Security Vulnerability
20 documented incidents where AI agents exhibited security vulnerability.
STUPID-2026-000410.0criticalGithub CopilotVerified
Copilot autocompleted AWS credentials into public repository
STUPID-2026-000610.0criticalDevinVerified
Devin confidently shipped code that passed tests but had a SQL injection vulnerability
STUPID-2026-002210.0criticalUnknown AgentVerified
AI vibe-coded Next.js app pinned vulnerable dependency — cryptominer compromised production server
STUPID-2026-002710.0criticalGemini CliVerified
Gemini CLI silently executed arbitrary code from an untrusted repo (CVE-2026-12537, CVSS 10.0)
STUPID-2026-002810.0criticalGithub CopilotVerified
Rule Files Backdoor: hidden Unicode in config files made Copilot and Cursor emit malicious code
STUPID-2026-002910.0criticalCursorVerified
Malicious cloned repository triggered code execution in Cursor on Windows
STUPID-2026-003010.0criticalClineVerified
Clinejection: an AI issue-triage workflow enabled arbitrary code execution on the CI runner
STUPID-2026-003110.0criticalLovableVerified
Lovable-built apps inverted access control, exposing 170+ production databases (CVE-2025-48757)
STUPID-2026-003210.0criticalMultiple AgentsVerified
Scan of 5,600 vibe-coded apps found 2,000+ high-impact vulns, 400+ exposed secrets, PII leaks
STUPID-2026-003410.0criticalUnknown AgentVerified
Vibe-coded Moltbook exposed 1.5M API keys and 35,000 user emails via misconfigured database
STUPID-2026-003510.0criticalAmazon QVerified
Hacker slipped a data-wiping prompt into Amazon Q's VS Code extension, shipped to ~1M installs
STUPID-2026-003810.0criticalUnknown AgentVerified
Vibe-coded Tea app leaked 72,000 IDs and selfies plus 1.1M private messages from an unsecured bucket
STUPID-2026-004710.0criticalGithub CopilotVerified
GitHub Copilot suggested 2,702 valid secrets — 33% of extracted keys were real, live credentials
STUPID-2026-004810.0criticalGithub CopilotVerified
CamoLeak: hidden prompt injection turned GitHub Copilot Chat into a silent code/secret exfiltration channel (CVSS 9.6)
STUPID-2026-005110.0criticalMicrosoft CopilotVerified
EchoLeak: a zero-click email silently exfiltrated data from Microsoft 365 Copilot (CVE-2025-32711, CVSS 9.3)
STUPID-2026-005310.0criticalSlack AiVerified
Slack AI could be tricked into leaking private-channel data via indirect prompt injection
STUPID-2026-006110.0criticalGitlab DuoVerified
A hidden comment made GitLab Duo leak private source code and inject rogue HTML
STUPID-2026-00197.5highClaude CodeVerified
Claude Opus 4.5 leaked API key in console logs during YouTube scraper build
STUPID-2026-00247.5highClaude CodeVerified
Claude Code MCP trust boundary failures allow workspace privilege escalation
STUPID-2026-00637.5highManusVerified