Skip to the card

Card 010 of 9932026-09-21 issue

Observed arrival · 2026-09-21

ACVE, a vulnerability registry for AI-agent configurations

agentcve.org Visit website
Editorial interest 78/100 Selection signal · not a rating of the site

Credibility concern recorded. The source reference remains available for verification and correction.

A public registry cataloguing vulnerable combinations of AI-agent harnesses, models, tools, permissions, and versions.

Landing page captured for the 2026-09-21 issue.
For
AI-agent developers and security reviewers
Worth noticing
Its index separates code, behavioural, and artifact findings, while 67 of 80 entries are marked unverified.

Field notes

The index divides findings into code, behavioural, and artifact categories and exposes status labels such as reviewed, unverified, withdrawn, demonstrated, and exploited. It also tracks affected harnesses and reports 25 entries marked as occurring in the wild, including examples involving repository hooks, MCP configurations, approval modes, and sandbox boundaries. The homepage does not establish independent verification; 67 of the 80 listed advisories are marked unverified.

Observed signals

Read the marks

Editorial observations of this landing page, not a rating.

OpenPublic substance visible
PrettyNotable craft visible
ProPolished or operationally mature
NicheUnusually specific use
RiskCredibility concern recorded

One card from the complete issue

A Passport-Sized Place to Begin

246,713 arrived 999 judged 993 catalogued Enter the complete issue
agentcve.org

Landing page observed 2026-09-21. The live site may have changed.