← Real-world cases

ServiceNow AI Platform pre-auth sandbox-escape RCE (CVE-2026-6875)

Disclosed vulnerability13 Jul 2026

Distinct from the library's ServiceNow Now Assist agent-discovery case (second-order agent-to-agent injection): this is a formally-tracked, reportedly actively-exploited pre-auth RCE in mainstream enterprise SaaS AI, showing that unsafe dynamic evaluation of attacker text as code turns an AI product into a high-value RCE target. CVSS, dates and exploitation are per the advisory and reporting.

Practise the risk class — related scenarios

Interactive simulations of the risk class this case illustrates (not a re-enactment of this specific event).

🪄The Approval That Lied

A coding agent asks to write ./notes.txt — the file it actually overwrites is your SSH keys

📧The Email That Gave Orders

A support email hides instructions — and the assistant obeys them

🗄️When the Query Bites Back

A text-to-SQL agent runs the model's output straight at the database

👂Overheard Through the Cache

A speed optimisation becomes a cross-tenant listening device

🏭Poisoning the Agent Factory

Compromise the pipeline that builds agents, and every new worker is born malicious

🪟Stealing the Model

Two doors to the same secret: reconstruct the model through its API, or just walk off with the weight file

🧩Summarise This, Run That

An auto-approving coding agent reads a poisoned page — and executes code it never should have

🪤The Bug Report That Ran Code

A fake Sentry error report hijacks a developer's coding agent into running a shell command

🔗The Chain of Innocent Commands

Every command is harmless on its own — the sequence is the exploit

📼The Compromised Flight Recorder

The forensic record is itself the attack surface — an agent's log is poisoned, then quietly rewritten

📦The Dataset That Ran Code

A 'safe' dataset preview turns an upload into code execution on the pipeline's workers

🔓The Model That Forgot to Say No

A cost-saving open-weights swap quietly ships a model with its safety surgically removed

🖼️The Picture That Whispered

A screenshot that's harmless at full size becomes an order once the system shrinks it

💤The Sleeper

A capable third-party model that behaves perfectly — until it sees the trigger

🎫The Stolen Session

An attacker captures the agent's bearer token — and inherits its authority

🔌The Tool With a Hidden Agenda

A trusted MCP email tool quietly BCCs every message to an attacker

🥸The Uninvited Agent

A forged peer registers on the agent directory — and the planner enlists it

🖼️Zero-Click Leak by Picture

An inbox summary quietly ships a secret to an attacker's server

More cases on Unsafe Tool / Code Execution

Replit AI agent deletes a production databaseGTG-1002 — first reported AI-orchestrated cyber-espionage campaign (Claude Code)IDEsaster — AI coding IDEs/agents turned into exfiltration & RCE surfacesGitHub Copilot / VS Code RCE via prompt injection ('YOLO mode', CVE-2025-53773)Model Namespace Reuse (Hugging Face name-trust hijack)Amazon Q Developer 'wiper' prompt shipped via poisoned pull request (CVE-2025-8217)NVIDIA Triton Inference Server unauthenticated RCE chain (CVE-2025-23319 / -23320 / -23334)TeamPCP poisons the LiteLLM AI gateway on PyPI to harvest LLM API keysAgentjacking — hijacking AI coding agents via Sentry error reports (Tenet Security)LeRobot async-inference gRPC pickle RCE (CVE-2026-25874)Flowise AI agent builder CustomMCP RCE (CVE-2025-59528)Project Glasswing — Claude 'Mythos' autonomously finds 10,000+ software vulnerabilitiesAI-assisted breach of Mexican government infrastructure (Claude Code + GPT-4.1)Hugging Face agentic production intrusion via a poisoned dataset (July 2026)LiteLLM MCP test-endpoint command injection chained to unauthenticated RCE (CVE-2026-42271)Amazon Q Developer auto-loads workspace MCP configs, enabling zero-click AWS credential theft (CVE-2026-12957)Cursor 'DuneSlide' — indirect prompt injection escapes the IDE sandbox to zero-click RCE (CVE-2026-50548 / CVE-2026-50549)Hermes AI agent run unattended ('YOLO' mode) to automate post-exploitation at Thailand's Ministry of FinanceJADEPUFFER — first documented end-to-end autonomous agentic ransomware operation (Sysdig)Agentic botnets via universal, transferable adversarial HalluSquattingGhostApproval — symlink following + approval-UI misrepresentation defeats human-in-the-loop in six AI coding assistants (CVE-2026-12958 / CVE-2026-50549)MOSAIC: CLI command-composition attacks on LLM coding agentsAgent Data Injection: malicious trusted-data bypasses prompt-injection defensesClaude Code Opus 5 Auto Mode hijacked to RCE via indirect prompt injectionAWS Kiro agentic IDE rewrites its own MCP config for zero-click RCE (CVE-2026-10591)Frontier models escape air-gapped eval harnesses (incl. Claude PyPI malware)CISA/NSA/FBI warn of AI-generated exploit scripts targeting Siemens S7 PLCs (AA26-231A)The Week of Sandbox Escapes: AI coding-agent sandbox bypasses (CVE-2026-48124 and more)keyv/cacheable npm worm plants Claude Code and VS Code hook files as an AI-agent execution vectorLangflow unauthenticated code-injection RCE added to CISA KEV (CVE-2026-9198)

AI RiskAtlas is an educational model of how GenAI & agentic systems work and fail. Architectures and payloads are illustrative and simplified for learning — not operational guidance. Real-world cases are summarised from public reporting.

Sources & further reading →·Built by Shi Yuan ↗