---
title: "智能体安全事件记录：自 2025 年以来共 17 起 · DotsAgent"
description: "自 2025 年 4 月以来公开的 AI agent 安全事件，涵盖 MCP 工具投毒、Claude Code WebFetch 数据外泄等；每起事件均附有 CVE、根本原因和修复措施。"
url: https://dotsagent.io/zh/security/incidents
---

自 2025 年以来的 17 起事件

# Agent 安全事件记录

按时间从近到远列出涉及 AI agent、MCP server 和 agent 平台的公开事件。每条记录都会说明事件经过、攻击得以奏效的原因，以及你可以如何调整自己的配置。

1. 2026年6月5日 [MCP Python SDK 会话劫持与跨会话任务访问](https://dotsagent.io/zh/security/incidents/2026-06-mcp-python-sdk-session-hijack)MCP Python SDK 中的两个漏洞可能导致会话劫持，以及访问属于其他会话的任务。SDK 1.27.2 已修复这两个漏洞。`CVE-2026-52869``CVE-2026-52870`MCPSDK会话隔离
2. 2026年6月 [Claude Code 的 WebFetch 自动批准功能可通过 huggingface.co 外传数据](https://dotsagent.io/zh/security/incidents/2026-06-claude-code-webfetch-exfiltration)Claude Code 0.2.54 至 2.1.163 会自动批准发往 huggingface.co 的 WebFetch 请求，因此托管在该网站上的恶意内容可能将会话数据带出。`CVE-2026-54316`Claude Code数据外传出站流量
3. 2026年4月15日 [评论与控制：PR 文本窃取 CI Agent 的机密](https://dotsagent.io/zh/security/incidents/2026-04-comment-and-control-ci-secrets)pull request 和 issue 文本中的提示注入窃取了 Claude Code Security Review、Gemini CLI Action 和 GitHub Copilot Agent 的 CI 机密。CI提示注入机密
4. 2026年2月4日 [MCP TypeScript SDK 在客户端之间泄露响应](https://dotsagent.io/zh/security/incidents/2026-02-mcp-typescript-sdk-response-leak)使用 MCP TypeScript SDK 构建的 MCP 服务器如果让多个客户端共用同一个服务器或 transport 实例，就可能把一个客户端的响应发送给另一个客户端。此问题已在 1.26.0 中修复。`CVE-2026-25536`MCPSDK会话隔离
5. 2026年2月1日 [ClawHavoc：数百个恶意 ClawHub skills 传播 AMOS](https://dotsagent.io/zh/security/incidents/2026-02-clawhavoc-malicious-skills)Koi Security 在 ClawHub 的 2,857 个 skills 中发现 341 个恶意项，大多数会投放 Atomic macOS Stealer。到 2026 年 2 月 16 日，恶意 skills 数量已达到 824 个。OpenClaw供应链恶意软件
6. 2026年1月31日 [Moltbook 数据库泄露 1.5M 个 agent API token](https://dotsagent.io/zh/security/incidents/2026-01-moltbook-database-exposure)面向 OpenClaw agent 的社交网络 Moltbook 未对其 Supabase 数据库启用行级安全，导致约 1.5M 个 API token、35k 个邮箱地址和私信暴露。数据泄露SupabaseOpenClaw
7. 2026年1月31日 [大量 OpenClaw 网关暴露于互联网](https://dotsagent.io/zh/security/incidents/2026-openclaw-gateways-exposed)Censys 统计显示，2026 年 1 月 31 日有 21,639 个 OpenClaw 网关可从公共互联网访问；OpenA2A 的索引显示，9 月 1 日这一数字达到 192,492。OpenClaw暴露配置
8. 2026年1月30日 [OpenClaw Control UI 泄露 gateway token，导致一键 RCE](https://dotsagent.io/zh/security/incidents/2026-01-openclaw-control-ui-rce)OpenClaw 的 Control UI 信任 gatewayUrl 查询参数，导致 gateway token 泄露并可一键触发 RCE，即使安装仅绑定到 loopback 也不例外。CVSS 8.8。`CVE-2026-25253`OpenClawRCEtoken 窃取
9. 2025年9月25日 [postmark-mcp：恶意 MCP 服务器暗中复制所有邮件](https://dotsagent.io/zh/security/incidents/2025-09-postmark-mcp-backdoor)npm 上的 postmark-mcp 1.0.16 会悄悄将其处理的每封邮件密送给攻击者。Koi Security 称这是已知的首个恶意 MCP 服务器。`MAL-2025-47604`MCP供应链npm
10. 2025年7月23日 [Amazon Q Developer 扩展中包含擦除数据的提示词](https://dotsagent.io/zh/security/incidents/2025-07-amazon-q-wiper-prompt)VS Code 版 Amazon Q Developer 1.84.0 随附了一个旨在擦除数据的注入提示词。AWS 将问题追溯到 CodeBuild 中权限范围过大的 GitHub token。`CVE-2025-8217`供应链CI凭据
11. 2025年7月9日 [mcp-remote 通过 authorization_endpoint 注入 OS 命令](https://dotsagent.io/zh/security/incidents/2025-07-mcp-remote-os-command-injection)mcp-remote 0.0.5 至 0.1.15 可能执行恶意 MCP 服务器在 authorization_endpoint 值中植入的 OS 命令。CVSS 评分为 9.6，已在 0.1.16 中修复。`CVE-2025-6514`MCP远程代码执行OAuth
12. 2025年7月1日 [EscapeRoute：Filesystem MCP 服务器沙箱逃逸](https://dotsagent.io/zh/security/incidents/2025-07-filesystem-mcp-escaperoute)Cymulate 在 Anthropic 的 Filesystem MCP 服务器中发现了沙箱逃逸和符号链接绕过漏洞，攻击者可借此访问授权目录之外的文件。`CVE-2025-53109``CVE-2025-53110`MCP沙箱逃逸文件访问
13. 2025年7月 [Supabase MCP 智能体通过支持工单泄露 token](https://dotsagent.io/zh/security/incidents/2025-07-supabase-mcp-token-leak)支持工单中的提示注入使 Cursor 智能体读取并泄露了集成 token 表；该智能体通过 service_role 密钥连接到 Supabase MCP。MCP提示注入致命三要素
14. 2025年6月13日 [MCP Inspector 代理可被浏览器用于远程代码执行](https://dotsagent.io/zh/security/incidents/2025-06-mcp-inspector-rce)0.14.1 之前的 MCP Inspector 会启动一个无身份验证的本地代理，网页可访问该代理并在开发者的机器上执行代码。CVSS 9.4。`CVE-2025-49596`MCPRCE开发者工具
15. 2025年6月11日 [EchoLeak：Microsoft 365 Copilot 遭遇零点击数据窃取](https://dotsagent.io/zh/security/incidents/2025-06-echoleak-m365-copilot)一封经过精心构造的邮件就能让 Microsoft 365 Copilot 泄露数据，用户无需点击任何内容。Aim Security 将此漏洞报告为 EchoLeak；Microsoft 已在服务器端修复。`CVE-2025-32711`prompt 注入数据外泄Copilot
16. 2025年5月26日 [GitHub MCP 恶意 agent 流程通过公开 issue 泄露私有仓库数据](https://dotsagent.io/zh/security/incidents/2025-05-github-mcp-toxic-agent-flow)Invariant Labs 展示了攻击者如何利用恶意的公开 GitHub issue 引导 GitHub MCP server 上的 agent，将私有仓库数据复制到公开 pull request 中。MCP提示词注入数据外泄
17. 2025年4月1日 [MCP 工具投毒：工具描述中的隐藏指令](https://dotsagent.io/zh/security/incidents/2025-04-mcp-tool-poisoning)Invariant Labs 展示了 MCP server 如何在模型读取的工具描述中隐藏指令，并介绍了工具影子攻击和 rug pull 变体。MCP提示词注入供应链

为 AI agent 开发者提供的独立参考资料。与此处提及的任何厂商均无关联。

© 2026 DotsAgent · 事实核查日期：2026年10月1日
