VulnWatch VulnWatch
← Back to dashboard
#

Agentic / MCP

653 entries

Every Agentic / MCP entry VulnWatch has indexed, sorted by publication date.

Subscribe to this tag's RSS feed

Medium github

SearXNG MCP Server is Vulnerable to SSRF in web_url_read: the internal-address guard is disabled by default (MCP_HTTP_HARDEN off)

Ref: https://github.com/ihor-sokoliuk/mcp-searxng/issues/87#issuecomment-4645453694 ### Summary The web_url_read tool fetches a caller-supplied URL server-side and converts it to markdown. An SSRF g...

Prompt Injection SSRF Agentic / MCP prompt injection mcp server llm
6.5
CVSS
1 month ago
High github

MCP PHP SDK: client HttpTransport SSE buffer (sseBuffer .= chunk) grows unbounded when server withholds the event delimiter

## Summary The HTTP client transport in `mcp/sdk` reads a Server-Sent-Events (SSE) response stream incrementally and appends each 4 KiB chunk to an in-memory buffer (`$this->sseBuffer .= $chunk;`) wi...

Agentic / MCP adversarial mcp server
0.0
CVSS
1 month ago
High github

Contentful MCP Server: export_space/import_space tools pass LLM-controlled `host`/`proxy` args to CMA client, redirecting server PAT to attacker-controlled endpoint

### Summary `export_space` and `import_space` tools in `@contentful/mcp-tools` accept LLM-controlled `host` and `proxy` parameters that are spread directly into the options object passed to `contentf...

Prompt Injection SSRF Agentic / MCP prompt injection mcp server replicate llm
7.7
CVSS
1 month ago
High nvd

CVE-2026-75149: marimo before 0.23.15 contains a code injection vulnerability in the notebook configuration handler that allows attacker

marimo before 0.23.15 contains a code injection vulnerability in the notebook configuration handler that allows attackers to execute arbitrary commands by supplying a crafted MCP server entry with an...

8.7
CVSS
1 month ago
Unknown rss_securityweek

Prevalent AI Raises $22 Million to Expand Data Fabric Platform

The previously bootstrapped company helps organizations securely and reliably operate AI agents at scale. The post Prevalent AI Raises $22 Million to Expand Data Fabric Platform appeared first on Secu...

1 month ago
Critical nvd

CVE-2026-75625: Kraken agents fail to verify peer-to-peer downloaded blobs against their requested SHA-256 digest before committing to t

Kraken agents fail to verify peer-to-peer downloaded blobs against their requested SHA-256 digest before committing to the content-addressable cache, relying only on CRC32 checksums for piece validati...

Agentic / MCP agent-to-agent
9.1
CVSS
1 month ago
Medium nvd

CVE-2026-75130: Context7 through 2.1.2 contains a prompt injection vulnerability that allows attackers to execute malicious instructions

Context7 through 2.1.2 contains a prompt injection vulnerability that allows attackers to execute malicious instructions in connected AI coding agents by injecting unsanitized content through the Cust...

Prompt Injection Agentic / MCP prompt injection mcp server
6.4
CVSS
1 month ago
High nvd

CVE-2026-50143: The Apify MCP server enables AI agents to extract data from websites using ready-made scrapers, crawlers, and automation

The Apify MCP server enables AI agents to extract data from websites using ready-made scrapers, crawlers, and automation tools available on the Apify Store. Prior to 0.10.11, getActorMCPServerURL in s...

Agentic / MCP mcp server ai agent
8.1
CVSS
1 month ago
Unknown rss_thehackernews

AI "Mind Viruses" Can Spread Between Agents Through Persistent Prompt Files

Security researchers at Anthropic and Switzerland's EPFL have demonstrated that self-propagating payloads can spread from one artificial intelligence (AI) agent to the next through the editable system...

Agentic / MCP anthropic
1 month ago
Unknown rss_securityweek

Xpander Raises $7.5 Million for AI Management and Governance

Xpander’s platform uses a universal agent harness that executes AI agents as portable workloads and securely renders interfaces on demand. The post Xpander Raises $7.5 Million for AI Management and Go...

1 month ago
Medium nvd

CVE-2026-75845: ArcadeDB versions 26.4.2 through 26.7.3 contain an authorization bypass vulnerability in the set_server_setting MCP serv

ArcadeDB versions 26.4.2 through 26.7.3 contain an authorization bypass vulnerability in the set_server_setting MCP server-level tool. SetServerSettingTool.execute() gates only on the global allowAdmi...

5.3
CVSS
1 month ago
Unknown rss_securityweek

Fortinet Acquires AI Security Company Virtue AI

Fortinet will use Virtue AI technology to enhance its AI security portfolio, including for AI models, applications, and agentic systems. The post Fortinet Acquires AI Security Company Virtue AI appear...

Agentic / MCP ai model agentic
1 month ago
High github

atomic-agents-stack: HTTP MCP catalog accepts cleartext http and spawns catalog-supplied commands (MITM to RCE)

The HTTP MCP server-registry backend factory (`atomic_agents/mcp_registry/http.py`, `make_http_mcp_server_registry_backend_from_url`) accepts both `http` and `https` schemes. Catalog entries carry `co...

0.0
CVSS
1 month ago
Critical nvd

CVE-2026-75110: MemOS is a memory operating system for LLMs and AI agents. In deployments where authentication is enabled (AUTH_ENABLED=

MemOS is a memory operating system for LLMs and AI agents. In deployments where authentication is enabled (AUTH_ENABLED=true) but the undocumented, defaultless INTERNAL_SERVICE_SECRET environment vari...

Agentic / MCP ai agent llm
9.3
CVSS
1 month ago
Unknown rss_thehackernews

How MCP Servers Can Expose Enterprise Secrets

MCP servers can expose enterprise secrets through plaintext configuration files, over-permissioned access and prompt injection, often before security teams even know the server is running. As more org...

Prompt Injection Agentic / MCP model context protocol prompt injection mcp server ai agent
1 month ago
Unknown rss_securityweek

Conflicting Test Goals Pushed Claude Agents to Deploy Self-Replicating Malware

Anthropic has been conducting tests to identify issues in how AI agents interact with each other. The post Conflicting Test Goals Pushed Claude Agents to Deploy Self-Replicating Malware appeared first...

Agentic / MCP anthropic ai agent claude
1 month ago
High github

Token Optimizer MCP: OS command injection in smart_user via username in get-user-info

### Summary `token-optimizer-mcp` is vulnerable to OS command injection in the `smart_user` tool. The `get-user-info` operation accepts a user-controlled `username` argument and later interpolates i...

8.4
CVSS
1 month ago
Medium nvd

CVE-2026-73846: CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, canonicalizeParams in src/utils/cache.t

CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, canonicalizeParams in src/utils/cache.ts serializes request parameters with unescaped ampersand, equals-sign, and verti...

Agentic / MCP mcp server
6.5
CVSS
1 month ago
Medium nvd

CVE-2026-73845: CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, the ckan_get_mqa_quality and ckan_get_m

CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, the ckan_get_mqa_quality and ckan_get_mqa_quality_details tools in src/tools/quality.ts use isValidMqaServer to validat...

Agentic / MCP mcp server
5.3
CVSS
1 month ago
Low nvd

CVE-2026-73844: CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, error paths reflect raw upstream respon

CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, error paths reflect raw upstream response bodies and internal exception messages back to the caller instead of a saniti...

3.7
CVSS
1 month ago
High nvd

CVE-2026-49986: The Cortex MCP server (`neuro-cortex-memory`), a cross-platform persistent memory MCP, prior to version 3.17.1 treats th

The Cortex MCP server (`neuro-cortex-memory`), a cross-platform persistent memory MCP, prior to version 3.17.1 treats the `CLAUDE_PROJECT_DIR` environment variable — automatically set by Claude Code t...

Agentic / MCP claude code mcp server claude
7.1
CVSS
1 month ago
Medium nvd

CVE-2026-19753: A vulnerability was detected in Model Context Protocol mcp-rdf-explorer 1.0.0. Affected is the function explore_url of t

A vulnerability was detected in Model Context Protocol mcp-rdf-explorer 1.0.0. Affected is the function explore_url of the file src/mcp-rdf-explorer/server.py of the component MCP Server. Performing a...

SSRF Agentic / MCP model context protocol mcp server
5.5
CVSS
1 month ago
High nvd

CVE-2026-73658: Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 4.4.2 until 4.5.0-rc.5,

Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 4.4.2 until 4.5.0-rc.5, Aws4FetchClient.buildUrl() and Aws4FetchClient.presign() in apps/webapp/app/v3/...

8.2
CVSS
1 month ago
Medium nvd

CVE-2026-73657: Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 4.4.2 until 4.5.0-rc.4,

Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 4.4.2 until 4.5.0-rc.4, `POST /api/v1/runs/:runParam/replay` in apps/webapp/app/routes/api.v1.runs.$run...

4.2
CVSS
1 month ago
Critical nvd

CVE-2026-72776: AgenticSeek (commit fc242c7) contains an unauthenticated remote code execution vulnerability that allows any network-adj

AgenticSeek (commit fc242c7) contains an unauthenticated remote code execution vulnerability that allows any network-adjacent attacker to execute arbitrary commands by submitting crafted queries to th...

9.3
CVSS
1 month ago