AgentsCVE-2026-27896 MCP Go SDK Case-Insensitive Security BypassCVE Reports·high signalXBlueskyLinkedInCopy linkHigh-severity interpretation conflict in official MCP Go SDK. Go encoding/json case-insensitive matching lets attackers bypass WAFs. Fixed in v1.3.1.SourceSource pageCVE Reports↳ Follow the threadPolicy dependency / Stack layerCodex routes MCP elicitations and tool approvals through one decision API, with model policy overriding the legacy review flagGitHubStack layer / Threat patternOpenAI Agents SDK 0.22.1 adds server-wide guardrails on MCP tools and configurable Unix-local sandbox isolationGitHubPolicy dependency / Threat patternMCP ext-apps migrated to SDK v2 across 125 files to cut a server-to-client dependency edgeGitHubStack layer / Threat patternIris trains 35B and 397B search agents by reverse-constructing questions from hyperlink structure, and reports benchmarks both with and without context managementarXiv / HuggingFace Daily PapersThreat pattern / Update threadLangChain's deepagents-talon adds channel-scoped MCP server authorization and OAuth device auth for Slack and GitHubGitHub ReleasesStack layer / Threat patternSHAP Dilutes Malware Feature Credit by 1/m and Can Reverse the Sign of an Unused FeaturearXiv 2609.04626Policy dependency / Threat patternCONTINUITY names "security-context discontinuity" as the failure mode where individually correct agent security controls compose into an insecure systemarXivStack layer / Threat patterntranscripts-mcp lets one coding tool search the session history of the other twoGitHub