Detection Dashboard
Run a comprehensive security scan of your browser environment
Attribution Tracer
Identify the source and nature of your connection
MCP CVE Database
Known vulnerabilities in the MCP ecosystem with digital drone relevance
18 vulnerabilities cataloged
| CVE ID | Severity | Component | Description | Status | Digital Drone Relevance |
|---|---|---|---|---|---|
| CVE-2025-54135 | 9.8 | Cursor IDE (CurXecute) | CurXecute (CVSS 9.8) — indirect prompt injection writes malicious MCP config files (.cursor/mcp.json) without user approval, hijacking agent context and triggering RCE. Fixed in Cursor v1.3.9. | Patched | Execution manipulation means attacker rewrites what the IDE drone does — from safe tasks to arbitrary system commands. |
| OPENCLAW-2026 | 9.8 | OpenClaw Platform | 135,000+ agent instances publicly exposed with 63% running zero authentication — the largest known mass-exposure event in AI agent infrastructure. | Active crisis | Mass drone army — 135K agents simultaneously controllable by any attacker on the internet with no authentication barrier. |
| CVE-2025-6514 | 9.6 | mcp-remote | OS command injection via crafted authorization_endpoint URL in widely-used MCP proxy (437K+ downloads). Fixed in v0.1.16. | Patched | Compromised MCP proxy redirects all agent tool calls to attacker-controlled servers, turning every downstream agent into a drone. |
| CVE-2025-49596 | 9.4 | MCP Inspector | Missing authentication between Inspector client and proxy allows unauthenticated attackers to launch arbitrary MCP commands over stdio. Fixed in v0.14.1. | Patched — exposure persists | Turns the debugging tool into an unauthenticated C2 channel — any agent connected to an exposed Inspector is directly controllable. |
| CVE-2025-32711 | 9.3 | Microsoft 365 Copilot | EchoLeak — Zero-click AI command injection (CWE-77) enabling unauthenticated network information disclosure from enterprise M365 environments. | Patched | Zero-click exfiltration from enterprise tools — compromised agents silently exfiltrate data with no user interaction required. |
| CVE-2025-65720 | 9.0 | GPT Researcher / MCP Ecosystem | Attacker-crafted HTML page triggers arbitrary command execution via the AI agent runtime — one of several concurrent by-design RCE patterns across 150M+ MCP downloads. | Ongoing — design-level fix needed | Architecture-level flaw means ALL MCP agents are potentially weaponizable as digital drones via a single malicious HTML page. |
| CVE-2026-16806 | 8.8 | Chrome WebMCP | Use-After-Free in Chrome WebMCP component allows remote code execution via crafted HTML. Affected versions prior to Chrome 150.0.7871.186. | Patched | DIRECT WebMCP exploit — crafted page achieves RCE inside the browser hosting the WebMCP agent context. |
| CVE-2026-3918 | 8.8 | Chrome WebMCP | Use-After-Free in Chrome WebMCP (prior to v146.0.7680.71) enables heap corruption and potential arbitrary code execution via crafted HTML page. | Patched | Heap corruption in the WebMCP runtime can redirect agent tool registration to attacker-controlled handlers. |
| CVE-2026-3913 | 8.8 | Chrome WebML | Heap buffer overflow in Chrome WebML component (< v146.0.7680.71) exploitable via crafted HTML — allows remote attackers to achieve heap corruption and code execution. | Patched | WebML powers on-device AI inference in the browser; a heap overflow here compromises the agent's own model execution context. |
| MSTI-2026 | 8.5 | WebMCP Spec | Mid-Session Tool Injection (arXiv:2606.06387) — third-party scripts exploit AbortSignal race conditions or timing attacks to hijack or frame registered tools mid-session. | Research disclosure | DIRECT WebMCP attack — third-party scripts silently redirect agent browser actions mid-session without leaving a detectable trace. |
| CVE-2025-54136 | 8.0 | Cursor IDE (MCPoison) | MCPoison — attacker with write access to a shared repo swaps a trusted MCP server for a malicious command in .cursor/mcp.json, achieving persistent RCE without user warning. Fixed in Cursor v1.3. | Patched | Poisoned tool descriptions give attackers direct behavioral control of any IDE agent — the primary "drone programming" mechanism. |
| CVE-2025-64702 | 7.5 | quic-go (HTTP/3) | QPACK header expansion DoS — HTTP/3 implementation enforces compressed HEADERS frame size limits but not decoded header section size, enabling memory exhaustion via crafted frames. Fixed in v0.57.0. | Patched | WebTransport/QUIC is the transport layer for real-time agent communication — a DoS here stalls or crashes the drone's C2 channel. |
| CVE-2025-9611 | 7.0 | Playwright MCP | DNS rebinding attack via missing Origin header validation in Microsoft Playwright MCP Server (< v0.0.40) — allows unauthorized invocation of browser automation tools from a victim's browser. | Patched | DNS rebinding turns a victim's own browser into an attack relay, triggering MCP browser-automation tools on the local server from an external page. |
| CVE-2026-0628 | 6.5 | Chrome / WebView (Extension Hijack) | Insufficient policy enforcement in Chrome WebView tag (< v143.0.7499.192) — malicious extension injects scripts or HTML into privileged pages, enabling extension-to-WebMCP trust escalation. | Patched | Extension content scripts can register tools from the page's origin context, bridging extension privileges into WebMCP's trust model in ways the spec does not account for. |
| CVE-2026-21438 | 6.5 | webtransport-go | Memory leak in webtransport-go (< v0.10.0) — closed streams not removed from internal map, preventing GC and enabling resource exhaustion DoS. Fixed in v0.10.0. | Patched | Gradual memory exhaustion on WebTransport servers crashes the agent transport layer, severing drone C2 channels or causing silent message loss. |
| CVE-2026-21435 | 6.5 | webtransport-go | QUIC flow control starvation in webtransport-go (< v0.10.0) — peer withholds credit causing CloseWithError to block indefinitely, resulting in hung session closures. | Patched | Hung session closures stall agent loop teardown, creating zombie drone sessions that cannot be cleanly shut down or audited. |
| CVE-2025-68143 | 6.4 | mcp-server-git | git_init tool fails to validate target path, allowing repo creation outside CWD boundaries in any directory accessible to the server process. Resolved by removing the tool in v2025.9.25. | Patched | Agent could clone attacker repos with malicious post-checkout hooks into sensitive system directories, establishing persistent footholds. |
| CVE-2025-1647 | 5.6 | Bootstrap 3.x (DOM Clobbering) | XSS via improper input neutralization in Bootstrap 3.4.1 through 3.x — exploited via DOMino Effect chaining (DEFCON 33) to achieve cross-origin DOM clobbering in AI-agent-rendered pages. | Patched (HeroDevs) | DOM clobbering in agent-rendered UIs can override global objects the WebMCP API relies on, silently redirecting tool registration callbacks. |
CurXecute (CVSS 9.8) — indirect prompt injection writes malicious MCP config files (.cursor/mcp.json) without user approval, hijacking agent context and triggering RCE. Fixed in Cursor v1.3.9.
Digital Drone Relevance
Execution manipulation means attacker rewrites what the IDE drone does — from safe tasks to arbitrary system commands.
135,000+ agent instances publicly exposed with 63% running zero authentication — the largest known mass-exposure event in AI agent infrastructure.
Digital Drone Relevance
Mass drone army — 135K agents simultaneously controllable by any attacker on the internet with no authentication barrier.
OS command injection via crafted authorization_endpoint URL in widely-used MCP proxy (437K+ downloads). Fixed in v0.1.16.
Digital Drone Relevance
Compromised MCP proxy redirects all agent tool calls to attacker-controlled servers, turning every downstream agent into a drone.
Missing authentication between Inspector client and proxy allows unauthenticated attackers to launch arbitrary MCP commands over stdio. Fixed in v0.14.1.
Digital Drone Relevance
Turns the debugging tool into an unauthenticated C2 channel — any agent connected to an exposed Inspector is directly controllable.
EchoLeak — Zero-click AI command injection (CWE-77) enabling unauthenticated network information disclosure from enterprise M365 environments.
Digital Drone Relevance
Zero-click exfiltration from enterprise tools — compromised agents silently exfiltrate data with no user interaction required.
Attacker-crafted HTML page triggers arbitrary command execution via the AI agent runtime — one of several concurrent by-design RCE patterns across 150M+ MCP downloads.
Digital Drone Relevance
Architecture-level flaw means ALL MCP agents are potentially weaponizable as digital drones via a single malicious HTML page.
Use-After-Free in Chrome WebMCP component allows remote code execution via crafted HTML. Affected versions prior to Chrome 150.0.7871.186.
Digital Drone Relevance
DIRECT WebMCP exploit — crafted page achieves RCE inside the browser hosting the WebMCP agent context.
Use-After-Free in Chrome WebMCP (prior to v146.0.7680.71) enables heap corruption and potential arbitrary code execution via crafted HTML page.
Digital Drone Relevance
Heap corruption in the WebMCP runtime can redirect agent tool registration to attacker-controlled handlers.
Heap buffer overflow in Chrome WebML component (< v146.0.7680.71) exploitable via crafted HTML — allows remote attackers to achieve heap corruption and code execution.
Digital Drone Relevance
WebML powers on-device AI inference in the browser; a heap overflow here compromises the agent's own model execution context.
Mid-Session Tool Injection (arXiv:2606.06387) — third-party scripts exploit AbortSignal race conditions or timing attacks to hijack or frame registered tools mid-session.
Digital Drone Relevance
DIRECT WebMCP attack — third-party scripts silently redirect agent browser actions mid-session without leaving a detectable trace.
MCPoison — attacker with write access to a shared repo swaps a trusted MCP server for a malicious command in .cursor/mcp.json, achieving persistent RCE without user warning. Fixed in Cursor v1.3.
Digital Drone Relevance
Poisoned tool descriptions give attackers direct behavioral control of any IDE agent — the primary "drone programming" mechanism.
QPACK header expansion DoS — HTTP/3 implementation enforces compressed HEADERS frame size limits but not decoded header section size, enabling memory exhaustion via crafted frames. Fixed in v0.57.0.
Digital Drone Relevance
WebTransport/QUIC is the transport layer for real-time agent communication — a DoS here stalls or crashes the drone's C2 channel.
DNS rebinding attack via missing Origin header validation in Microsoft Playwright MCP Server (< v0.0.40) — allows unauthorized invocation of browser automation tools from a victim's browser.
Digital Drone Relevance
DNS rebinding turns a victim's own browser into an attack relay, triggering MCP browser-automation tools on the local server from an external page.
Insufficient policy enforcement in Chrome WebView tag (< v143.0.7499.192) — malicious extension injects scripts or HTML into privileged pages, enabling extension-to-WebMCP trust escalation.
Digital Drone Relevance
Extension content scripts can register tools from the page's origin context, bridging extension privileges into WebMCP's trust model in ways the spec does not account for.
Memory leak in webtransport-go (< v0.10.0) — closed streams not removed from internal map, preventing GC and enabling resource exhaustion DoS. Fixed in v0.10.0.
Digital Drone Relevance
Gradual memory exhaustion on WebTransport servers crashes the agent transport layer, severing drone C2 channels or causing silent message loss.
QUIC flow control starvation in webtransport-go (< v0.10.0) — peer withholds credit causing CloseWithError to block indefinitely, resulting in hung session closures.
Digital Drone Relevance
Hung session closures stall agent loop teardown, creating zombie drone sessions that cannot be cleanly shut down or audited.
git_init tool fails to validate target path, allowing repo creation outside CWD boundaries in any directory accessible to the server process. Resolved by removing the tool in v2025.9.25.
Digital Drone Relevance
Agent could clone attacker repos with malicious post-checkout hooks into sensitive system directories, establishing persistent footholds.
XSS via improper input neutralization in Bootstrap 3.4.1 through 3.x — exploited via DOMino Effect chaining (DEFCON 33) to achieve cross-origin DOM clobbering in AI-agent-rendered pages.
Digital Drone Relevance
DOM clobbering in agent-rendered UIs can override global objects the WebMCP API relies on, silently redirecting tool registration callbacks.
Digital Drone Threat Assessment
AI agents with browser access are being used as undetectable attack vectors
Critical Finding
AI agents with browser access are being used as undetectable attack vectors. These “digital drones” operate with full user credentials, real browser fingerprints, and human-like behavioral patterns — making them invisible to conventional bot detection systems. The MCP (Model Context Protocol) ecosystem has introduced new attack surfaces that enable tool poisoning, mid-session injection, and data exfiltration through covert channels.
1,400%
increase in AI agent bot traffic (2025)
135,000+
exposed OpenClaw agent instances
2.8%
of sites can detect AI agent traffic
18+
CVEs in MCP/WebMCP ecosystem (2025-2026)
Attack Chain Visualization
Why Digital Drones Are Hard to Detect
Real Browser Fingerprints
Agents use real Chrome instances with genuine browser fingerprints — identical to human users
Valid Session Credentials
Agents inherit the user's authenticated session — cookies, tokens, and all
Human-Like Interactions
AI agents click, scroll, and type with near-human behavioral patterns
Encrypted Covert Channels
WebRTC, Service Workers, and WebGPU enable data exfiltration invisible to network monitors
MCP Tool Injection
Mid-session tool poisoning silently redirects agent behavior without any visible change
Cloud-Native Infrastructure
Agents run on legitimate cloud platforms — indistinguishable from normal automation traffic
SuperSayan Features
A comprehensive security intelligence platform for the agentic web
Headless Detection Engine
10+ signal composite detection with scoring algorithm
AI Agent Behavioral Fingerprinting
Mouse straightness, velocity CV, click pattern analysis
WebMCP Tool Invocation Monitor
Wrap execute callbacks for real-time tool observation
Chrome Extension "Glow" System
Elements accessed by agents glow red; pages glow on headless access
MCP Vulnerability Scanner
14+ CVEs cataloged with digital drone relevance scoring
The “Glow” Extension
Visual detection of AI agent and automated browser interactions
How It Works
When a Chrome headless shell or AI agent accesses an element, it glows red. When a page is accessed by an automated browser, the entire page gets a subtle red border glow. The extension monitors DOM mutations, user activation states, and API call patterns to distinguish human from agent interactions in real-time.
// Agent accesses element
MutationObserver → DOM change detected
navigator.userActivation → isActive: false
→ Element glows red (programmatic)
// Human clicks element
userActivation → isActive: true
→ Element stays normal (human)
MutationObserver
Watches for programmatic DOM changes in real-time
navigator.userActivation
Distinguishes human vs programmatic actions
PerformanceObserver
Detects burst API call patterns from automation
WebMCP toolchange
Monitors tool injection and modification events
Visual CSS Overlay
Configurable glow intensity for detected interactions
Incident Report
Exportable report with OSINT attribution data