Fetching from the wire…
Security2026-06-08 · source-backed
CVE-2026-44338 (CVSS 7.3) comes from PraisonAI's legacy Flask api_server.py shipping with AUTH_ENABLED=False and AUTH_TOKEN=None, exposing GET /agents and POST /chat to anyone on the network. Sysdig watched a scanner identifying as "CVE-Detector/1.0" hit the exact endpoint under four hours after the advisory dropped. Affects 2.5.6–4.6.33, fixed in 4.6.34. The lesson isn't "patch faster," it's "insecure-by-default is now exploited at machine speed." If your agent framework ships auth off, treat that as a shipped vulnerability, not a config choice.
Each link below shares sources, entities, or timing with this story.
Cisco Talos uncovered "UAT-10608", a credential harvesting campaign exploiting CVE-2025-55182 (CVSS 10.0) in React Server Components and Next.js App Router. 766 servers worldwide. 24 hours. Post-compromise, 91.5% of hosts leaked database credentials and 78.2% exposed SSH priva...
Thirty CVEs in sixty days. That's the MCP ecosystem's security track record for 2026 so far, and the severity is climbing. Three disclosures dropped this week that should make anyone running agent infrastructure pause. First, PraisonAI, a popular multi-agent orchestration fram...
BlueRock scanned over 7,000 MCP servers against 22-plus security rules. 36.7% carry potential server-side request forgery exposure from unrestricted outbound fetch, and 42% handle credentials insecurely. Their worked example is Microsoft's 85K-star Markitdown MCP server and it...
NVD posted nine advisories on August 25, clustering into one shape: a local server assuming a browser can't reach it. PraisonAI validated MCP origins with request_origin.startswith(allowed) against a localhost allowlist, so an attacker-registered localhost.attacker.com passes...
Between September 14 and September 15, NVD published seven entries hitting MCP infrastructure. I read all of them expecting to find something clever. There's nothing clever in any of them. CVE-2026-57124, 9.8, published September 14. PraisonAI's default UI exposes POST /api/mc...
IBM's bulletin lists CVE-2026-85025, rated CVSS 9.8, which allows unauthenticated code execution through publicly shared MCP project endpoints in Langflow 1.0.0 through 1.11.5. CVE-2026-78575 and CVE-2026-81941 let authenticated users run OS commands through the MCP stdio serv...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.