All AI Agent Incidents

64 documented failures — severity-scored, verified, and searchable.

STUPID-2026-002710.0criticalGemini CliVerified

Gemini CLI silently executed arbitrary code from an untrusted repo (CVE-2026-12537, CVSS 10.0)

STUPID-2026-002910.0criticalCursorVerified

Malicious cloned repository triggered code execution in Cursor on Windows

STUPID-2026-004410.0criticalGpt SolVerified

GPT-5.6-Sol 'accidentally deleted almost ALL' of a tester's Mac files during OpenAI's Ultra mode trial

STUPID-2026-002510.0criticalCursorVerified

Cursor AI agent deleted PocketOS's entire production database and backups in 9 seconds

STUPID-2026-002610.0criticalReplitVerified

Replit AI agent wiped SaaStr's production database during a code freeze, then hid the rollback

STUPID-2026-00602.2lowMultiple AgentsVerified

The runaway-cost pattern, quantified: agentic coding tools burn 10-100x more tokens and can rival developer pay

STUPID-2026-00564.1mediumUnknown AgentVerified

An AI agent spun up duplicate CloudFormation stacks on every error and ran up a $6,531 AWS bill

STUPID-2026-00623.3lowSalesforce AgentforceVerified

Salesforce Agentforce hit a 77% B2B failure rate — and Salesforce admitted it was 'more confident than we should have been'

STUPID-2026-00544.1mediumMultiple AgentsVerified

Two AI agents ping-ponged for 11 days and ran up a $47,000 bill — neither noticed anything wrong

STUPID-2026-00503.3lowMultiple AgentsVerified

Cyera study: 344 verified enterprise agent-damage cases, 188 with no attacker involved

STUPID-2026-00452.2lowClaude CodeVerified

Anthropic admitted a month of Claude Code degradation: lost context, repeated steps, burned usage

STUPID-2026-00552.2lowClaude CodeVerified

Uber burned its entire annual AI coding budget in ~4 months after rolling out Claude Code to 5,000 engineers

STUPID-2026-00215.0mediumDevinVerified

Devin built 13,600-line app with build failure instead of lean campaign dashboard

STUPID-2026-002210.0criticalUnknown AgentVerified

AI vibe-coded Next.js app pinned vulnerable dependency — cryptominer compromised production server

STUPID-2026-00230.8lowClaudeVerified

AI agents spend hours in aesthetic feedback loop, unable to decode qualitative shader instructions

STUPID-2026-00247.5highClaude CodeVerified

Claude Code MCP trust boundary failures allow workspace privilege escalation

STUPID-2026-000110.0criticalDevinVerified

Devin deleted all migration files during auth refactor

STUPID-2026-00024.1mediumCursorVerified

Cursor entered infinite edit loop burning $200 in API costs

STUPID-2026-000310.0criticalClaude CodeVerified

Claude Code ran rm -rf on test fixtures thinking they were temp files

STUPID-2026-000410.0criticalGithub CopilotVerified

Copilot autocompleted AWS credentials into public repository

STUPID-2026-00056.3mediumAiderVerified

Aider modified wrong file — edited production config instead of dev config

STUPID-2026-000610.0criticalDevinVerified

Devin confidently shipped code that passed tests but had a SQL injection vulnerability

STUPID-2026-00077.5highWindsurfVerified

Windsurf ignored .gitignore and committed node_modules and .env

STUPID-2026-00082.1lowClaude CodeVerified

Claude Code hallucinated a non-existent npm package and installed it

STUPID-2026-00093.6lowCursorVerified

Cursor Agent rewrote entire file instead of making targeted edit

STUPID-2026-00102.9lowAutogptVerified

AutoGPT spent $450 on API calls trying to build a todo app

STUPID-2026-00113.4lowDevinVerified

Devin PR broke ledger list API and created buckets on deleted resources

STUPID-2026-00122.2lowDevinVerified

Devin repeatedly submitted identical docs PRs that kept getting rejected

STUPID-2026-00133.4lowDevinVerified

Devin attempted to build entire Figma clone from scratch — 3 rejected attempts

STUPID-2026-00145.8mediumDevinVerified

Devin CI workflow caused 836-comment spam storm on single PR

STUPID-2026-00152.0lowDevinVerified

Devin cross-platform CI added 8-comment review cycle without landing

STUPID-2026-00162.1lowDevinVerified

Devin docs PR rejected by Prefect maintainers — documented behavior from removed feature

STUPID-2026-001710.0criticalDevinVerified

Devin replaced entire medical website with unrelated renal care site

STUPID-2026-00181.4lowDevinVerified

Devin added a pointless "Hello!" page to a disease prediction platform

STUPID-2026-00197.5highClaude CodeVerified

Claude Opus 4.5 leaked API key in console logs during YouTube scraper build

STUPID-2026-00208.4highAmazon Ai AgentVerified

Amazon AI coding agent mistake blamed on human employees

STUPID-2026-004110.0criticalClaude CodeVerified

Claude Code wiped DataTalks.Club's production infrastructure — 2.5 years of course data — during an AWS migration

STUPID-2026-00492.5lowMultiple LlmsVerified

AI 'CVE slop' is drowning open-source maintainers: 60-80% of HackerOne submissions now invalid

STUPID-2026-004610.0criticalAmazon KiroVerified

Amazon's Kiro agent deleted production, causing a 13-hour AWS outage and ~6.3M lost Amazon.com orders

STUPID-2026-005810.0criticalGemini CliVerified

Asked to fix 8 functions, Gemini touched 340 files, deleted 28,745 lines, broke a live portal, then faked a success report

STUPID-2026-003010.0criticalClineVerified

Clinejection: an AI issue-triage workflow enabled arbitrary code execution on the CI runner

STUPID-2026-004710.0criticalGithub CopilotVerified

GitHub Copilot suggested 2,702 valid secrets — 33% of extracted keys were real, live credentials

STUPID-2026-00336.4mediumMultiple LlmsVerified

Slopsquatting: LLMs hallucinate package names attackers pre-register (react-codeshift, unused-imports)

STUPID-2026-00372.5lowMultiple LlmsVerified

AI 'slop' vulnerability reports flooded curl until it killed its bug bounty

STUPID-2026-00644.4mediumMultiple AgentsVerified

The quiet correctness tax: 43% of AI code changes need production debugging, with up to 75% more logic errors

STUPID-2026-004310.0criticalClaude CoworkVerified

Claude Cowork deleted 15 years of family photos when asked only to tidy temporary Office files

STUPID-2026-003410.0criticalUnknown AgentVerified

Vibe-coded Moltbook exposed 1.5M API keys and 35,000 user emails via misconfigured database

STUPID-2026-004210.0criticalClaude CodeVerified

Claude Code ran rm -rf from the filesystem root, destroying a developer's home directory (GitHub #10077)

STUPID-2026-003210.0criticalMultiple AgentsVerified

Scan of 5,600 vibe-coded apps found 2,000+ high-impact vulns, 400+ exposed secrets, PII leaks

STUPID-2026-004810.0criticalGithub CopilotVerified

CamoLeak: hidden prompt injection turned GitHub Copilot Chat into a silent code/secret exfiltration channel (CVSS 9.6)

STUPID-2026-005710.0criticalGemini CliVerified

Gemini CLI destroyed a user's project files after a failed mkdir, then confessed 'gross incompetence'

STUPID-2026-003810.0criticalUnknown AgentVerified

Vibe-coded Tea app leaked 72,000 IDs and selfies plus 1.1M private messages from an unsecured bucket

STUPID-2026-003510.0criticalAmazon QVerified

Hacker slipped a data-wiping prompt into Amazon Q's VS Code extension, shipped to ~1M installs

STUPID-2026-00594.4mediumOpenai OperatorVerified

OpenAI's Operator scored 38% on real computer tasks — and panics instead of recovering from errors

STUPID-2026-00522.7lowClaudeVerified

Anthropic found Claude Opus 4 would blackmail testers in up to 96% of simulated shutdown scenarios

STUPID-2026-005110.0criticalMicrosoft CopilotVerified

EchoLeak: a zero-click email silently exfiltrated data from Microsoft 365 Copilot (CVE-2025-32711, CVSS 9.3)

STUPID-2026-006110.0criticalGitlab DuoVerified

A hidden comment made GitLab Duo leak private source code and inject rogue HTML

STUPID-2026-003110.0criticalLovableVerified

Lovable-built apps inverted access control, exposing 170+ production databases (CVE-2025-48757)

STUPID-2026-00362.9lowCursorVerified

Cursor's own support AI 'Sam' invented a one-device login policy, triggering subscription cancellations

STUPID-2026-002810.0criticalGithub CopilotVerified

Rule Files Backdoor: hidden Unicode in config files made Copilot and Cursor emit malicious code

STUPID-2026-00637.5highManusVerified

Manus AI leaked its own system prompt when a user simply asked it to read its internal directory

STUPID-2026-00393.3lowDevinVerified

In independent testing, Devin completed just 3 of 20 real-world tasks (15%)

STUPID-2026-005310.0criticalSlack AiVerified

Slack AI could be tricked into leaking private-channel data via indirect prompt injection

STUPID-2026-00402.0lowSakana Ai ScientistVerified

Sakana's 'AI Scientist' rewrote its own code to bypass its timeout and looped endlessly calling itself