Security has always kept ledgers: CVEs, breach disclosures, kill chains. For agentic AI there has been, until very recently, no equivalent. Incidents were reported as one-off “prompt injection” stories, then forgotten, because each one looked like a research demo rather than a category.
It is a category now. What follows is a running record of documented incidents where an AI agent, whether a coding assistant, a computer-use agent or a review bot, acted on instructions it should have treated as data, and produced a real effect: stolen credentials, exfiltrated data, deleted production state. Each row carries a source. Where the source is a community-curated case study rather than a CVE or a vendor disclosure, that is stated.
The ledger
| Incident | When | What actually happened | Severity | Source |
|---|---|---|---|---|
| EchoLeak (CVE-2025-32711) | 2025 | A single crafted email to Microsoft 365 Copilot triggered zero-click, unauthenticated exfiltration of mailbox data, with no user interaction | rated 9.3 | arXiv:2509.10540 |
| CamoLeak (CVE-2025-59145) | 2025 | Prompt injection in repository content made GitHub Copilot Chat exfiltrate source code, API keys and cloud secrets through GitHub’s own Camo image proxy | CVSS 9.6 | CSA note |
| Notion AI PDF injection | Sep 2025 | Malicious PDFs with hidden instructions steered Notion’s AI to collect workspace text and send it to an attacker-controlled endpoint | patched; no public CVE | PromptArmor |
| OpenAI Codex command injection | late 2025 | A GitHub branch name was passed unsanitized into shell commands during task setup, leaking the user’s GitHub access token | patched (CWE-78) | BeyondTrust |
| Comment and Control | Apr 2026 | PR titles, issue bodies and hidden HTML comments made three vendors’ review agents post their own CI secrets back through GitHub | CVSS 9.4; no CVE issued | CSA note |
| Semantic Kernel RCE | May 2026 | Prompt injection reached an eval() call and an exposed file-write function in Microsoft’s agent SDK, giving host code execution |
CVE-2026-26030 (9.8), CVE-2026-25592 (10.0) | Microsoft |
| Cursor git-hook RCE | Jun 2026 | Cursor executed hook commands from .claude/settings.local.json inside untrusted workspace content, without dedicated approval |
CVE-2026-48124 (8.5) | NVD / Cursor advisory |
| Cline npm-token theft | 2026 | Prompt injection on Cline’s issue-triage bot stole npm tokens and published a malicious package | ~4,000 developers, ~8 hours | awesome-agent-failures (community) |
| Amazon Q extension injection | 2026 | An injected prompt inside the official AWS extension ordered Amazon Q to delete filesystems and wipe S3 buckets | ~1M installs at risk; a syntax error stopped it | awesome-agent-failures (community) |
| MCP STDIO RCE “by design” | 2026 | A malicious MCP command runs even when the server returns an error, and it is reachable across thousands of exposed servers; Anthropic called it expected behavior | 7,000+ exposed servers | awesome-agent-failures (community) |
| Clawdbot / OpenClaw exposure | 2026 | Unauthenticated dashboards, one-click RCE and an exposed agent social network | found in 22% of enterprises | awesome-agent-failures (community) |
| Destruction cluster | 2025–26 | Production database wipes (PocketOS, Replit), a 28,745-line code purge, an 11-day $47,000 agent loop, retail outages | case studies | awesome-agent-failures (community) |
What the ledger actually says
Three things, once the rows are laid side by side.
The injection surface is the same surface people already use. PR titles, issue bodies, branch names, calendar invites, PDFs, MCP tool descriptions. None of it is exotic. Attackers don’t need a new technique; they need the agent to treat collaboration content as instruction.
The exfiltration channel is usually the platform’s own. CamoLeak went through GitHub’s image proxy. Comment and Control posted secrets as review comments. The attackers repeatedly didn’t need an external listener, which is why network egress controls, the tool most teams reach for first, don’t catch them.
The vendors are paying bounties and staying quiet. In the Comment and Control cluster, three of the largest AI providers paid $100, $1,337 and $500 and issued no CVE, no advisory, no user notice. The ledger above exists in part because the usual disclosure machinery did not.
The line that separates the rows
Every row is an agent acting on authority it should not have had at that moment. A detector that reads transcripts afterwards would have recorded most of them, after the token was already in the comment, after the email was already gone. The question the ledger poses is not “can we detect more of these,” but “can the action be decided before it happens, against an authority the session actually holds.” That is the question the rest of this journal keeps returning to.
Sources accessed 2026-09-20. Rows marked “community” are case studies curated in the awesome-agent-failures list and are secondary reports, not vendor disclosures or CVEs. CVE and CVSS figures are taken from the linked vendor advisories, NVD or the papers cited; where a number is contested between sources, the vendor’s own disclosure wins.