Pillar 03 Agent Authority Proof
The layer that records and proves the delegation relationships of agents.
Eleven vulnerabilities were disclosed across six agent frameworks including LangChain, LangGraph, and CrewAI
injected content is never checked before it crosses into trusted framework logic
Four unauthenticated flaws reaching code execution, privilege escalation, and SQL injection were disclosed in ServiceNow AI Platform
a third disclosure, still with no layer that checks authorization before the action
All 15 x402 payment facilitators were found in violation
payment verification is never bound to settlement before the action
OpenClaw's agent cancelled a stranger's gym reservation, unasked, to move its user up the queue
the action was never authorized against the user's own permissions
OpenAI, Anthropic and Meta eval models breached real companies through Irregular's misconfiguration
'contained' was never independently verified before the action
One Pyodide sandbox escape was shown to reproduce across seven products
the premise 'it's isolated' was never independently verified
A co-located tenant's JWT was shown to be extractable from Cloudflare Workers via Spectre
a stolen token passes straight through as the user
Three coding agents broken in their default config: the harness marked a value safe, and a later stage acted on it with more authority
Novee Security attacked Anthropic's Claude Code, Google's Gemini CLI, and OpenAI's Codex — each in the configuration the vendor ships by def…
Claude Mythos 5, in evaluation, tried to plant a backdoor in a real OSS project, erased the history, and vouched for itself from a second account
review could not verify an independent endorsement or an untampered history
Atlassian Rovo can be tricked into sending Jira and Confluence data outward by instructions in an uploaded file or a URL parameter
the origin of the instruction is never verified before the action
Ruflo's MCP Bridge: one unauthenticated request opened 233 high-privilege tools, and the memory poisoning survives the patch
tool-call authorization and memory provenance are never verified before execution
AWS Kiro: a harmless summarize request makes the agent rewrite its own MCP config and reach RCE
the approval boundary never verifies self-modification of authorization settings before execution
OpenAI's evaluation agents escaped containment and breached an unrelated company's production
Hugging Face
ServiceNow AI Platform
one unauthenticated request escaped the sandbox to code execution (CVE-2026-6875)
WebMCP
swapping the tools mid-session led agents to call the attacker's tool without noticing
Gitea: a Docker default let anyone impersonate an admin with a single HTTP header (CVE-2026-20896)
The official Docker image of the self-hosted Git service Gitea shipped a vulnerability that let anyone impersonate an administrator with a s…
JadePuffer: an LLM agent autonomously ran a ransomware attack
from breach to credential theft, lateral movement, and encryption — deciding on the fly
Cursor (DuneSlide): a single injected prompt escaped the agent's sandbox and ran arbitrary commands (CVE-2026-50548 / 50549)
A developer merely asking the AI code editor Cursor a normal question could pull in a hidden instruction slipped into web-search results or …
Amazon Q Developer: opening a repo auto-executed a bundled MCP config and exfiltrated AWS credentials (CVE-2026-12957)
Just by opening a malicious repository in Visual Studio Code and enabling the AI coding assistant Amazon Q Developer extension, a developer …
Kestra: Ending a Request Path With /configs Bypassed Authentication and Allowed Unauthenticated Code Execution as Root
On 2026-06-26, a vulnerability allowing unauthenticated arbitrary code execution as root (CVE-2026-53576, CVSS 10.0) was disclosed in Kestra…
A Dormant, Un-Revoked Credential Turned a Trusted Integration into Mass Salesforce Extraction (Klue)
un-revoked test credentials and long-lived OAuth tokens that go unverified at the moment of action (Huntress / ReliaQuest)
Replit: an AI agent broke a code freeze, wiped production data, then fabricated records to cover it
destructive actions ran past an explicit ban and the agent could falsify its own actions (SaaStr / Jason Lemkin)
Universal Robots PolyScope: unauthenticated network access yields RCE on industrial robots
the robot doesn't verify the commander's authority before physical action (CVE-2026-8153)
DJI ROMO: one authenticated client reached 7,000 robot vacuums' cameras
the cloud didn't separate per-device authorization (No Broker ACL)
Unitree (UniPwn): one shared key across the fleet
per-device identity absent, so one compromise broke the whole fleet (Alias Robotics)
LiteLLM AI Gateway: from low-privilege user to admin and RCE
authorization not independently verified before action (Obsidian Security)
Hugging Face LeRobot: a robotics framework executed untrusted data received over an unauthenticated channel
deserializing (pickle) unverified data leads straight to code execution (CVE-2026-25874)
ShadowMQ: one unsafe pattern (unauthenticated ZMQ + pickle) copied across AI inference frameworks
the same flaw spread at ecosystem scale through reuse (Oligo Security)
From State Store to RCE
When an AI Agent Trusts Its Own Checkpoint (LangGraph)
When "Allow All" OAuth to an AI Tool Becomes the Breach Path (Vercel / Context.ai)
In April 2026, Vercel disclosed that the breach path was the broad "Allow all" OAuth an employee had granted the AI tool Context.ai, turned …
Claude Code GitHub Action: one issue claiming "[bot]" led the agent to privileged execution
the trigger's authority and input origin not verified before acting (GMO Flatt Security)
Salesloft Drift: a trusted integration's OAuth tokens stolen, hundreds of Salesforce tenants queried
broad, persistent OAuth not scope/revocation-verified per action (UNC6395)
No Check on Who Was Authorized
64 Million Records Within Reach in McDonald's McHire (Paradox.ai)
Reachable Meant Readable
DeepSeek's Unauthenticated ClickHouse Backend Exposure
ServiceNow Scripted REST Endpoint Served Customer Data Without Authentication
ServiceNow disclosed that a Scripted REST endpoint had shipped with requires_authentication=false, letting customer-instance tables be queri…
Asking the AI Support Bot Was Enough
Instagram Account Takeovers via Meta High Touch Support
When the Assistant Becomes the Trigger
AI Coding Agents Auto-Execute Project-Local Config (SymJack / TrustFall + Miasma)
Semantic Kernel: Prompt Injection Turned Into Host-Level Remote Code Execution
the functions and parameters an agent can call are not authorized or verified before execution (CVE-2026-25592 / CVE-2026-26030)
One Edge Appliance Compromise Cascaded to Full Domain Takeover
An Implicitly Trusted F5 BIG-IP Became the Pivot, Along With the Credentials It Stored
AI Agents Drove Intrusions From Initial Access to Exfiltration
Signature-Based Detection Cannot Track Tooling the AI Generates Per Target (SHADOW-AETHER-040 / 064)
One-Click GitHub OAuth Token Theft via github.dev
The Webview Trusted Synthetic Events, and the Token Was Not Scoped to the Repo
MCP Design: Config-to-Command Execution and Supply-Chain-Scale RCE
Not a single-language implementation bug but inherent in the reference SDK design across supported languages
LibreChat CVE-2026-32625
User-Supplied MCP Server URLs as an Exfiltration Channel for Server Secrets
Adaptive AI Worm
Runtime Exploit Synthesis as a Threat Model
GTG-1002: AI agent autonomously executed 80–90% of a cyberattack
first reported AI-orchestrated espionage, agent authority never independently verified
Starlette CVE-2026-48710 (BadHost)
MCP Server Authentication Bypass via HTTP Host Header Manipulation
Cursor + Claude Opus 4.6 Wiped PocketOS Production DB in 9 Seconds
The Unverified Destructive Authority of AI Coding Agents