Observed arrival · 2026-09-21
ACVE, a vulnerability registry for AI-agent configurations
Credibility concern recorded. The source reference remains available for verification and correction.
A public registry cataloguing vulnerable combinations of AI-agent harnesses, models, tools, permissions, and versions.
- For
- AI-agent developers and security reviewers
- Worth noticing
- Its index separates code, behavioural, and artifact findings, while 67 of 80 entries are marked unverified.
Field notes
The index divides findings into code, behavioural, and artifact categories and exposes status labels such as reviewed, unverified, withdrawn, demonstrated, and exploited. It also tracks affected harnesses and reports 25 entries marked as occurring in the wild, including examples involving repository hooks, MCP configurations, approval modes, and sandbox boundaries. The homepage does not establish independent verification; 67 of the 80 listed advisories are marked unverified.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
One card from the complete issue