ATLAS Landscape
AML.T0110

AI Agent Tool Poisoning

Adversaries may achieve persistence by poisoning tools used by AI agents including built-in tools or tools available to the agent via Model Context Protocol (MCP) connections. This involves compromising benign tools already integrated into the agent's environment. By altering tool behavior such as modifying parameters or descriptions, injecting hidden logic, or redirecting outputs, attackers can maintain long-term influence over the agent's actions, decisions, or external interactions. Poisoned tools may silently exfiltrate data, execute unauthorized commands, or manipulate downstream processes without raising suspicion.

Severity CVE CVSS
HIGH CVE-2026-39891 8.8
HIGH GHSA-g985-wjh9-qxxc 8.4
HIGH CVE-2026-40156 7.8
MEDIUM CVE-2026-4502 6.5
CRITICAL CVE-2026-40111
HIGH GHSA-qx8j-g322-qj6m
MEDIUM GHSA-2qrv-rc5x-2g2h
LOW GHSA-767m-xrhc-fxm7
MEDIUM GHSA-w6wx-jq6j-6mcj