Agent security incident log
Public incidents involving AI agents, MCP servers and agent platforms, newest first. Each entry explains what happened, why the attack worked and what to change in your own setup.
MCP Python SDK session hijack and cross-session task access
Two flaws in the MCP Python SDK allowed session hijacking and access to tasks that belonged to other sessions. Both are fixed in version 1.27.2 of the SDK.
Claude Code WebFetch auto-approval let data out via huggingface.co
Claude Code 0.2.54 up to 2.1.163 auto-approved WebFetch requests to huggingface.co, so attacker content hosted there could pull data out of a session.
Comment and Control: PR text steals secrets from CI agents
Prompt injection in pull request and issue text stole CI secrets from Claude Code Security Review, Gemini CLI Action and GitHub Copilot Agent.
MCP TypeScript SDK leaked responses between clients
MCP servers on the TypeScript SDK that shared one server or transport instance across clients could send one client's responses to another. Fixed in 1.26.0.
ClawHavoc: hundreds of malicious ClawHub skills spread AMOS
Koi Security found 341 malicious skills among 2,857 on ClawHub, most delivering Atomic macOS Stealer. By 16 February 2026 the count had reached 824.
Moltbook database exposed 1.5M agent API tokens
Moltbook, a social network for OpenClaw agents, left its Supabase database without row-level security, exposing about 1.5M API tokens, 35k emails and DMs.
OpenClaw gateways exposed to the internet at scale
Censys counted 21,639 OpenClaw gateways reachable from the public internet on 31 January 2026; OpenA2A's index put the figure at 192,492 on 1 September.
OpenClaw Control UI leaked gateway tokens for one-click RCE
OpenClaw's Control UI trusted a gatewayUrl query parameter, leaking the gateway token and enabling one-click RCE, even on loopback-only installs. CVSS 8.8.
postmark-mcp: malicious MCP server copied every email
postmark-mcp 1.0.16 on npm quietly sent a blind copy of every email it handled to an attacker. Koi Security called it the first known malicious MCP server.
Amazon Q Developer extension shipped with a wiper prompt
Amazon Q Developer for VS Code 1.84.0 shipped with an injected prompt meant to wipe data. AWS traced it to an over-scoped GitHub token in CodeBuild.
mcp-remote OS command injection via authorization_endpoint
mcp-remote 0.0.5 to 0.1.15 could run OS commands planted by a malicious MCP server in its authorization_endpoint value. CVSS 9.6, fixed in 0.1.16.
EscapeRoute: Filesystem MCP server sandbox escape
Cymulate found a sandbox escape and a symlink bypass in Anthropic's Filesystem MCP server, letting it reach files outside the directories it was allowed to use.
Supabase MCP agent leaks tokens through a support ticket
A prompt injection in a support ticket made Cursor's agent, connected to Supabase MCP with the service_role key, read an integration tokens table and leak it.
MCP Inspector proxy allowed remote code execution from a browser
MCP Inspector before 0.14.1 ran a local proxy without authentication that a web page could reach, giving code execution on the developer's machine. CVSS 9.4.
EchoLeak: zero-click data theft from Microsoft 365 Copilot
One crafted email made Microsoft 365 Copilot leak data without the user clicking anything. Aim Security reported it as EchoLeak; Microsoft fixed it server-side.
GitHub MCP toxic agent flow leaks private repos via a public issue
Invariant Labs showed a malicious public GitHub issue steering an agent on the GitHub MCP server into copying private-repo data into a public pull request.
MCP tool poisoning: hidden instructions in tool descriptions
Invariant Labs showed that an MCP server can hide instructions in the tool descriptions a model reads, and described tool shadowing and rug-pull variants.