AI Agent Threats

Browse by attack type

Showing 561–568 of 568 threats, newest first

MCPauthentication-bypasspath-traversaltelegramsession-hijackbearer-tokenASI01 · Goal HijackingSurface: ProtocolPropagation: Single Hop

The fast-mcp-telegram MCP server fails to sanitize Bearer tokens used for session file lookup, allowing a remote attacker to use path traversal sequences to authenticate as the default legacy Telegram session. This effectively bypasses the server's multi-user session isolation, letting an unauthenticated or low-privilege remote client impersonate the primary account owner and access their Telegram session and MCP tools.

Updated Jul 5, 2026 · CVSS 9.4

prompt-injectionmultilingual-attacksobfuscationjailbreakresearchphishing-generationmalware-generationsafety-alignmentASI01 · Goal HijackingAML.T0051AML.T0054Surface: ModelPropagation: None

This is an academic research paper (arXiv, not an active exploit) empirically benchmarking six major LLMs against direct, multilingual, and obfuscated prompt injection attacks. The study finds that all tested models can be induced to generate phishing content, malicious websites, and malware, with non-English prompts and multi-stage obfuscation significantly increasing compliance rates. Since this is a research disclosure rather than an in-the-wild exploit or agent-specific vulnerability, severity is rated medium rather than high/critical.

Updated Jul 5, 2026

researchprompt-injectionbenchmarkdefense-evaluationindirect-injectionfidelity-tradeoffASI01 · Goal HijackingAML.T0051Surface: ModelPropagation: None

This is an academic research paper, not an active exploit or vulnerability disclosure. It introduces a benchmark (SecFid) showing that current defenses against indirect prompt injection achieve security by suppressing untrusted text, which degrades task fidelity for legitimate uses like translation or document editing. No new attack technique or exploited system is described; it is a measurement and evaluation contribution.

Updated Jul 5, 2026

ASI06 · Memory PoisoningSurface: MemoryPropagation: Single Hop

Attackers seed false facts or standing instructions into an agent's long-term memory or RAG store, quietly steering decisions across future sessions long after the original malicious input is gone.

Updated Jul 3, 2026

ASI01 · Goal HijackingASI07 · Inter-Agent CommsSurface: Inter Agent CommsPropagation: Self Propagating

Adversarial instructions planted in content processed by one agent can replicate into its outputs and infect downstream agents, spreading through normal inter-agent messaging the way the Morris II research worm spread through AI email assistants.

Updated Jul 3, 2026

ASI05 · Unsafe Code ExecutionSurface: Tool LayerPropagation: NoneMCP

The MCP Inspector developer tool shipped a proxy that lacked authentication, allowing browser-based attackers to reach it from a malicious web page and execute code on the developer's machine. Reported by Oligo Security with a CVSS score of 9.4.

Updated Jul 3, 2026 · CVSS 9.4

ASI04 · Agentic Supply ChainSurface: ProtocolPropagation: NoneMCPsupply-chain

A critical flaw in the widely used mcp-remote OAuth proxy let malicious MCP servers achieve remote code execution on connecting developer machines, turning a routine agent connection into full host compromise. The package had hundreds of thousands of downloads before patching.

Updated Jul 3, 2026 · CVSS 9.6

ASI04 · Agentic Supply ChainSurface: Tool LayerPropagation: Single HopMCP

Malicious or compromised MCP servers embed hidden instructions in tool metadata that the model reads but the human approving the tool never sees, steering agents into data exfiltration or unauthorized actions. First documented publicly by Invariant Labs in 2025 and since reproduced across many clients.

Updated Jul 3, 2026