Security has always kept ledgers: CVEs, breach disclosures, kill chains. For agentic AI there has been, until very recently, no equivalent. Incidents were reported as one-off “prompt injection” stories, then forgotten, because each one looked like a research demo rather than a category.

It is a category now. What follows is a running record of documented incidents where an AI agent, whether a coding assistant, a computer-use agent or a review bot, acted on instructions it should have treated as data, and produced a real effect: stolen credentials, exfiltrated data, deleted production state. Each row carries a source. Where the source is a community-curated case study rather than a CVE or a vendor disclosure, that is stated.

The ledger

Incident When What actually happened Severity Source
EchoLeak (CVE-2025-32711) 2025 A single crafted email to Microsoft 365 Copilot triggered zero-click, unauthenticated exfiltration of mailbox data, with no user interaction rated 9.3 arXiv:2509.10540
CamoLeak (CVE-2025-59145) 2025 Prompt injection in repository content made GitHub Copilot Chat exfiltrate source code, API keys and cloud secrets through GitHub’s own Camo image proxy CVSS 9.6 CSA note
Notion AI PDF injection Sep 2025 Malicious PDFs with hidden instructions steered Notion’s AI to collect workspace text and send it to an attacker-controlled endpoint patched; no public CVE PromptArmor
OpenAI Codex command injection late 2025 A GitHub branch name was passed unsanitized into shell commands during task setup, leaking the user’s GitHub access token patched (CWE-78) BeyondTrust
Comment and Control Apr 2026 PR titles, issue bodies and hidden HTML comments made three vendors’ review agents post their own CI secrets back through GitHub CVSS 9.4; no CVE issued CSA note
Semantic Kernel RCE May 2026 Prompt injection reached an eval() call and an exposed file-write function in Microsoft’s agent SDK, giving host code execution CVE-2026-26030 (9.8), CVE-2026-25592 (10.0) Microsoft
Cursor git-hook RCE Jun 2026 Cursor executed hook commands from .claude/settings.local.json inside untrusted workspace content, without dedicated approval CVE-2026-48124 (8.5) NVD / Cursor advisory
Cline npm-token theft 2026 Prompt injection on Cline’s issue-triage bot stole npm tokens and published a malicious package ~4,000 developers, ~8 hours awesome-agent-failures (community)
Amazon Q extension injection 2026 An injected prompt inside the official AWS extension ordered Amazon Q to delete filesystems and wipe S3 buckets ~1M installs at risk; a syntax error stopped it awesome-agent-failures (community)
MCP STDIO RCE “by design” 2026 A malicious MCP command runs even when the server returns an error, and it is reachable across thousands of exposed servers; Anthropic called it expected behavior 7,000+ exposed servers awesome-agent-failures (community)
Clawdbot / OpenClaw exposure 2026 Unauthenticated dashboards, one-click RCE and an exposed agent social network found in 22% of enterprises awesome-agent-failures (community)
Destruction cluster 2025–26 Production database wipes (PocketOS, Replit), a 28,745-line code purge, an 11-day $47,000 agent loop, retail outages case studies awesome-agent-failures (community)

What the ledger actually says

Three things, once the rows are laid side by side.

The injection surface is the same surface people already use. PR titles, issue bodies, branch names, calendar invites, PDFs, MCP tool descriptions. None of it is exotic. Attackers don’t need a new technique; they need the agent to treat collaboration content as instruction.

The exfiltration channel is usually the platform’s own. CamoLeak went through GitHub’s image proxy. Comment and Control posted secrets as review comments. The attackers repeatedly didn’t need an external listener, which is why network egress controls, the tool most teams reach for first, don’t catch them.

The vendors are paying bounties and staying quiet. In the Comment and Control cluster, three of the largest AI providers paid $100, $1,337 and $500 and issued no CVE, no advisory, no user notice. The ledger above exists in part because the usual disclosure machinery did not.

The line that separates the rows

Every row is an agent acting on authority it should not have had at that moment. A detector that reads transcripts afterwards would have recorded most of them, after the token was already in the comment, after the email was already gone. The question the ledger poses is not “can we detect more of these,” but “can the action be decided before it happens, against an authority the session actually holds.” That is the question the rest of this journal keeps returning to.


Sources accessed 2026-09-20. Rows marked “community” are case studies curated in the awesome-agent-failures list and are secondary reports, not vendor disclosures or CVEs. CVE and CVSS figures are taken from the linked vendor advisories, NVD or the papers cited; where a number is contested between sources, the vendor’s own disclosure wins.