Sourced from Tenet Security's "Agentjacking" disclosure (tenetsecurity.ai/blog/agentjacking-coding-agents-with-fake-sentry-errors/), corroborated by Cloud Security Alliance Lab Space and multiple independent security outlets (The Hacker News, Infosecurity Magazine, DevOps.com). Read the primary source directly, not a secondary summary.
Mechanism: an attacker obtains a target's Sentry DSN, a public, write-only credential intentionally embedded in frontend JavaScript, requiring no additional authentication. The attacker POSTs a crafted error event directly to Sentry's ingest endpoint, embedding carefully formatted markdown (headings, code blocks, a fabricated "## Resolution" section naming an executable command) within standard error fields, styled to be visually indistinguishable from Sentry's own authentic system-generated output. When a developer asks their AI coding agent to investigate the error, the Sentry MCP server returns the poisoned event to the agent as diagnostic data. The agent treats the MCP tool response as authoritative system output rather than untrusted external data, cannot distinguish the attacker's embedded instruction from legitimate remediation guidance, and executes the suggested command with full developer privileges.
Evidence: 85% exploitation success rate across three tested agents (Claude Code, Cursor, OpenAI Codex CLI). At least 2,388 organizations identified with publicly exposed Sentry DSNs. Sentry itself has acknowledged the issue as "technically not defensible" given the DSN's intentional public-write design, and has activated a narrow, specific-payload-string content filter rather than a structural fix. The attack bypasses EDR, WAF, IAM, VPN, Cloudflare, and firewalls entirely, since no conventionally malicious artifact exists anywhere in the chain.
Checked against near-neighbors at the field level, including a deliberate re-check that initially flagged this as possibly already covered: distinct from AVE-2026-00044 (Async Task Result Poisoning -- that record's own stated distinguishing property is a temporal gap between task dispatch and later result consumption bypassing synchronous checks; this mechanism is a synchronous MCP tool call/response within the same interaction, with no temporal gap at all), AVE-2026-00043 (MCP App UI Payload Injection -- that record's mechanism is instructions hidden in non-rendered elements, invisible to the user; this mechanism's content is fully rendered and visible, its evasion technique is visual mimicry of a trusted system's own authentic template, the opposite concealment strategy), AVE-2026-00042 (REPL Code Mode Payload Injection -- that record is tool-result content breaking out of a data context into a dynamic eval()/exec() code string via escape sequences; this mechanism requires no code-context breakout at all, the agent reads the content as natural-language diagnostic guidance and is persuaded, not tricked via a syntactic escape), and AVE-2026-00018 (Tool Result Manipulation -- that record is the agent itself being instructed to falsify or alter a tool result before reporting it; this mechanism is the inverse, a tool result itself deceiving the agent into acting).
researcher field will credit Tenet Security directly, not AVE.
Sourced from Tenet Security's "Agentjacking" disclosure (tenetsecurity.ai/blog/agentjacking-coding-agents-with-fake-sentry-errors/), corroborated by Cloud Security Alliance Lab Space and multiple independent security outlets (The Hacker News, Infosecurity Magazine, DevOps.com). Read the primary source directly, not a secondary summary.
Mechanism: an attacker obtains a target's Sentry DSN, a public, write-only credential intentionally embedded in frontend JavaScript, requiring no additional authentication. The attacker POSTs a crafted error event directly to Sentry's ingest endpoint, embedding carefully formatted markdown (headings, code blocks, a fabricated "## Resolution" section naming an executable command) within standard error fields, styled to be visually indistinguishable from Sentry's own authentic system-generated output. When a developer asks their AI coding agent to investigate the error, the Sentry MCP server returns the poisoned event to the agent as diagnostic data. The agent treats the MCP tool response as authoritative system output rather than untrusted external data, cannot distinguish the attacker's embedded instruction from legitimate remediation guidance, and executes the suggested command with full developer privileges.
Evidence: 85% exploitation success rate across three tested agents (Claude Code, Cursor, OpenAI Codex CLI). At least 2,388 organizations identified with publicly exposed Sentry DSNs. Sentry itself has acknowledged the issue as "technically not defensible" given the DSN's intentional public-write design, and has activated a narrow, specific-payload-string content filter rather than a structural fix. The attack bypasses EDR, WAF, IAM, VPN, Cloudflare, and firewalls entirely, since no conventionally malicious artifact exists anywhere in the chain.
Checked against near-neighbors at the field level, including a deliberate re-check that initially flagged this as possibly already covered: distinct from AVE-2026-00044 (Async Task Result Poisoning -- that record's own stated distinguishing property is a temporal gap between task dispatch and later result consumption bypassing synchronous checks; this mechanism is a synchronous MCP tool call/response within the same interaction, with no temporal gap at all), AVE-2026-00043 (MCP App UI Payload Injection -- that record's mechanism is instructions hidden in non-rendered elements, invisible to the user; this mechanism's content is fully rendered and visible, its evasion technique is visual mimicry of a trusted system's own authentic template, the opposite concealment strategy), AVE-2026-00042 (REPL Code Mode Payload Injection -- that record is tool-result content breaking out of a data context into a dynamic eval()/exec() code string via escape sequences; this mechanism requires no code-context breakout at all, the agent reads the content as natural-language diagnostic guidance and is persuaded, not tricked via a syntactic escape), and AVE-2026-00018 (Tool Result Manipulation -- that record is the agent itself being instructed to falsify or alter a tool result before reporting it; this mechanism is the inverse, a tool result itself deceiving the agent into acting).
researcherfield will credit Tenet Security directly, not AVE.