A widely installed documentation MCP server carried a prompt injection into connected coding agents
CVE-2026-75130, published on 18 August 2026, records that Context7 through version 2.1.2 contains a prompt injection that allows attackers to execute malicious instructions in connected AI coding agents by injecting unsanitised content through its custom instructions feature, served by its MCP server. The record carries a critical score under one scoring version.
The verdict
Verified
The document exists. The ledger fetched it at its publisher and quotes it.
Key facts
What the sources say
- Record ID
- AIL-2026-0025
- Kind
- Injection
- Jurisdiction
- Global
- Last verified
- Added
- The CVE record states that the product contains a prompt injection allowing attackers to execute malicious instructions in connected AI coding agents.
- The injection arrives through unsanitised content in the custom instructions feature served by the MCP server.
- Affected versions are everything through 2.1.2 according to the CVE record.
- The record carries two scores from different versions of the scoring system, which is why published severities for it differ.
- The record was assigned by a vulnerability numbering authority rather than by the product's own vendor.
Dimension by dimension
5 dimensions, each one stated, silent or open
Identity, Authorization, Limits, Accountability, Revocation. Stated means the document you can open below says it; silent means the ledger read the document and it does not.
- IdentitySilent
- Content served by a documentation tool reached the agent with the standing of an instruction.CVE Program record, CVE-2026-75130, primary source, 18 August 2026.
- AuthorizationSilent
- The record states the injected instructions execute in connected coding agents, which hold the developer's own reach.CVE Program record, CVE-2026-75130, primary source, 18 August 2026.
- LimitsSilent
- The record describes unsanitised content, so no filtering bounded what could arrive.CVE Program record, CVE-2026-75130, primary source, 18 August 2026.
- AccountabilityStated
- A public CVE record exists with an assigning authority, an affected range and published scores.CVE Program record, CVE-2026-75130, primary source, 18 August 2026.
- RevocationOpen
- The record names an affected range and the public documentation of a fixed release was not established here.CVE Program record, CVE-2026-75130, primary source, 18 August 2026.
Figures
Every number, with who measured it and when
- 9 CVSS base score
CVSS version 3.1 base score on the CVE record
CVE Program record, CVE-2026-75130, primary source, as of .
- 6.4 CVSS base score
CVSS version 4.0 base score on the same CVE record
CVE Program record, CVE-2026-75130, primary source, as of .
What it changes
For a team deploying an agent
A documentation server looks like the safest thing you can connect to a coding agent, and it is an instruction channel. Keep an inventory of every MCP server your developers run, with its version and who publishes it, and subscribe to CVE feeds for each one. Treat everything a server returns as untrusted content, and never let a documentation tool's output reach an agent that can write code unreviewed.
Sources
What this record was verified against
- CVE Program record, CVE-2026-75130Primary · 18 August 2026
Related
Records that sit beside this one
A coding assistant carried a prompt injection that let a remote attacker run commands on the user's machine
Global · verified 15 September 2026
The CVE record states that a prompt injection vulnerability in the named version allows remote attackers to execute arbitrary commands on a victim system.
A cloned MCP server silently copied every email agents sent through it
Global · verified 15 September 2026
The Register reports that a backdoored version added a blind copy of every message to an attacker controlled address.
Has a confirmation prompt ever been documented stopping a destructive agent action in a real incident?
Global · verified 15 September 2026
Every incident record in this dataset that involves a destructive or irreversible action records human approval as absent, bypassed or uninformed.
Does any published standard require an agent to hold an identity distinct from the person it acts for?
Global · verified 15 September 2026
The Model Context Protocol authorization specification states that clients must implement resource indicators for OAuth so that a token names the resource it is for.
Does any registry classify AI incidents by the authority control that failed, and does anyone count agent incidents?
Global · verified 15 September 2026
The AI Incident Database describes itself as indexing the collective history of harms or near harms realised in the real world by deployed AI systems.
Who is liable when an agent commits its principal to something false or binding?
Global · verified 15 September 2026
The Canadian tribunal decision is a small claims level decision and is not binding precedent on other courts.
Cite this record
Free to reuse under CC BY 4.0, with attribution. The record ID AIL-2026-0025 is permanent and is never reused.
- In a sentence
- According to the GAGE Agent Incident Ledger (as of 15 September 2026), a widely installed documentation mcp server carried a prompt injection into connected coding agents.
- APA
- GAGE (Global Academy of Generative-AI Education). (2026). A widely installed documentation MCP server carried a prompt injection into connected coding agents. Agent Incident Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0025-context7-mcp-documentation-server-prompt-injection-cve
- MLA
- "A widely installed documentation MCP server carried a prompt injection into connected coding agents." Agent Incident Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0025-context7-mcp-documentation-server-prompt-injection-cve.
- Chicago
- GAGE (Global Academy of Generative-AI Education). "A widely installed documentation MCP server carried a prompt injection into connected coding agents." Agent Incident Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0025-context7-mcp-documentation-server-prompt-injection-cve.
- Permalink
- https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0025-context7-mcp-documentation-server-prompt-injection-cve
Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any vendor disclosure.
Back to the full ledger, or every record for Global and every injection record.
GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.