Vibe Coding
A Serena MCP server CVE for the oldest mistake: binding 0.0.0.0 in HTTP mode
CVE-2026-38924, published 2026-09-14 at 2.9 LOW, records that Oraios AI Serena before 1.0.0 listens on 0.0.0.0 for its MCP server in HTTP mode. The NVD note is the interesting part: the supplier itself called 0.0.0.0 a potential security hazard, while the documentation at the time of the report recommended it. Low score, but it is the default that turns a local coding-agent tool into something anyone on the same network can drive.
Source
↳ Follow the thread