Fetching from the wire…
Security2026-08-27 · source-backed
Published to NVD and GitHub Security Advisories on August 27, this is a traversal in read_context in src/index.ts of bsmi021 mcp-file-context-server 1.0.0, remotely exploitable via the path argument, rated 5.5 MEDIUM (NVD). NVD's text notes the project was informed early through an issue report and the exploit is now public. A file-reading MCP server with a live traversal and no fix is a short path from prompt injection to arbitrary file disclosure.
Each link below shares sources, entities, or timing with this story.
NVD posted nine advisories on August 25, clustering into one shape: a local server assuming a browser can't reach it. PraisonAI validated MCP origins with request_origin.startswith(allowed) against a localhost allowlist, so an attacker-registered localhost.attacker.com passes...
Three separate Anthropic changes over about two weeks point the same direction, and none of them announced themselves as a strategy. Claude Code 2.1.238 added claude self-hosted-runner --defer-shutdown-max-min, which keeps serving attached sessions on SIGTERM, parks whatever's...
Go look at your ~/.claude/CLAUDE.md right now. Mine has internal package names, a build command with a host in it, and notes about which credentials live where. I wrote it assuming exactly one reader. RuntimeWire published traced request captures on August 9 showing Muse Code...
Ten days from spec to shipped client. That's fast even for this ecosystem. The MCP 2026-07-28 revision replaced the bidirectional stateful protocol with request/response. Every request now independently carries protocol version, client identity and capabilities. Cloudflare's t...
PostHog Desktop launched August 26 running a fleet of coding agents with Claude and GPT models, plan mode, parallel execution, MCP servers and a skill marketplace, whose context is the product's own production signals: in-app activity, logs, errors, payments and session record...
Terra Security's adversarial testing found recurring vulnerability patterns across AI coding tools including Claude Code, Loveable, and Base44. CVE-2026-25724 is a path traversal vulnerability in Claude Code (pre-2.1.7) where symbolic links bypass deny rules in settings.json b...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.