CVE Watch

LIVE

Tracked vulnerabilities in AI agent infrastructure — MCP servers, tool runtimes, SDKs, and orchestration layers. CVSS scores, affected versions, and Ofir's analysis.

35 CVEs tracked

CVE IDTitleSeverityCVSSAffected ToolDisclosed
CVE-2026-32173Azure SRE Agent Authentication Bypass Enables Unauthenticated Info Disclosure
azuresre-agent
high8.6Microsoft Azure SRE Agent
unspecified
Apr 3, 2026
CVE-2026-34159llama.cpp RPC Deserialization Bypass Enables Unauthenticated RCE
llama.cppinference-engine
critical9.8llama.cpp
< b8492
Apr 1, 2026
CVE-2026-34742MCP Go SDK DNS Rebinding Allows Malicious Websites to Invoke Local Agent Tools
mcpgo-sdk
highN/AModel Context Protocol Go SDK
< 1.4.0
Apr 1, 2026
TH-10Axios npm Supply Chain Attack — Cross-Platform RAT via Postinstall Script
supply-chainnpm
criticalN/Aaxios (npm)
malicious versions published 2026-03-31 00:21–03:15 UTC
Mar 31, 2026
TH-05ChatGPT Code Execution Runtime — Hidden DNS Outbound Channel Enables Data Exfiltration
chatgptdata-exfiltration
highN/AOpenAI ChatGPT (Code Execution / Data Analysis runtime)
< 2026-02-20
Mar 30, 2026
TH-04OpenAI Codex Command Injection via Branch Name — GitHub Token Theft
ai-coding-agentcommand-injection
highN/AOpenAI Codex
< Feb 5 2026 (web, SDK, IDE integrations)
Mar 30, 2026
CVE-2026-32922OpenClaw Token Scope Bypass Allows Unauthenticated Privilege Escalation to Admin RCE
openclawprivilege-escalation
critical9.9OpenClaw
< 2026.3.11
Mar 29, 2026
CVE-2026-27893vLLM RCE via Hardcoded trust_remote_code Override
vllminference
high8.8vLLM
>= 0.10.1, < 0.18.0
Mar 27, 2026
CVE-2026-33989Path Traversal in mobile-mcp Allows Arbitrary File Write via Screenshot Tools
mcpagentic-security
high8.1@mobilenext/mobile-mcp
< 0.0.49
Mar 27, 2026
CVE-2026-32628AnythingLLM SQL Injection in Built-in SQL Agent Plugin
sql-injectionagentic-security
high8.8AnythingLLM
≤ 1.11.1
Mar 26, 2026
TH-03Azure MCP Server RCE Enables Full Entra ID / Cloud Tenant Takeover
mcpazure
criticalN/AAzure MCP Server
Streamable HTTP/SSE transport mode (all versions prior to patch)
Mar 26, 2026
CVE-2026-23744MCPJam Inspector RCE via Unauthenticated MCP Server Installation
mcpagentic-security
highN/AMCPJam Inspector
≤ 1.4.2
Mar 25, 2026
TH-02TeamPCP Backdoors LiteLLM via Trivy-Stolen CI/CD Credentials — 3.4M Daily Downloads, LLM API Keys Targeted
litellmsupply-chain
highN/ALiteLLM
1.82.7, 1.82.8
Mar 24, 2026
CVE-2026-33010mcp-memory-service Wildcard CORS Lets Any Website Steal, Modify, or Delete Agent Memories
mcpagentic-security
high8.1mcp-memory-service
< 10.25.1
Mar 20, 2026
CVE-2026-33068Claude Code Workspace Trust Dialog Bypassed by Malicious Repository Settings File
claude-codeagentic-security
high7.7Claude Code CLI
< 2.1.53
Mar 20, 2026
CVE-2026-25536MCP TypeScript SDK Cross-Client Response Data Leak in Shared Server Deployments
mcpagentic-security
high8.1@modelcontextprotocol/sdk (TypeScript)
1.10.0 – 1.25.3
Mar 17, 2026
CVE-2026-33017Langflow Unauthenticated RCE via Public Flow Build Endpoint — Exploited in 20 Hours
langflowagentic-security
critical9.3Langflow
<= 1.8.1
Mar 17, 2026
CVE-2026-4270AWS API MCP Server File Access Restriction Bypass
mcpagentic-security
highN/AAWS API MCP Server (awslabs.aws-api-mcp-server)
>= 0.2.14, < 1.3.9
Mar 16, 2026
CVE-2026-32617AnythingLLM: No Authentication on HTTP Endpoints and Agent WebSocket by Default
llm-frameworkauthentication-bypass
highN/AAnythingLLM (Mintplex-Labs)
≤ 1.11.1
Mar 14, 2026
CVE-2026-3059Unauthenticated RCE in SGLang LLM Serving Framework via Pickle Deserialization
llm-infrastructuredeserialization
criticalN/ASGLang
< 0.4.6.post1
Mar 12, 2026
CVE-2026-3060SGLang Encoder Disaggregation RCE via Unauthenticated Pickle Deserialization
llm-servingpickle
critical9.8SGLang LLM Serving Framework
< unpatched (no official fix at time of publication)
Mar 12, 2026
CVE-2026-32247Graphiti Cypher Injection via LLM-Controlled Search Filters
mcpagentic-security
highN/AGraphiti (graphiti-core)
< 0.28.2
Mar 12, 2026
CVE-2026-27826Unauthenticated SSRF in mcp-atlassian via Custom Header Injection
mcpatlassian
high8.5mcp-atlassian
< patched
Mar 11, 2026
CVE-2026-31829SSRF in Flowise AgentFlow HTTP Node Enables Internal Network Pivoting
flowiseagent-orchestration
highN/AFlowise
< patched
Mar 11, 2026
CVE-2026-26030Critical RCE in Microsoft Semantic Kernel Python SDK via Malicious Filter Expressions
semantic-kernelagentic-security
critical9.8Microsoft Semantic Kernel Python SDK
< patched March 2026 release
Mar 10, 2026
CVE-2026-26118Azure MCP Server SSRF Enables Token Theft and Privilege Escalation
azuremcp
high8.8Azure MCP Server
< March 2026 patched release
Mar 10, 2026
CVE-2026-26144Microsoft Excel XSS Enables Zero-Click Silent Data Exfiltration via Copilot Agent
copilotexcel
high7.5Microsoft Excel (with Copilot Agent mode)
Microsoft Excel (pre-March 2026 Patch Tuesday)
Mar 10, 2026
CVE-2026-30856Tool Execution Hijacking and Indirect Prompt Injection in Tencent WeKnora
mcptool-hijacking
highN/ATencent WeKnora
< 0.3.0
Mar 7, 2026
CVE-2026-29783GitHub Copilot CLI Shell Expansion Bypass Enables Arbitrary Code Execution
copilotshell
highN/AGitHub Copilot CLI
< 1.0.0 (patched build March 2026)
Mar 6, 2026
TH-01Malicious AI Browser Extensions Harvest LLM Chat Histories at Enterprise Scale
supply-chainagentic-security
highN/AChromium-based AI assistant browser extensions (ChatGPT, DeepSeek sidebars)
N/A — supply chain campaign
Mar 5, 2026
CVE-2025-59536Claude Code MCP Consent Bypass — Repository Config Executes Before User Trust
claude-codemcp
high8.7Anthropic Claude Code
< patched (Feb 2026)
Feb 28, 2026
CVE-2026-21852Claude Code API Key Theft via Malicious Repo — Zero Interaction Required
claude-codemcp
criticalN/AAnthropic Claude Code
< patched (Feb 2026)
Feb 28, 2026
CVE-2026-27825MCP SDK Remote Code Execution via Malformed Tool Response
mcpremote-code-execution
critical9.8MCP SDK
<=1.2.3
Feb 28, 2026
CVE-2026-27896MCP Go SDK Case-Insensitive JSON Parsing Allows Security Control Bypass
mcpagentic-security
high7.5Model Context Protocol (MCP) Go SDK
< patched release
Feb 28, 2026
CVE-2026-27966Langflow CSV Agent Node Executes LLM-Controlled Code Without Sandboxing — Full Server RCE
langflowrce
critical10.0Langflow (CSV Agent node)
< patched (Feb 2026)
Feb 25, 2026