Threat Library

Agent-to-agent threats first — conventional coverage one click away.

Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10

Showing 20 of 541 threats

MCPMCPHubbroken-access-controlprivilege-escalationIDORadmin-bypassconfiguration-tamperingASI06 · Memory PoisoningSurface: ProtocolPropagation: Single Hop

MCPHub, a centralized hub for orchestrating multiple MCP servers, contained a broken access control flaw where any authenticated user could modify system-wide configuration via the PUT /api/system-config endpoint, since the handler never checked admin privileges. This allows a low-privileged user to reconfigure routing to MCP servers, potentially redirecting agent traffic, disabling security controls, or hijacking tool orchestration across the hub. The issue is fixed in version 1.0.29.

path-traversalzip-extractionmcpbmcp-server-managementarbitrary-file-writearbitrary-file-deletemanifest-injectionASI04 · Agentic Supply ChainSurface: Tool LayerPropagation: Single Hop

MCPHub, a hub for managing multiple MCP servers, fails to sanitize the manifest.json 'name' field when extracting uploaded MCPB (zip) files, allowing an attacker to use path traversal sequences to write files outside the intended extraction directory. The same unsanitized field is also used during cleanup, enabling arbitrary directory deletion. This lets a malicious MCP server package achieve file system compromise on the host running MCPHub, potentially leading to code execution or destructive data loss.

MCPbroken-access-controlmissing-authzprompt-injectionstored-injectionMCPHubIDOR-likemulti-tenantASI02 · Tool MisuseAML.T0051AML.T0054Surface: Tool LayerPropagation: Single Hop

MCPHub prior to version 1.0.32 fails to enforce admin-only access on prompt and resource management endpoints, allowing any authenticated non-admin user to create, overwrite, or shadow globally-served prompt templates and resources. Because these tampered records are consulted before any connected MCP server for every session, the flaw enables stored prompt injection into other users' LLM sessions. The issue is patched in 1.0.32.

MCPDNS-rebindingCSRForigin-validationlocal-serverash_aielixirASI05 · Unsafe Code ExecutionSurface: ProtocolPropagation: Single Hop

The ash_ai library's MCP server implementation has a flawed origin validation check that can be bypassed using DNS rebinding, allowing a malicious website to issue cross-site requests to a user's locally running MCP server as that user's authenticated actor. Both values used in the trust decision (Host header and X-Forwarded-Proto header) are attacker-controlled from the browser, making the check ineffective by default. This affects versions 0.8.0 through before 1.0.0 and is fixed by defaulting to trusting only localhost origins.

roboticsiotroot-rcebluetoothphysical-securityunitreehumanoid-robothardware

Security researcher Olivier Laflamme disclosed two independent exploit chains achieving root remote code execution on the Unitree G1 EDU humanoid robot, tracked as CVE-2026-76639 and CVE-2026-76640. One chain requires only Bluetooth Low Energy proximity to compromise the robot's Locomotion PC, while the other exploits a network-adjacent path through the chat_go and bashrunner components, posing serious risks for research, industrial, and educational deployments of the robot.

browser-extensioncryptocurrency-theftmalicious-extensionchromeedgewallet-stealeragent-relevant

Researchers identified 19 malicious Chrome and Edge extensions published over the past six months that steal cryptocurrency wallet secrets and drain funds. The extensions share common code and tradecraft, suggesting a coordinated campaign distributed through official browser extension stores. This poses a broad supply-chain risk to any user or organization installing these extensions.

clickfixsocial-engineeringpowershellwindows-terminalreverse-tunnelbackdoorfake-captchainitial-accessagent-relevant

Microsoft disclosed a new ClickFix-style social engineering campaign, dubbed TerminalFix, that uses fraudulent Cloudflare CAPTCHA pages to trick users into executing malicious commands in Windows Terminal or PowerShell instead of the traditional Run dialog. Successful execution deploys a reverse-tunnel backdoor granting attackers persistent remote access to the compromised host. This shift to terminal-based execution increases the likelihood that victims run more complex, capability-rich payloads compared to earlier ClickFix variants.

browser-extensionchrome-web-storeedgecryptocurrency-theftclickfixmalware-frameworkdata-exfiltrationagent-relevant

Multiple malicious extensions distributed through the Chrome Web Store and Microsoft Edge Add-ons store delivered a modular malware framework capable of stealing cryptocurrency, browsing history, and other sensitive data. The campaign also deployed ClickFix-style social engineering lures to trick users into executing further malicious commands, expanding the attack's reach beyond simple browser compromise.

infostealersession-hijackingcredential-theftAI-account-abuseagent-relevantLLM-abusetoken-theft

Anthropic has warned that infostealer malware infecting user PCs is exfiltrating active Claude session tokens, allowing attackers to hijack accounts and consume victims' paid usage. This represents a growing trend of infostealers specifically targeting AI service credentials and session cookies rather than just traditional banking or email accounts.

data-breachdata-theftaviationcustomer-dataextortion

The threat actor group FulcrumSec claims to have stolen 86 GB of data from Manchester Airports Group (MAG), including detailed customer, booking, and travel records. BleepingComputer validated at least one traveller's record from leaked samples, suggesting the breach scope exceeds what MAG initially disclosed.

langflownamespace-collisionuser-id-confusiondata-exposuremessage-injectionmulti-tenancyASI02 · Tool MisuseSurface: MemoryPropagation: Single Hop

IBM Langflow OSS versions 1.0.0 through 1.11.1 contain a flaw where user identifiers can collide across namespaces, allowing a remote attacker to access another user's sensitive data or inject messages into their session. This is a serious multi-tenancy isolation failure in a widely used agent-building framework, warranting prompt patching.

langflowpath-traversalfile-readagent-frameworkunauthenticated-accesscveASI08 · Cascading FailuresSurface: Tool LayerPropagation: Single Hop

A path traversal vulnerability in IBM Langflow OSS (versions 1.0.0 through 1.11.1) allows a remote attacker to read arbitrary files on the host system. Langflow is a visual builder for LLM/agent workflows, so this flaw could expose sensitive configuration, credentials, or agent memory/state files stored on disk. This is a genuine, high-severity infrastructure vulnerability rather than a novel agentic attack technique.

langflowimproper-authenticationunauthenticated-accessagent-frameworkflow-executioninformation-disclosureASI02 · Tool MisuseSurface: PlannerPropagation: Single Hop

IBM Langflow OSS versions 1.0.0 through 1.11.1 contain an improper authentication flaw that allows a remote attacker to execute arbitrary flows and access sensitive information without valid credentials. This is a genuine, high-impact vulnerability in a widely used agent/LLM orchestration framework that could let attackers run arbitrary agent pipelines and exfiltrate data. Organizations running affected versions should patch immediately.

langflowrcecode-injectionagent-frameworkauthenticated-attackerflow-builderASI05 · Unsafe Code ExecutionAML.T0011AML.T0053Surface: Tool LayerPropagation: Single Hop

IBM Langflow OSS versions 1.0.0 through 1.11.1 contain a vulnerability that allows a remote authenticated attacker to execute arbitrary code due to improper control over code generation. This affects a widely used low-code framework for building AI agent workflows, meaning any authenticated user could potentially compromise the underlying host or downstream agent components.

data-extortiongovernmentdata-breachberlinstate-networkdouble-extortion

Berlin's state administrative network was compromised in August 2026, with attackers exfiltrating data and subsequently demanding an extortion payment. The Berlin government has publicly refused to pay, and forensic investigation has revealed additional data outflows from the Senate Department for Mobility, Transport, Climate Protection and Environment, suggesting a broader compromise than initially disclosed.

print-managementpatch-bypassactive-exploitationrcepath-traversalauthentication-bypass

PaperCut has issued a second emergency patch after security researchers found multiple ways to bypass the initial fixes for two actively exploited vulnerabilities in PaperCut NG and MF print management software. Attackers exploiting these flaws can potentially achieve unauthorized access or remote code execution, prompting urgent re-patching for organizations still running vulnerable versions.

icsotcisa-advisoryfuel-managementargument-injectionbuffer-overflowrcephplegacy-software

All-Line Equipment Company's Fuel-Boss fuel management systems (Standard, Portal, Master/Slave, and Backflush variants) running PHP 7.1.5 or earlier are vulnerable to two high-severity flaws: an argument injection vulnerability in the PHP imap_open() function and a buffer overflow in PHP-FPM's FastCGI handling. Successful exploitation could allow remote attackers to execute arbitrary OS commands or code on affected systems, posing risk to critical manufacturing, defense, emergency services, and transportation sector operators using this equipment.

ICSOTdenial-of-serviceCC-LinkMELSECcritical-manufacturingMitsubishi-ElectricCVE-2025-3511

Multiple Mitsubishi Electric FA products, including CC-Link IE TSN modules and MELSEC iQ-R/iQ-F series Ethernet and CPU modules, contain a denial-of-service vulnerability (CVE-2025-3511) in their Ethernet function. A remote attacker can send a specially crafted UDP packet to cause a DoS condition, communication delay, or timeout error, requiring a system reset for recovery in most cases.

MCPDNS-rebindingSSRFlocalhost-exposureHTTP-transportmisconfigurationASI07 · Inter-Agent CommsSurface: ProtocolPropagation: Single Hop

pg-aiguide's MCP HTTP transport failed to enable a built-in DNS-rebinding protection option, allowing a malicious webpage to rebind a domain to the local server's address and issue unauthorized requests to the locally running MCP server via a victim's browser. This effectively bypasses the localhost trust boundary that MCP servers typically rely on for security. The issue was a configuration oversight rather than a missing SDK feature, and is fixed in version 0.5.1 by explicitly enabling the allow-list.

SSRFMCPserver-side-request-forgeryinstance-metadatacloud-credentialsurl-validation-bypasstool-poisoning-vectorASI05 · Unsafe Code ExecutionSurface: Tool LayerPropagation: Single Hop

An MCP server tool that fetches URLs on behalf of callers only validated the URL scheme and syntax, not the destination host or resolved IP address. This allowed any caller of the MCP server to force it to request internal-only endpoints, including cloud instance metadata services, and read back sensitive data such as cloud credentials.