Apify token ### Summary `@apify/actors-mcp-server` version `0.10.7` builds Actor standby URLs by directly concatenating a trusted base URL with an attacke...

SSRF API Abuse Agentic / MCP model context protocol mcp server
8.1
CVSS
1 month ago
Medium github

repomix: attach_packed_output can bypass file-read secret scanning for supported local files

# `attach_packed_output` can register arbitrary `.json/.txt/.md/.xml` files and bypass the MCP file-read safety check ## Summary Repomix's MCP server exposes a normal `file_system_read_file` tool th...

Agentic / MCP mcp server
0.0
CVSS
1 month ago
High github

Cortex has Untrusted Project Bootstrap Code Execution via `CLAUDE_PROJECT_DIR`

## Untrusted Project Bootstrap Code Execution via `CLAUDE_PROJECT_DIR` ### Summary The Cortex MCP server (`neuro-cortex-memory`) treats the `CLAUDE_PROJECT_DIR` environment variable — automatically...

Remote Code Execution Agentic / MCP claude code mcp server replicate claude
0.0
CVSS
1 month ago
High github

auth-fetch-mcp has SSRF Protection Bypass via IPv4-mapped IPv6 Loopback

## SSRF Protection Bypass via IPv4-mapped IPv6 Loopback ### Summary `auth-fetch-mcp` v3.0.1 implements SSRF protection in `assertSafeUrl()` (`src/security.ts`) to block requests to private and loopb...

SSRF Agentic / MCP mcp server ai agent
7.4
CVSS
1 month ago
Medium nvd

CVE-2026-58446: Presenton before 0.8.8-beta bundles an MCP server that, on server/Docker deployments configured with session authenticat

Presenton before 0.8.8-beta bundles an MCP server that, on server/Docker deployments configured with session authentication (AUTH_USERNAME/AUTH_PASSWORD), is reachable unauthenticated at /mcp because...

Agentic / MCP mcp server llm
6.9
CVSS
1 month ago
High nvd

CVE-2026-10564: IBM Langflow OSS 1.0.0 through 1.9.6 contains a Server-Side Request Forgery (SSRF). The legacy RSSReaderComponent in rss

IBM Langflow OSS 1.0.0 through 1.9.6 contains a Server-Side Request Forgery (SSRF). The legacy RSSReaderComponent in rss.py and SearXNG component in searxng.py make unvalidated HTTP requests to user-c...

Prompt Injection SSRF Agentic / MCP prompt injection langflow agentic
8.2
CVSS
1 month ago