Fetching from the wire…
Security2026-08-27 · source-backed
GHSA-8cp3-qxj6-px34 covers utcp-http <= 1.1.3, where OpenApiConverter._extract_auth() reads the OAuth2 tokenUrl straight out of a remote spec and never validates it. The ensure_secure_url() guard the library applies to discovery URLs and tool invocation URLs is simply absent on the token endpoint, so registering an attacker-controlled spec and invoking any generated OAuth2 tool exfiltrates client_id and client_secret (GitHub Advisory). Two companion advisories the same hour: redirect-following without re-validation, and a prior SSRF fix that was never applied to the GraphQL and WebSocket plugins.
Each link below shares sources, entities, or timing with this story.
CVE-2026-45018 covers Chainlit >=2.4.0rc0 <2.12.0. With features.mcp.enabled = true, POST /mcp accepts a user-controlled fullCommand for stdio transport. validate_mcp_command() checks the executable name against an allowlist and never inspects arguments, so npx -y -c '<command...
On August 25 the advisory database published 20 advisories against PraisonAI and praisonaiagents: 1 critical, 15 high, 4 medium. The recurring pattern is authentication that's declared but never enforced. praisonai serve agents --api-key is silently ignored. AgentServer declar...
luckyPipewrench/pipelock (795 stars), an agent egress firewall that scans mediated HTTP, MCP, A2A and WebSocket traffic for exfiltration, SSRF and prompt injection, landed both fixes in 24 hours. GitHub A metrics side channel in a mediation proxy leaks exactly what the proxy e...
The July 29 release includes a security fix (PR #16095) authenticating WebSockets outside the URL, where credentials leak into proxy logs, browser history, and referrer headers. That's a common failure mode in agent UIs that stream over sockets, and worth checking in your own....
oomol-lab/open-connector (Apache 2.0, v1.2.0 released July 16, 2,682 stars since June 29) is an auth gateway where users connect SaaS accounts once and agents get execution results and metadata, never the credentials. Supports API keys, OAuth2, custom credentials, and no-auth...
— Security researcher Ari Marzouk disclosed 30+ vulnerabilities (24 CVEs) affecting Cursor, GitHub Copilot, Windsurf, Zed, Kiro, Roo Code, Junie, and Cline. The devastating finding: every tested AI IDE is vulnerable because none accounts for autonomous LLM agent behavior in th...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.