Threat Library

Agent-to-agent threats first — conventional coverage one click away.

Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10

Showing 20 of 1541 threats

MCPtaint-analysistool-descriptionresearchcode-injectiondefensive-toolingLLM-self-reflectionASI05 · Unsafe Code ExecutionAML.T0051AML.T0053Surface: Tool LayerPropagation: Single Hop

This is a defensive research paper (not an active exploit) analyzing taint-style vulnerabilities in MCP server implementations, where untrusted input flows into dangerous sinks like command execution or file access. The authors propose SPELLSMITH, a mitigation that uses enhanced tool descriptions and LLM self-reflection to reduce exploitation risk without requiring code-level fixes. Severity is medium since it documents a real and underexplored class of vulnerabilities in deployed MCP servers, but the source itself is a proactive defense proposal rather than a disclosed active attack.

SSRFMCPmcp-whatsappunpatchedrolling-releaseinput-validationASI04 · Agentic Supply ChainSurface: Tool LayerPropagation: Single Hop

A server-side request forgery (SSRF) vulnerability exists in the aerostack-mcp project's mcp-whatsapp component, specifically in the upload_media function's media_url argument. A remote attacker can supply a malicious URL to force the MCP server to make unintended requests, potentially reaching internal network resources. The vendor has been notified but has not responded or patched the issue.

n8nMCPcredential-exfiltrationSSRFprivilege-escalationworkflow-automationuse-only-credential-bypassASI05 · Unsafe Code ExecutionSurface: Tool LayerPropagation: Single Hop

A vulnerability in n8n's AI Agents feature allowed a low-privilege user with only 'use' access to a shared credential to bypass the configured Allowed HTTP Request Domains restriction by pointing an MCP tool at an arbitrary attacker-controlled URL. This let the attacker exfiltrate the credential's secret value to an external server, effectively escalating from use-only access to full credential disclosure. The issue is fixed in n8n 2.27.4 and 2.28.1.

zero-day-brokerexploit-marketfraudvendor-risksupply-chaintrust-and-safetydisinformation

Krebs on Security reports that a startup soliciting zero-day vulnerabilities in popular software for large payouts is operated by individuals with histories of fraud, fake intelligence companies, and a defunct AI-based lobbying platform run under assumed identities. This raises significant vendor-trust and supply-chain risk concerns for any organization considering selling vulnerabilities to, or purchasing exploit intelligence from, this entity. There is no confirmed active exploitation tied to this report, but the operators' background suggests elevated risk of exploit misuse, data misrepresentation, or fraudulent business practices.

residential-proxyfake-installertrojanized-softwaremalvertisingdns-abuseagent-relevant

A threat actor dubbed Lurking Lizard has been running a residential proxy business since at least August 2022 using more than 230 lookalike domains that distribute trojanized software installers, including fake 7-Zip installers. Victims who download these fake installers unknowingly turn their devices into residential proxy exit nodes, which are then resold for anonymized traffic routing, potentially including malicious or fraudulent activity.

symlink-attackfile-write-confusionai-coding-agenttool-poisoningsupply-chainmalicious-repohuman-approval-bypassASI06 · Memory PoisoningAML.T0053AML.T0010Surface: Tool LayerPropagation: Single Hop

Researchers found that six popular AI coding assistants can be tricked by a malicious repository containing symlinks: the agent asks the user to approve an edit to what looks like a harmless file, but the actual write lands on a sensitive system file instead. This allows an attacker who convinces a developer to open a booby-trapped project to gain code execution or persistence on the developer's machine, bypassing the intended human-approval safety check.

prompt-injectioncode-executionautonomous-agentsclaude-codecodexsecurity-scanningproof-of-concepttool-misuseASI01 · Goal HijackingAML.T0051AML.T0053Surface: Tool LayerPropagation: Single Hop

Researchers at the AI Now Institute demonstrated an attack called 'Friendly Fire' where malicious source code, submitted for automated security review, tricks AI coding agents like Claude Code and OpenAI Codex into executing the attacker's payload on the host machine. This occurs when the agents run in autonomous modes that self-approve actions, turning a defensive scanning tool into a code execution vector.

npmpypisupply-chaincredential-theftpayment-fraudstealer-malwaretyposquattingagent-relevant

Threat actors published malicious packages on npm and PyPI masquerading as legitimate SDKs for Paysafe, Skrill, and Neteller payment platforms. These packages deliver information-stealing malware that harvests credentials from developers and downstream application users. The campaign highlights the ongoing risk of typosquatting and impersonation attacks within open-source package registries.

data-breachextortionhigher-educationfile-storagecredential-theft

Mount Royal University in Calgary confirmed that attackers breached its network and exfiltrated data from file storage systems before deleting it, with threat actors publicly claiming responsibility for the attack. The incident reflects an ongoing trend of threat actors targeting higher-education institutions for data theft and extortion rather than traditional ransomware encryption.

microsoft-defenderzero-daypatch-tuesdaywindowsendpoint-security

Microsoft disclosed and patched a zero-day vulnerability in Microsoft Defender, dubbed 'RoguePlanet', following the June 2026 Patch Tuesday cycle. The vulnerability was actively exploited or publicly known prior to patch release, prompting an out-of-band advisory. Organizations relying on Defender for endpoint protection should prioritize patching to prevent detection evasion or compromise of protected hosts.

icsotauthentication-bypassxssend-of-lifecisa-advisory

CISA disclosed two vulnerabilities in Digi International's PortServer TS and Digi One SP/SP IA/IA serial-to-network devices: an authentication bypass allowing unauthenticated access to restricted web resources, and a stored XSS flaw exploitable by authenticated administrators. These are legacy, end-of-life industrial devices used across critical manufacturing, communications, IT, and transportation sectors, with no vendor firmware fix planned for the XSS issue.

ICSOTenergy-sectorinsecure-transmissioncredential-theftsession-hijackingHitachi-EnergyPROMOD-V

Hitachi Energy PROMOD V versions 1.0.10 and prior rely on insecure HTTP communication instead of HTTPS due to a lack of TLS support in the third-party Digipede grid server component. This flaw could allow an attacker with network access to intercept or manipulate data in transit, potentially leading to credential theft, session hijacking, or unauthorized access to industrial engineering workstations.

xssspoofingdynamics-365customer-voicemicrosoftweb-vulnerabilityinput-validation

CVE-2026-47646 is a cross-site scripting (XSS) vulnerability in Microsoft Dynamics 365 Customer Voice that allows an unauthorized, unauthenticated attacker to inject malicious scripts and perform spoofing attacks over a network. With a CVSS score of 9.3, this flaw could enable attackers to impersonate legitimate users or interfaces, potentially harvesting credentials or session data submitted through survey forms.

wordpressplugin-vulnerabilityfile-uploadrceunauthenticatedcms-security

The Blocksy Companion Pro WordPress plugin (versions before 2.1.47) contains a critical unauthenticated arbitrary file upload vulnerability in its Advanced Reviews and Custom Fonts feature, allowing attackers to achieve remote code execution without any authentication. Exploitation involves bypassing a weak extension validation check using double-extension filenames, enabling attackers to upload and execute malicious PHP web shells. Given the CVSS score of 9.8 and ease of exploitation, this vulnerability poses severe risk to any WordPress site running the affected plugin version.

no-threatinformationalagentic-engineeringblog-postcode-rewriteSurface: Supply ChainPropagation: None

This is a blog post by Simon Willison describing how Bun's developer used AI coding agents (Claude) to rewrite the Bun JavaScript runtime from Zig to Rust, validated against a TypeScript conformance test suite. There is no security vulnerability, exploit, prompt injection, or agent threat described in this content; it is a case study in large-scale agentic software engineering.

CSWSHcross-site-websocket-hijackingMCPorigin-validationlocalhost-bypassclineagent-hubrceASI05 · Unsafe Code ExecutionSurface: Inter Agent CommsPropagation: Single Hop

Cline's local Hub dashboard server fails to validate the Origin header on its WebSocket /browser endpoint, allowing any malicious website visited by a user to connect and issue commands. When ROOM_SECRET is unset (the default for local binds), attackers can read workspace state, tamper with MCP and provider settings, and trigger arbitrary command execution if a model provider is configured. This is a critical, fully remotely exploitable vulnerability via drive-by browser interaction with no user awareness required.

MCPauthentication-bypassLiteLLMunauthenticated-accessAI-gatewayOAuth2privilege-escalationASI08 · Cascading FailuresAML.T0049AML.T0053Surface: ProtocolPropagation: Single Hop

LiteLLM's MCP Streamable HTTP endpoint prior to version 1.84.0 could be tricked into skipping key validation by sending a fabricated Authorization header, causing the server to fall back to an empty, effectively unauthenticated user context. This let attackers reach MCP tooling and any downstream tools/agents exposed through the proxy without holding a valid LiteLLM API key. The vulnerability is fixed in 1.84.0.

path-traversalfile-exfiltrationprompt-injectioncomposiofile-upload-toolcredential-theftssh-keysASI05 · Unsafe Code ExecutionAML.T0051AML.T0048Surface: Tool LayerPropagation: Single Hop

Composio SDK versions before 0.2.32-beta.283 fail to validate file paths in a file-upload tool, allowing an attacker who controls untrusted input (e.g., via prompt injection) to redirect the agent into reading and uploading sensitive local files such as SSH private keys to attacker-controlled storage. This is a realistic and impactful supply-chain/tool-layer vulnerability, not a speculative or low-severity issue.

surveysystematization-of-knowledgesandbox-isolationTOCTOUaccess-controlMCPcoding-agentsCVE-reviewresearch-paperASI05 · Unsafe Code ExecutionSurface: Tool LayerPropagation: None

This is an academic survey (SoK) that reviews and categorizes 39 existing papers on execution-layer security for AI coding agents, rather than describing a novel exploit or active campaign. It highlights systemic weaknesses across the field—such as high denylist bypass rates, unaddressed TOCTOU races, and fragmented treatment of MCP threats—and references four previously disclosed, already-patched CVEs. Severity is low-to-medium as a direct threat signal since no new vulnerability or attack technique is disclosed; its value is as a roadmap of known/likely weak points defenders should prioritize.

MCPunicode-steganographytool-poisoningapproval-bypasstag-blockrug-pulltool-description-injectionhuman-in-the-loop-bypassASI05 · Unsafe Code ExecutionAML.T0051AML.T0054Surface: ProtocolPropagation: Single Hop

Researchers demonstrate a structural flaw in the Model Context Protocol: the metadata a human approves in a tool-installation dialog is not guaranteed to match the bytes actually sent to the model. Using invisible Unicode TAG-block characters embedded in tool descriptions, an attacker can smuggle hidden instructions that a human reviewer never sees but that reach the LLM verbatim on every turn, and this was confirmed across three independent MCP server implementations. This is a research proof-of-concept, not an observed active exploit, but it identifies a reproducible, protocol-level weakness rather than a one-off bug.