Skip to content
StupidLLM
Incidents
Compare
Failure Modes
Methodology
Search
Home
/
Failure Modes
/
Security Vulnerability
Failure mode
Security Vulnerability
26 documented incidents where AI agents exhibited security vulnerability.
10.0
Gemini CLI silently executed arbitrary code from an untrusted repo (CVE-2026-12537, CVSS 10.0)
Gemini Cli
10.0
Malicious cloned repository triggered code execution in Cursor on Windows
Cursor
10.0
AI vibe-coded Next.js app pinned vulnerable dependency — cryptominer compromised production server
Unknown Agent
10.0
Clinejection: an AI issue-triage workflow enabled arbitrary code execution on the CI runner
Cline
10.0
GitHub Copilot suggested 2,702 valid secrets — 33% of extracted keys were real, live credentials
Github Copilot
10.0
Vibe-coded Moltbook exposed 1.5M API keys and 35,000 user emails via misconfigured database
Unknown Agent
10.0
Scan of 5,600 vibe-coded apps found 2,000+ high-impact vulns, 400+ exposed secrets, PII leaks
Multiple Agents
10.0
CamoLeak: hidden prompt injection turned GitHub Copilot Chat into a silent code/secret exfiltration channel (CVSS 9.6)
Github Copilot
10.0
Vibe-coded Tea app leaked 72,000 IDs and selfies plus 1.1M private messages from an unsecured bucket
Unknown Agent
10.0
Hacker slipped a data-wiping prompt into Amazon Q's VS Code extension, shipped to ~1M installs
Amazon Q
10.0
EchoLeak: a zero-click email silently exfiltrated data from Microsoft 365 Copilot (CVE-2025-32711, CVSS 9.3)
Microsoft Copilot
10.0
A hidden comment made GitLab Duo leak private source code and inject rogue HTML
Gitlab Duo
10.0
Lovable-built apps inverted access control, exposing 170+ production databases (CVE-2025-48757)
Lovable
10.0
Rule Files Backdoor: hidden Unicode in config files made Copilot and Cursor emit malicious code
Github Copilot
10.0
Slack AI could be tricked into leaking private-channel data via indirect prompt injection
Slack Ai
9.8
Cursor's terminal sandbox trusted an agent-set working directory, letting zero-click prompt injection escape it and gain code execution (CVE-2026-50548)
Cursor
9.2
An AI vendor's automated evaluation sandbox was prompt-injected into handing over its production API keys for multiple AI providers, which the attacker then used against the vendor and ~30 other AI companies (Anthropic GTG-50020)
Unknown Agent
8.5
Symlink-hijack lets a booby-trapped repo overwrite config in Claude Code, Gemini CLI, Cursor, Copilot CLI, Grok Build and Codex (SymJack)
Multiple Agents
8.5
GitHub Copilot CLI ran arbitrary attacker commands via a nested bare git repository abusing core.fsmonitor (CVE-2026-45033)
Github Copilot
8.3
Self-propagating npm worm plants persistence in Claude Code's hook files to survive credential rotation (ChainDrop / keyv supply-chain attack)
Claude Code
7.7
Claude Code's git worktree handling let a malicious repo escape the sandbox via symlink and fsmonitor tricks, overwriting shell init files (CVE-2026-55607)
Claude Code
7.5
Claude Code MCP trust boundary failures allow workspace privilege escalation
Claude Code
7.5
Claude Opus 4.5 leaked API key in console logs during YouTube scraper build
Claude Code
7.5
Manus AI leaked its own system prompt when a user simply asked it to read its internal directory
Manus
7.2
Claude Code leaked API keys via malicious repo settings before trust prompt
Claude Code
5.4
Claude Code loaded managed config from a world-writable Windows path, enabling local privilege escalation (CVE-2026-35603)
Claude Code