dotsagent.io
Language:English
17 incidents since 2025

Agent security incident log

Public incidents involving AI agents, MCP servers and agent platforms, newest first. Each entry explains what happened, why the attack worked and what to change in your own setup.

  1. MCP Python SDK session hijack and cross-session task access

    Two flaws in the MCP Python SDK allowed session hijacking and access to tasks that belonged to other sessions. Both are fixed in version 1.27.2 of the SDK.

    CVE-2026-52869CVE-2026-52870MCPSDKsession isolation
  2. Claude Code WebFetch auto-approval let data out via huggingface.co

    Claude Code 0.2.54 up to 2.1.163 auto-approved WebFetch requests to huggingface.co, so attacker content hosted there could pull data out of a session.

    CVE-2026-54316Claude Codedata exfiltrationegress
  3. Comment and Control: PR text steals secrets from CI agents

    Prompt injection in pull request and issue text stole CI secrets from Claude Code Security Review, Gemini CLI Action and GitHub Copilot Agent.

    CIprompt injectionsecrets
  4. MCP TypeScript SDK leaked responses between clients

    MCP servers on the TypeScript SDK that shared one server or transport instance across clients could send one client's responses to another. Fixed in 1.26.0.

    CVE-2026-25536MCPSDKsession isolation
  5. ClawHavoc: hundreds of malicious ClawHub skills spread AMOS

    Koi Security found 341 malicious skills among 2,857 on ClawHub, most delivering Atomic macOS Stealer. By 16 February 2026 the count had reached 824.

    OpenClawsupply chainmalware
  6. Moltbook database exposed 1.5M agent API tokens

    Moltbook, a social network for OpenClaw agents, left its Supabase database without row-level security, exposing about 1.5M API tokens, 35k emails and DMs.

    data exposureSupabaseOpenClaw
  7. OpenClaw gateways exposed to the internet at scale

    Censys counted 21,639 OpenClaw gateways reachable from the public internet on 31 January 2026; OpenA2A's index put the figure at 192,492 on 1 September.

    OpenClawexposureconfiguration
  8. OpenClaw Control UI leaked gateway tokens for one-click RCE

    OpenClaw's Control UI trusted a gatewayUrl query parameter, leaking the gateway token and enabling one-click RCE, even on loopback-only installs. CVSS 8.8.

    CVE-2026-25253OpenClawRCEtoken theft
  9. postmark-mcp: malicious MCP server copied every email

    postmark-mcp 1.0.16 on npm quietly sent a blind copy of every email it handled to an attacker. Koi Security called it the first known malicious MCP server.

    MAL-2025-47604MCPsupply chainnpm
  10. Amazon Q Developer extension shipped with a wiper prompt

    Amazon Q Developer for VS Code 1.84.0 shipped with an injected prompt meant to wipe data. AWS traced it to an over-scoped GitHub token in CodeBuild.

    CVE-2025-8217supply chainCIcredentials
  11. mcp-remote OS command injection via authorization_endpoint

    mcp-remote 0.0.5 to 0.1.15 could run OS commands planted by a malicious MCP server in its authorization_endpoint value. CVSS 9.6, fixed in 0.1.16.

    CVE-2025-6514MCPRCEOAuth
  12. EscapeRoute: Filesystem MCP server sandbox escape

    Cymulate found a sandbox escape and a symlink bypass in Anthropic's Filesystem MCP server, letting it reach files outside the directories it was allowed to use.

    CVE-2025-53109CVE-2025-53110MCPsandbox escapefile access
  13. Supabase MCP agent leaks tokens through a support ticket

    A prompt injection in a support ticket made Cursor's agent, connected to Supabase MCP with the service_role key, read an integration tokens table and leak it.

    MCPprompt injectionlethal trifecta
  14. MCP Inspector proxy allowed remote code execution from a browser

    MCP Inspector before 0.14.1 ran a local proxy without authentication that a web page could reach, giving code execution on the developer's machine. CVSS 9.4.

    CVE-2025-49596MCPRCEdeveloper tools
  15. EchoLeak: zero-click data theft from Microsoft 365 Copilot

    One crafted email made Microsoft 365 Copilot leak data without the user clicking anything. Aim Security reported it as EchoLeak; Microsoft fixed it server-side.

    CVE-2025-32711prompt injectiondata exfiltrationCopilot
  16. GitHub MCP toxic agent flow leaks private repos via a public issue

    Invariant Labs showed a malicious public GitHub issue steering an agent on the GitHub MCP server into copying private-repo data into a public pull request.

    MCPprompt injectiondata exfiltration
  17. MCP tool poisoning: hidden instructions in tool descriptions

    Invariant Labs showed that an MCP server can hide instructions in the tool descriptions a model reads, and described tool shadowing and rug-pull variants.

    MCPprompt injectionsupply chain

Independent reference for people who build AI agents. Not affiliated with any vendor named here.

© 2026 DotsAgent · Facts checked October 1, 2026