Fetching from the wire…
Security2026-06-26 · source-backed
Wiz Research disclosed that Amazon Q Developer auto-launched MCP servers defined in a repo's .amazonq/mcp.json, so a single config file in a cloned repo could execute code with your live AWS keys, cloud CLI tokens, and SSH agent attached. Reported April 20, fixed May 12, public writeup June 26. No known exploitation, but it's a textbook "repo config equals code execution" failure. The defense is concrete: treat any MCP config shipped inside a repo as untrusted code, disable auto-start of repo-defined servers, require explicit approval before spawning them.
Each link below shares sources, entities, or timing with this story.
Wiz disclosed CVE-2026-12957 and CVE-2026-12958 in Amazon Q Developer, where the agent loaded MCP server configs straight out of a repo's .amazonq/mcp.json with no consent check and no workspace-trust gate. A booby-trapped repo could reach arbitrary code execution and steal AW...
Full 10.0. Network vector, low complexity, no authentication, no user interaction, high impact on confidentiality, integrity and availability. CVE-2026-79696, published September 9, is a code injection flaw in adk web affecting Google's Agent Development Kit for Python 2.0.0 t...
1. Set package cooldown to 72 hours across all your package managers. pnpm: resolution-time=72h, uv: --exclude-newer, npm via .npmrc. This single config change would have protected you from the LiteLLM attack. Willison's survey covers all seven managers. 2. Install Lasso Secur...
The Model Context Protocol has a security problem that's no longer theoretical — it's statistical. Between January and February 2026, researchers filed 30+ CVEs against MCP servers, clients, and infrastructure. One package with nearly 500,000 downloads carried a CVSS 9.6 RCE....
Your read-only flag is a claim, not a guarantee. Two independent Postgres MCP servers proved it on September 4. Postgres MCP Pro got CVE-2026-85620 at CVSS 9.2. The bug is one line of reasoning in safe_sql.py: the validator checks function names on FuncCall AST nodes. A functi...
This is the one that should make you check your own setup tonight. June MCP-security roundups flag roughly 12,520 internet-exposed MCP services, about 40% of them with no authentication at all. On top of that, Adversa AI's TrustFall and SymJack research shows that Claude Code,...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.