---
title: "Agent security incident log: 17 incidents since 2025 · DotsAgent"
description: "Public AI agent security incidents since April 2025, from MCP tool poisoning to Claude Code WebFetch exfiltration, each with CVEs, root cause and fixes."
url: https://dotsagent.io/security/incidents
---

17 incidents since 2025

# Agent security incident log

Public incidents involving AI agents, MCP servers and agent platforms, newest first. Each entry explains what happened, why the attack worked and what to change in your own setup.

1. Jun 5, 2026 [MCP Python SDK session hijack and cross-session task access](https://dotsagent.io/security/incidents/2026-06-mcp-python-sdk-session-hijack)Two flaws in the MCP Python SDK allowed session hijacking and access to tasks that belonged to other sessions. Both are fixed in version 1.27.2 of the SDK.`CVE-2026-52869``CVE-2026-52870`MCPSDKsession isolation
2. Jun 2026 [Claude Code WebFetch auto-approval let data out via huggingface.co](https://dotsagent.io/security/incidents/2026-06-claude-code-webfetch-exfiltration)Claude Code 0.2.54 up to 2.1.163 auto-approved WebFetch requests to huggingface.co, so attacker content hosted there could pull data out of a session.`CVE-2026-54316`Claude Codedata exfiltrationegress
3. Apr 15, 2026 [Comment and Control: PR text steals secrets from CI agents](https://dotsagent.io/security/incidents/2026-04-comment-and-control-ci-secrets)Prompt injection in pull request and issue text stole CI secrets from Claude Code Security Review, Gemini CLI Action and GitHub Copilot Agent.CIprompt injectionsecrets
4. Feb 4, 2026 [MCP TypeScript SDK leaked responses between clients](https://dotsagent.io/security/incidents/2026-02-mcp-typescript-sdk-response-leak)MCP servers on the TypeScript SDK that shared one server or transport instance across clients could send one client's responses to another. Fixed in 1.26.0.`CVE-2026-25536`MCPSDKsession isolation
5. Feb 1, 2026 [ClawHavoc: hundreds of malicious ClawHub skills spread AMOS](https://dotsagent.io/security/incidents/2026-02-clawhavoc-malicious-skills)Koi Security found 341 malicious skills among 2,857 on ClawHub, most delivering Atomic macOS Stealer. By 16 February 2026 the count had reached 824.OpenClawsupply chainmalware
6. Jan 31, 2026 [Moltbook database exposed 1.5M agent API tokens](https://dotsagent.io/security/incidents/2026-01-moltbook-database-exposure)Moltbook, a social network for OpenClaw agents, left its Supabase database without row-level security, exposing about 1.5M API tokens, 35k emails and DMs.data exposureSupabaseOpenClaw
7. Jan 31, 2026 [OpenClaw gateways exposed to the internet at scale](https://dotsagent.io/security/incidents/2026-openclaw-gateways-exposed)Censys counted 21,639 OpenClaw gateways reachable from the public internet on 31 January 2026; OpenA2A's index put the figure at 192,492 on 1 September.OpenClawexposureconfiguration
8. Jan 30, 2026 [OpenClaw Control UI leaked gateway tokens for one-click RCE](https://dotsagent.io/security/incidents/2026-01-openclaw-control-ui-rce)OpenClaw's Control UI trusted a gatewayUrl query parameter, leaking the gateway token and enabling one-click RCE, even on loopback-only installs. CVSS 8.8.`CVE-2026-25253`OpenClawRCEtoken theft
9. Sep 25, 2025 [postmark-mcp: malicious MCP server copied every email](https://dotsagent.io/security/incidents/2025-09-postmark-mcp-backdoor)postmark-mcp 1.0.16 on npm quietly sent a blind copy of every email it handled to an attacker. Koi Security called it the first known malicious MCP server.`MAL-2025-47604`MCPsupply chainnpm
10. Jul 23, 2025 [Amazon Q Developer extension shipped with a wiper prompt](https://dotsagent.io/security/incidents/2025-07-amazon-q-wiper-prompt)Amazon Q Developer for VS Code 1.84.0 shipped with an injected prompt meant to wipe data. AWS traced it to an over-scoped GitHub token in CodeBuild.`CVE-2025-8217`supply chainCIcredentials
11. Jul 9, 2025 [mcp-remote OS command injection via authorization_endpoint](https://dotsagent.io/security/incidents/2025-07-mcp-remote-os-command-injection)mcp-remote 0.0.5 to 0.1.15 could run OS commands planted by a malicious MCP server in its authorization_endpoint value. CVSS 9.6, fixed in 0.1.16.`CVE-2025-6514`MCPRCEOAuth
12. Jul 1, 2025 [EscapeRoute: Filesystem MCP server sandbox escape](https://dotsagent.io/security/incidents/2025-07-filesystem-mcp-escaperoute)Cymulate found a sandbox escape and a symlink bypass in Anthropic's Filesystem MCP server, letting it reach files outside the directories it was allowed to use.`CVE-2025-53109``CVE-2025-53110`MCPsandbox escapefile access
13. Jul 2025 [Supabase MCP agent leaks tokens through a support ticket](https://dotsagent.io/security/incidents/2025-07-supabase-mcp-token-leak)A prompt injection in a support ticket made Cursor's agent, connected to Supabase MCP with the service_role key, read an integration tokens table and leak it.MCPprompt injectionlethal trifecta
14. Jun 13, 2025 [MCP Inspector proxy allowed remote code execution from a browser](https://dotsagent.io/security/incidents/2025-06-mcp-inspector-rce)MCP Inspector before 0.14.1 ran a local proxy without authentication that a web page could reach, giving code execution on the developer's machine. CVSS 9.4.`CVE-2025-49596`MCPRCEdeveloper tools
15. Jun 11, 2025 [EchoLeak: zero-click data theft from Microsoft 365 Copilot](https://dotsagent.io/security/incidents/2025-06-echoleak-m365-copilot)One crafted email made Microsoft 365 Copilot leak data without the user clicking anything. Aim Security reported it as EchoLeak; Microsoft fixed it server-side.`CVE-2025-32711`prompt injectiondata exfiltrationCopilot
16. May 26, 2025 [GitHub MCP toxic agent flow leaks private repos via a public issue](https://dotsagent.io/security/incidents/2025-05-github-mcp-toxic-agent-flow)Invariant Labs showed a malicious public GitHub issue steering an agent on the GitHub MCP server into copying private-repo data into a public pull request.MCPprompt injectiondata exfiltration
17. Apr 1, 2025 [MCP tool poisoning: hidden instructions in tool descriptions](https://dotsagent.io/security/incidents/2025-04-mcp-tool-poisoning)Invariant Labs showed that an MCP server can hide instructions in the tool descriptions a model reads, and described tool shadowing and rug-pull variants.MCPprompt injectionsupply chain

Independent reference for people who build AI agents. Not affiliated with any vendor named here.

© 2026 DotsAgent · Facts checked October 1, 2026
