Injection
Where did instructions arrive through content?
10 records of kind injection are on the Agent Incident Ledger as of September 2026: 10 verified, 0 reported, 0 announced, 0 absent, 0 open. By jurisdiction: United States 8, Global 2.
Injection
10 records, newest first
A coding assistant carried a prompt injection that let a remote attacker run commands on the user's machine
Global · verified 15 September 2026
The CVE record states that a prompt injection vulnerability in the named version allows remote attackers to execute arbitrary commands on a victim system.
A widely installed documentation MCP server carried a prompt injection into connected coding agents
Global · verified 15 September 2026
The CVE record states that the product contains a prompt injection allowing attackers to execute malicious instructions in connected AI coding agents.
A browser agent read the local file system and shipped it out while still answering the user normally
United States · verified 15 September 2026
The research states the agent autonomously accesses the local file system and exfiltrates the contents to an attacker controlled endpoint while still returning the expected response.
A stranger's issue steered a continuous integration agent into reading the environment that held its own API key
United States · verified 15 September 2026
The research states that the returned environment blob contains the unscrubbed API key.
ShareLeak, where a public form field overrode an enterprise agent's instructions and mailed out customer records
United States · verified 15 September 2026
The research states that the compromised agent accesses connected lists and sends sensitive customer data to an attacker controlled email address.
A summarise request made the Comet browser agent read a one time code from the user's mailbox and post it publicly
United States · verified 15 September 2026
Brave states that traditional browser protections such as the same origin policy and cross origin resource sharing are effectively useless against this class.
ForcedLeak, a lead form that turned a CRM agent into an exfiltration path through an expired allowlisted domain
United States · verified 15 September 2026
Noma Security states that an allowlisted domain had expired and become available for purchase, and that the researchers bought it.
A support ticket steered a developer's assistant into reading a database through the Supabase MCP server
United States · verified 15 September 2026
General Analysis states that the editor assistant ingests untrusted customer text while holding service role privileges.
A public issue steered an agent through the GitHub MCP server into publishing private repository data
United States · verified 15 September 2026
Invariant Labs states that an attacker can create a malicious issue on a public repository containing a prompt injection.
Amazon Q Developer for VS Code shipped carrying an injected prompt to wipe the machine
United States · verified 15 September 2026
AWS security bulletin AWS-2025-015 states the malicious code was distributed with the extension but was unsuccessful in executing due to a syntax error.
Every surface
Cut the ledger another way
By kind
By jurisdiction
Cite this page
Free to reuse under CC BY 4.0, with attribution.
- In a sentence
- According to the GAGE Agent Incident Ledger (as of 15 September 2026), injection: agent incident ledger.
- APA
- GAGE (Global Academy of Generative-AI Education). (2026). Injection: Agent Incident Ledger. Agent Incident Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/agent-incident-ledger/kinds/injection
- MLA
- "Injection: Agent Incident Ledger." Agent Incident Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/agent-incident-ledger/kinds/injection.
- Chicago
- GAGE (Global Academy of Generative-AI Education). "Injection: Agent Incident Ledger." Agent Incident Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/agent-incident-ledger/kinds/injection.
- Permalink
- https://www.gage.academy/tools/agent-incident-ledger/kinds/injection
Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any vendor disclosure.
Back to the full ledger and every injection record.
GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.