AgentsVulnerable MCP Project Catalogs Critical CVEsVulnerable MCP Project·high signalXBlueskyLinkedInCopy linkvulnerablemcp.info catalogs CVE-2026-25536 TypeScript SDK cross-client leak, CVE-2026-23744 MCPJam RCE, chained mcp-server-git CVEs. Adversa AI MCP Security TOP 25 most comprehensive taxonomy.SourceSource pageVulnerable MCP Project↳ Follow the threadStack layer / Threat patternchrome-devtools-mcp 1.9.0 publishes itself as an Agent Plugins 1.0 package installable across five agent clientsGitHubStack layer / Threat patternOpenAI Agents SDK 0.22.1 adds server-wide guardrails on MCP tools and configurable Unix-local sandbox isolationGitHubPolicy dependency / Threat patternMCP ext-apps migrated to SDK v2 across 125 files to cut a server-to-client dependency edgeGitHubStack layer / Threat patternGirder ships a semantic code graph as one static Rust binary and claims a 97.85% byte cut versus full-file readsGitHubStack layer / Threat patternNotifkit Ships Notification Infrastructure as an MIT npm Library With an MCP Server, Explicitly Positioned Against Novunotifkit on GitHub, via Hacker News Show HNStack layer / Threat patternRed Hat Ships ripwire and Argues Coding Agents Need a Deterministic Repo Map, Not a Vector DatabaseRed Hat Emerging Technologies (corroborated by Hacker News and independent X coverage)Stack layer / Threat patternSBOM Tools Cover Only the First Two of Four Supply-Chain Propagation StagesarXiv 2609.05380Stack layer / Threat patternCodex users are getting 'Cyber Abuse' warnings from OpenAI for security-reviewing their own code, with appeals rejected then reversedr/OpenAI (79 upvotes, 58 comments)