Skip to content
Vulnerability intelligence

CVE-2026-22708 — Security Advisory

Tenet Security disclosed a new attack class on June 12. Attackers inject prompts into Sentry error events using publicly discoverable DSNs. AI coding agents retrieve the events via MCP and execute attacker-controlled code. Sentry called it 'technically not defensible.'

CVSS 7.8 2026