Category
Vulnerability
A disclosed flaw in a named AI product, with or without a CVE.
Incident feed
8 of 8 · newest firstCVE-2026-103435Claude Code: symlink race allowed writes outside the projectCVE-2026-103435 is a time-of-check to time-of-use race in Claude Code before 2.1.129. A user who can write to a shared workspace could swap a file for a symlink and make Claude Code write outside the project.
CVE-2026-104850MCP TypeScript SDK: OAuth client could leak credentials to serversCVE-2026-104850 in the MCP TypeScript SDK let a malicious MCP server pick the authorization server that receives a client's OAuth refresh tokens and client secrets. Fixed in @modelcontextprotocol/sdk 1.31.0 and client 2.2.0.
CVE-2026-102697Ollama agent mode: chained shell commands skip Bash approvalCVE-2026-102697 lets prompt-injected output in Ollama's experimental agent mode add commands after an approved one with ;, && or ||, so they run without approval. Ollama 0.14.0 to before 0.31.2 is affected.
AnthropicClaude Desktop for macOS: Cowork files could run commands on openClaude Desktop for macOS before 1.15962.0 could run commands on the host when a user opened a malicious file from a Cowork folder, because its blocklist of executable file types was incomplete. Anthropic rated it CVSS 4.0 8.5.
Zenity Labs
SalesBleed: zero-click CRM data theft through Salesforce AgentforceSalesBleed is a Zenity Labs attack in which one web form lead carrying a prompt injection made Salesforce Agentforce leak Accounts data through DNS with zero clicks. Salesforce hardened its Trusted URLs filter in August 2026.Claude Code
Plugin4Shell: zero-click plugin RCE in four AI coding agentsPlugin4Shell is a zero-click remote code execution flaw in how Claude Code, Codex, GitHub Copilot and Gemini CLI install pinned plugins. AIR says Claude Code and Codex are fixed, Copilot is not, and Gemini CLI will not be patched.CVE-2026-65669
SQL Server Copilot: prompt injection escalates a user to sysadminCVE-2026-65669 let indirect prompt injection push GitHub Copilot in SQL Server Management Studio past its read-only mode and run T-SQL with a sysadmin's privileges. Microsoft rates it CVSS 9.6; SSMS 22.8.2 fixes it.ChatGPT connectors
ChatGPT sandbox: shared package cache leaked data across accountsCheck Point Research found that ChatGPT code containers from different accounts shared one internal JFrog Artifactory, giving attackers a hidden channel into a victim's session and connected apps. OpenAI shut the instance down.
0 matches. Clear a filter or try another term.