<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>ACVE advisories</title><link>https://agentcve.org/</link><description>Public registry of known-vulnerable AI agent configurations.</description><lastBuildDate>2026-09-20T02:45:17.577Z</lastBuildDate><item><title>ACVE-2026-0007 — Gemini CLI can execute commands from repository settings</title><link>https://agentcve.org/ACVE-2026-0007</link><guid isPermaLink="false">ACVE-2026-0007@2026-09-20T02:45:17.577Z</guid><pubDate>2026-09-20T02:45:17.577Z</pubDate><description>Gemini CLI can execute commands from repository settings</description></item><item><title>ACVE-2026-0004 — Claude Code deny rules can be bypassed through symlinked tools</title><link>https://agentcve.org/ACVE-2026-0004</link><guid isPermaLink="false">ACVE-2026-0004@2026-09-20T02:45:17.577Z</guid><pubDate>2026-09-20T02:45:17.577Z</pubDate><description>Claude Code deny rules can be bypassed through symlinked tools</description></item><item><title>ACVE-2026-0003 — Claude Code project permissions can select an unsafe permission mode</title><link>https://agentcve.org/ACVE-2026-0003</link><guid isPermaLink="false">ACVE-2026-0003@2026-09-20T02:45:17.577Z</guid><pubDate>2026-09-20T02:45:17.577Z</pubDate><description>Claude Code project permissions can select an unsafe permission mode</description></item><item><title>ACVE-2026-0002 — Claude Code sandbox settings can permit a sandbox escape</title><link>https://agentcve.org/ACVE-2026-0002</link><guid isPermaLink="false">ACVE-2026-0002@2026-09-20T02:45:17.577Z</guid><pubDate>2026-09-20T02:45:17.577Z</pubDate><description>Claude Code sandbox settings can permit a sandbox escape</description></item><item><title>ACVE-2025-0008 — Cursor can trust a mutable project MCP configuration</title><link>https://agentcve.org/ACVE-2025-0008</link><guid isPermaLink="false">ACVE-2025-0008@2026-09-20T02:45:17.577Z</guid><pubDate>2026-09-20T02:45:17.577Z</pubDate><description>Cursor can trust a mutable project MCP configuration</description></item><item><title>ACVE-2025-0007 — Codex CLI can auto-load project configuration</title><link>https://agentcve.org/ACVE-2025-0007</link><guid isPermaLink="false">ACVE-2025-0007@2026-09-20T02:45:17.577Z</guid><pubDate>2026-09-20T02:45:17.577Z</pubDate><description>Codex CLI can auto-load project configuration</description></item><item><title>ACVE-2025-0004 — Claude Code can traverse paths through untrusted context</title><link>https://agentcve.org/ACVE-2025-0004</link><guid isPermaLink="false">ACVE-2025-0004@2026-09-20T02:45:17.577Z</guid><pubDate>2026-09-20T02:45:17.577Z</pubDate><description>Claude Code can traverse paths through untrusted context</description></item><item><title>ACVE-2025-0003 — MCP filesystem servers permit path traversal through symlink and calendar-version paths</title><link>https://agentcve.org/ACVE-2025-0003</link><guid isPermaLink="false">ACVE-2025-0003@2026-09-20T02:45:17.577Z</guid><pubDate>2026-09-20T02:45:17.577Z</pubDate><description>MCP filesystem servers permit path traversal through symlink and calendar-version paths</description></item><item><title>ACVE-2025-0002 — mcp-remote can inject operating-system commands through an untrusted URL</title><link>https://agentcve.org/ACVE-2025-0002</link><guid isPermaLink="false">ACVE-2025-0002@2026-09-20T02:45:17.577Z</guid><pubDate>2026-09-20T02:45:17.577Z</pubDate><description>mcp-remote can inject operating-system commands through an untrusted URL</description></item><item><title>ACVE-2025-0001 — MCP Inspector can bypass local authentication and rebind localhost</title><link>https://agentcve.org/ACVE-2025-0001</link><guid isPermaLink="false">ACVE-2025-0001@2026-09-20T02:45:17.577Z</guid><pubDate>2026-09-20T02:45:17.577Z</pubDate><description>MCP Inspector can bypass local authentication and rebind localhost</description></item><item><title>ACVE-2024-0001 — Ollama can traverse paths and reach code execution</title><link>https://agentcve.org/ACVE-2024-0001</link><guid isPermaLink="false">ACVE-2024-0001@2026-09-20T02:45:17.577Z</guid><pubDate>2026-09-20T02:45:17.577Z</pubDate><description>Ollama can traverse paths and reach code execution</description></item><item><title>ACVE-2026-0013 — Gemini CLI README injection can reach allowlisted tools</title><link>https://agentcve.org/ACVE-2026-0013</link><guid isPermaLink="false">ACVE-2026-0013@2026-09-19T00:00:00Z</guid><pubDate>2026-09-19T00:00:00Z</pubDate><description>Gemini CLI README injection can reach allowlisted tools</description></item><item><title>ACVE-2026-0012 — Claude Code project hooks run automatically inside the repository</title><link>https://agentcve.org/ACVE-2026-0012</link><guid isPermaLink="false">ACVE-2026-0012@2026-09-19T00:00:00Z</guid><pubDate>2026-09-19T00:00:00Z</pubDate><description>Claude Code project hooks run automatically inside the repository</description></item><item><title>ACVE-2026-0011 — Codex trusted root scope combined with never-approve execution</title><link>https://agentcve.org/ACVE-2026-0011</link><guid isPermaLink="false">ACVE-2026-0011@2026-09-19T00:00:00Z</guid><pubDate>2026-09-19T00:00:00Z</pubDate><description>Codex trusted root scope combined with never-approve execution</description></item><item><title>ACVE-2026-0010 — HTTP MCP servers and permissive modes form an over-privileged combination</title><link>https://agentcve.org/ACVE-2026-0010</link><guid isPermaLink="false">ACVE-2026-0010@2026-09-19T00:00:00Z</guid><pubDate>2026-09-19T00:00:00Z</pubDate><description>HTTP MCP servers and permissive modes form an over-privileged combination</description></item><item><title>ACVE-2026-0009 — Azure MCP Server package identity and release need grounding</title><link>https://agentcve.org/ACVE-2026-0009</link><guid isPermaLink="false">ACVE-2026-0009@2026-09-19T00:00:00Z</guid><pubDate>2026-09-19T00:00:00Z</pubDate><description>Azure MCP Server package identity and release need grounding</description></item><item><title>ACVE-2026-0008 — Gemini CLI yolo mode disables the tool approval boundary</title><link>https://agentcve.org/ACVE-2026-0008</link><guid isPermaLink="false">ACVE-2026-0008@2026-09-19T00:00:00Z</guid><pubDate>2026-09-19T00:00:00Z</pubDate><description>Gemini CLI yolo mode disables the tool approval boundary</description></item><item><title>ACVE-2026-0006 — Cursor can execute a repository git hook</title><link>https://agentcve.org/ACVE-2026-0006</link><guid isPermaLink="false">ACVE-2026-0006@2026-09-19T00:00:00Z</guid><pubDate>2026-09-19T00:00:00Z</pubDate><description>Cursor can execute a repository git hook</description></item><item><title>ACVE-2026-0005 — Cursor prompt injection can reach tools outside the intended sandbox</title><link>https://agentcve.org/ACVE-2026-0005</link><guid isPermaLink="false">ACVE-2026-0005@2026-09-19T00:00:00Z</guid><pubDate>2026-09-19T00:00:00Z</pubDate><description>Cursor prompt injection can reach tools outside the intended sandbox</description></item><item><title>ACVE-2026-0001 — Claude Code project settings can expose credentials through a custom base URL</title><link>https://agentcve.org/ACVE-2026-0001</link><guid isPermaLink="false">ACVE-2026-0001@2026-09-19T00:00:00Z</guid><pubDate>2026-09-19T00:00:00Z</pubDate><description>Claude Code project settings can expose credentials through a custom base URL</description></item><item><title>ACVE-2025-0011 — Claude Code IDE extension can bypass local authentication</title><link>https://agentcve.org/ACVE-2025-0011</link><guid isPermaLink="false">ACVE-2025-0011@2026-09-19T00:00:00Z</guid><pubDate>2026-09-19T00:00:00Z</pubDate><description>Claude Code IDE extension can bypass local authentication</description></item><item><title>ACVE-2025-0010 — VS Code Copilot Chat settings can auto-approve tools</title><link>https://agentcve.org/ACVE-2025-0010</link><guid isPermaLink="false">ACVE-2025-0010@2026-09-19T00:00:00Z</guid><pubDate>2026-09-19T00:00:00Z</pubDate><description>VS Code Copilot Chat settings can auto-approve tools</description></item><item><title>ACVE-2025-0009 — Cursor CurXecute can inject an MCP configuration</title><link>https://agentcve.org/ACVE-2025-0009</link><guid isPermaLink="false">ACVE-2025-0009@2026-09-19T00:00:00Z</guid><pubDate>2026-09-19T00:00:00Z</pubDate><description>Cursor CurXecute can inject an MCP configuration</description></item><item><title>ACVE-2025-0006 — Claude Code project hooks can inject configuration and commands</title><link>https://agentcve.org/ACVE-2025-0006</link><guid isPermaLink="false">ACVE-2025-0006@2026-09-19T00:00:00Z</guid><pubDate>2026-09-19T00:00:00Z</pubDate><description>Claude Code project hooks can inject configuration and commands</description></item><item><title>ACVE-2025-0005 — Claude Code can execute commands under permissive approval modes</title><link>https://agentcve.org/ACVE-2025-0005</link><guid isPermaLink="false">ACVE-2025-0005@2026-09-19T00:00:00Z</guid><pubDate>2026-09-19T00:00:00Z</pubDate><description>Claude Code can execute commands under permissive approval modes</description></item></channel></rss>
