VRIL LABSv2026
2026 Security Research

Supersayan WebMCP Security

Next-Generation WebMCP Security Intelligence Platform

Detect. Defend. Trace. The complete countermeasure suite for the agentic web.

Live Scanner

Detection Dashboard

Run a comprehensive security scan of your browser environment

OSINT Intelligence

Attribution Tracer

Identify the source and nature of your connection

Vulnerability Database

MCP CVE Database

Known vulnerabilities in the MCP ecosystem with digital drone relevance

18 vulnerabilities cataloged

Cursor IDE (CurXecute)Patched

CurXecute (CVSS 9.8) — indirect prompt injection writes malicious MCP config files (.cursor/mcp.json) without user approval, hijacking agent context and triggering RCE. Fixed in Cursor v1.3.9.

Digital Drone Relevance

Execution manipulation means attacker rewrites what the IDE drone does — from safe tasks to arbitrary system commands.

OPENCLAW-20269.8
OpenClaw PlatformActive crisis

135,000+ agent instances publicly exposed with 63% running zero authentication — the largest known mass-exposure event in AI agent infrastructure.

Digital Drone Relevance

Mass drone army — 135K agents simultaneously controllable by any attacker on the internet with no authentication barrier.

mcp-remotePatched

OS command injection via crafted authorization_endpoint URL in widely-used MCP proxy (437K+ downloads). Fixed in v0.1.16.

Digital Drone Relevance

Compromised MCP proxy redirects all agent tool calls to attacker-controlled servers, turning every downstream agent into a drone.

MCP InspectorPatched — exposure persists

Missing authentication between Inspector client and proxy allows unauthenticated attackers to launch arbitrary MCP commands over stdio. Fixed in v0.14.1.

Digital Drone Relevance

Turns the debugging tool into an unauthenticated C2 channel — any agent connected to an exposed Inspector is directly controllable.

Microsoft 365 CopilotPatched

EchoLeak — Zero-click AI command injection (CWE-77) enabling unauthenticated network information disclosure from enterprise M365 environments.

Digital Drone Relevance

Zero-click exfiltration from enterprise tools — compromised agents silently exfiltrate data with no user interaction required.

GPT Researcher / MCP EcosystemOngoing — design-level fix needed

Attacker-crafted HTML page triggers arbitrary command execution via the AI agent runtime — one of several concurrent by-design RCE patterns across 150M+ MCP downloads.

Digital Drone Relevance

Architecture-level flaw means ALL MCP agents are potentially weaponizable as digital drones via a single malicious HTML page.

Chrome WebMCPPatched

Use-After-Free in Chrome WebMCP component allows remote code execution via crafted HTML. Affected versions prior to Chrome 150.0.7871.186.

Digital Drone Relevance

DIRECT WebMCP exploit — crafted page achieves RCE inside the browser hosting the WebMCP agent context.

Chrome WebMCPPatched

Use-After-Free in Chrome WebMCP (prior to v146.0.7680.71) enables heap corruption and potential arbitrary code execution via crafted HTML page.

Digital Drone Relevance

Heap corruption in the WebMCP runtime can redirect agent tool registration to attacker-controlled handlers.

Chrome WebMLPatched

Heap buffer overflow in Chrome WebML component (< v146.0.7680.71) exploitable via crafted HTML — allows remote attackers to achieve heap corruption and code execution.

Digital Drone Relevance

WebML powers on-device AI inference in the browser; a heap overflow here compromises the agent's own model execution context.

WebMCP SpecResearch disclosure

Mid-Session Tool Injection (arXiv:2606.06387) — third-party scripts exploit AbortSignal race conditions or timing attacks to hijack or frame registered tools mid-session.

Digital Drone Relevance

DIRECT WebMCP attack — third-party scripts silently redirect agent browser actions mid-session without leaving a detectable trace.

Cursor IDE (MCPoison)Patched

MCPoison — attacker with write access to a shared repo swaps a trusted MCP server for a malicious command in .cursor/mcp.json, achieving persistent RCE without user warning. Fixed in Cursor v1.3.

Digital Drone Relevance

Poisoned tool descriptions give attackers direct behavioral control of any IDE agent — the primary "drone programming" mechanism.

quic-go (HTTP/3)Patched

QPACK header expansion DoS — HTTP/3 implementation enforces compressed HEADERS frame size limits but not decoded header section size, enabling memory exhaustion via crafted frames. Fixed in v0.57.0.

Digital Drone Relevance

WebTransport/QUIC is the transport layer for real-time agent communication — a DoS here stalls or crashes the drone's C2 channel.

Playwright MCPPatched

DNS rebinding attack via missing Origin header validation in Microsoft Playwright MCP Server (< v0.0.40) — allows unauthorized invocation of browser automation tools from a victim's browser.

Digital Drone Relevance

DNS rebinding turns a victim's own browser into an attack relay, triggering MCP browser-automation tools on the local server from an external page.

Chrome / WebView (Extension Hijack)Patched

Insufficient policy enforcement in Chrome WebView tag (< v143.0.7499.192) — malicious extension injects scripts or HTML into privileged pages, enabling extension-to-WebMCP trust escalation.

Digital Drone Relevance

Extension content scripts can register tools from the page's origin context, bridging extension privileges into WebMCP's trust model in ways the spec does not account for.

webtransport-goPatched

Memory leak in webtransport-go (< v0.10.0) — closed streams not removed from internal map, preventing GC and enabling resource exhaustion DoS. Fixed in v0.10.0.

Digital Drone Relevance

Gradual memory exhaustion on WebTransport servers crashes the agent transport layer, severing drone C2 channels or causing silent message loss.

webtransport-goPatched

QUIC flow control starvation in webtransport-go (< v0.10.0) — peer withholds credit causing CloseWithError to block indefinitely, resulting in hung session closures.

Digital Drone Relevance

Hung session closures stall agent loop teardown, creating zombie drone sessions that cannot be cleanly shut down or audited.

mcp-server-gitPatched

git_init tool fails to validate target path, allowing repo creation outside CWD boundaries in any directory accessible to the server process. Resolved by removing the tool in v2025.9.25.

Digital Drone Relevance

Agent could clone attacker repos with malicious post-checkout hooks into sensitive system directories, establishing persistent footholds.

Bootstrap 3.x (DOM Clobbering)Patched (HeroDevs)

XSS via improper input neutralization in Bootstrap 3.4.1 through 3.x — exploited via DOMino Effect chaining (DEFCON 33) to achieve cross-origin DOM clobbering in AI-agent-rendered pages.

Digital Drone Relevance

DOM clobbering in agent-rendered UIs can override global objects the WebMCP API relies on, silently redirecting tool registration callbacks.

Threat Briefing

Digital Drone Threat Assessment

AI agents with browser access are being used as undetectable attack vectors

Critical Finding

AI agents with browser access are being used as undetectable attack vectors. These “digital drones” operate with full user credentials, real browser fingerprints, and human-like behavioral patterns — making them invisible to conventional bot detection systems. The MCP (Model Context Protocol) ecosystem has introduced new attack surfaces that enable tool poisoning, mid-session injection, and data exfiltration through covert channels.

1,400%

increase in AI agent bot traffic (2025)

135,000+

exposed OpenClaw agent instances

2.8%

of sites can detect AI agent traffic

18+

CVEs in MCP/WebMCP ecosystem (2025-2026)

Attack Chain Visualization

Attacker
MCP Tool Poisoning
AI Agent Compromised
Browser Access + User Credentials
Data Exfiltration via Covert Channels
Attacker Receives Data

Why Digital Drones Are Hard to Detect

Real Browser Fingerprints

Agents use real Chrome instances with genuine browser fingerprints — identical to human users

Valid Session Credentials

Agents inherit the user's authenticated session — cookies, tokens, and all

Human-Like Interactions

AI agents click, scroll, and type with near-human behavioral patterns

Encrypted Covert Channels

WebRTC, Service Workers, and WebGPU enable data exfiltration invisible to network monitors

MCP Tool Injection

Mid-session tool poisoning silently redirects agent behavior without any visible change

Cloud-Native Infrastructure

Agents run on legitimate cloud platforms — indistinguishable from normal automation traffic

Feature Suite

SuperSayan Features

A comprehensive security intelligence platform for the agentic web

Headless Detection Engine

10+ signal composite detection with scoring algorithm

AI Agent Behavioral Fingerprinting

Mouse straightness, velocity CV, click pattern analysis

WebMCP Tool Invocation Monitor

Wrap execute callbacks for real-time tool observation

Chrome Extension "Glow" System

Elements accessed by agents glow red; pages glow on headless access

MCP Vulnerability Scanner

14+ CVEs cataloged with digital drone relevance scoring

Chrome Extension

The “Glow” Extension

Visual detection of AI agent and automated browser interactions

example.com — AI Agent Detected
GLOW ACTIVE
AGENT ACCESS

How It Works

When a Chrome headless shell or AI agent accesses an element, it glows red. When a page is accessed by an automated browser, the entire page gets a subtle red border glow. The extension monitors DOM mutations, user activation states, and API call patterns to distinguish human from agent interactions in real-time.

// Agent accesses element
MutationObserver → DOM change detected
navigator.userActivation → isActive: false
→ Element glows red (programmatic)

// Human clicks element
userActivation → isActive: true
→ Element stays normal (human)

MutationObserver

Watches for programmatic DOM changes in real-time

navigator.userActivation

Distinguishes human vs programmatic actions

PerformanceObserver

Detects burst API call patterns from automation

WebMCP toolchange

Monitors tool injection and modification events

Visual CSS Overlay

Configurable glow intensity for detected interactions

Incident Report

Exportable report with OSINT attribution data