⚠ VYR Advisory Database — 10 active advisories

MCP & AI Agent
Threat Intelligence

CVE-style advisories for MCP server attacks, agent hijacking, credential exfiltration, and AI supply chain threats. Updated from real-world scan telemetry.

VYR-2026-001 Critical CVSS 9.1 MCP Tool Poisoning
MCP Tool Description Instruction Hijack
Published: 2026-01-15 Updated: 2026-05-01
Malicious MCP server encodes imperative instructions inside tool description fields. When an LLM reads the tools/list, the instructions execute as if issued by the operator, enabling data exfiltration or lateral movement.

Indicators of Compromise

VYR-2026-002 High CVSS 8.2 Supply Chain
npm MCP Package Typosquatting Attack
Published: 2026-02-03 Updated: 2026-04-20
Attackers register npm packages with names 1–2 characters different from canonical MCP packages (e.g., @modelcontextprot0col/server-filesystem). The package installs a backdoor that exfiltrates tool call arguments.

Indicators of Compromise

VYR-2026-003 High CVSS 7.8 Prompt Injection
Indirect Prompt Injection via Retrieved Documents
Published: 2026-01-28 Updated: 2026-05-10
Content retrieved from external sources (web search, RAG, email) contains embedded instructions that the LLM executes when processing the retrieved context, bypassing system-prompt restrictions.

Indicators of Compromise

VYR-2026-004 High CVSS 7.5 Memory Manipulation
AI Agent Memory Poisoning via Tool Results
Published: 2026-03-11 Updated: 2026-05-13
A compromised tool returns results containing instructions to modify the agent's stored memory or context, causing the agent to misclassify future requests or grant unauthorized permissions.

Indicators of Compromise

VYR-2026-005 Critical CVSS 9.8 Malware Generation
LLM-Generated Reverse Shell via Code Execution Tool
Published: 2026-02-20 Updated: 2026-05-14
The LLM is manipulated (via prompt injection or jailbreak) into generating a reverse shell payload that is then executed through an attached code-execution tool, giving the attacker persistent shell access.

Indicators of Compromise

VYR-2026-006 Critical CVSS 9.3 Data Exfiltration
Autonomous Agent Credential Exfiltration
Published: 2026-03-05 Updated: 2026-05-14
An autonomous agent tasked with file or environment access is manipulated into reading credential files (AWS credentials, .env, SSH keys) and exfiltrating them via an outbound HTTP call disguised as a legitimate API request.

Indicators of Compromise

VYR-2026-007 High CVSS 8.0 AI-to-AI Attack
Multi-Agent Chain Prompt Injection
Published: 2026-04-02 Updated: 2026-05-13
In a multi-agent pipeline, a compromised downstream agent returns a response that contains injected instructions targeted at the upstream orchestrator, causing the orchestrator to take unauthorized actions.

Indicators of Compromise

VYR-2026-008 High CVSS 7.6 Social Engineering
AI-Generated Spear Phishing via Email Agent
Published: 2026-04-18 Updated: 2026-05-10
An AI agent with email-send capability is manipulated via prompt injection to compose and send highly personalized spear-phishing emails to contacts in the user's address book, impersonating the user.

Indicators of Compromise

VYR-2026-009 High CVSS 8.4 Agent Hijacking
MCP Server Process Sandbox Escape
Published: 2026-04-25 Updated: 2026-05-14
A malicious MCP server uses tool calls to probe for sandbox misconfiguration, then exploits filesystem or network access that should be restricted, escaping the intended execution boundary.

Indicators of Compromise

VYR-2026-010 High CVSS 7.9 Supply Chain
Synthetic Maintainer Identity Package Takeover
Published: 2026-05-01 Updated: 2026-05-14
Attackers use AI-generated identities (synthetic GitHub profiles, bulk-registered npm accounts) to register look-alike packages or take over abandoned packages with expired maintainer emails.

Indicators of Compromise

No advisories match your search.

Monitor your MCP servers continuously

The scanner tells you what's wrong. VyriAI runtime monitoring tells you the moment something changes — drift, new tool poisoning, publisher changes.

Free scan now Start monitoring →