Fetching from the wire…
Security2026-08-28 · source-backed
startServer.ts defaulted the listen address to :: when no host was given, so startSseAndStreamableHttpMcpServer exposed both Streamable HTTP and SSE on all interfaces, with authentication middleware applied only when the caller supplied it (NVD). Any unauthenticated client with network reach gets command execution as the service user, or arbitrary file read and write. A 10.0 in an agent desktop tool is about as bad as this gets.
Each link below shares sources, entities, or timing with this story.
Patched in EE 19.3.1, 19.2.5 and 19.1.7, covering everything from 18.9, CVSS 7.3. An authenticated user with only Developer permissions could get the agent to process configuration they control and execute arbitrary commands inside the CI context (NVD). The blast radius is wha...
CVE-2026-75130, published August 18, covers Upstash's Context7 through 2.1.2: the Custom AI Instructions feature serves unsanitized content through the MCP server, so poisoned instructions can exfiltrate credentials from environment files to an attacker-controlled service and...
NVD published this against kazuph/mcp-fetch through 1.6.3 on August 26. isSafeUrl reads the hostname from the parsed URL, which for yields the bracketed string, then tests it with net.isIP, which returns zero for a bracketed value. The entire private-address branch is skipped,...
Langflow's CSV Agent node hardcodes allow_dangerous_code=True, exposing LangChain's python_repl_ast tool. Attackers inject prompts to execute arbitrary Python and OS commands without authentication. Patched in v1.8.0. This is the same eval() epidemic vulnerability class seen a...
Go look at your ~/.claude/CLAUDE.md right now. Mine has internal package names, a build command with a host in it, and notes about which credentials live where. I wrote it assuming exactly one reader. RuntimeWire published traced request captures on August 9 showing Muse Code...
VulnCheck disclosed on August 24 that Continue CLI's headless and auto modes give the Bash tool blanket allow permission, leaving isCriticalCommand as the only guard. Its dangerous-path test matches /, ~, /usr, /etc, /bin and /sbin, so recursive deletion of /home, /root, /var,...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.