Fetching from the wire…
Public story · 2026-02-25 · source-backed
The MCP CVE count reached 30+, all sharing the same root cause: user-controlled input reaching exec()/eval() without sanitization. AgentAudit scanned 194 MCP packages and found 118 security findings across 68 packages — 14 rated critical or high. Anthropic's own Git MCP server had 3 CVEs enabling RCE via prompt injection (patched). Across 16 responsible disclosures to network-exposed MCP servers, response rates were low. Action: Audit every MCP server you use for eval()/exec() calls with user input. Use mcp-scan for automated detection. (DEV Community / Kai Security)
Each link below shares sources, entities, or timing with this story.
Two new attack classes emerged: Anthropic's own official Git MCP server has three CVEs (CVE-2025-68143/44/45) enabling RCE via prompt injection. MCP Watch, a security scanner designed to audit MCP servers, itself contains a command injection (CVE-2025-66401). MCPJam Inspector...
The agent skills supply chain is under coordinated attack. Snyk's ToxicSkills audit found 36% of ClawHub's 3,984 skills contain prompt injection payloads, 13.4% have critical malware, and submission rates exploded 10x to 500+/day. This week alone: CVE-2026-2256 (CVSS 9.1) is a...
The Model Context Protocol has a security problem that's no longer theoretical — it's statistical. Between January and February 2026, researchers filed 30+ CVEs against MCP servers, clients, and infrastructure. One package with nearly 500,000 downloads carried a CVSS 9.6 RCE....
May 2026 produced CVEs for Oracle SQL injection, nginx-ui CVSS 9.8 full takeover, and code-mcp command injection. OX Security documented a systemic RCE flaw across packages with 150M+ downloads. Anthropic has said the behavior is "expected." That's their position. My position:...
1. Flip your multi-model pipeline to review-then-generate. Instead of using a reasoning model to plan before code generation, let the specialist generate freely and use reasoning tokens for review. Paper shows 90.2% pass@1 vs 87.2% for the planning pattern. Source 2. Audit you...
GitHub added allowedMcpServers and deniedMcpServers keys to enterprise Copilot managed settings on August 6, configured to fail closed on malformed config, then followed on August 7 with a usage API exposing totals_by_3rd_party_agent for per-agent spend attribution (digitalapp...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.