Fetching from the wire…
Security2026-08-29 · source-backed
CVE-2026-54746 (6.4) affects Hatchet from 0.40.0 until 0.91.1: the Dispatcher gRPC service didn't verify that a request's worker ID belonged to the tenant in the bearer-token context, in UpsertWorkerLabels and related calls. Hatchet orchestrates background tasks, AI agents and durable workflows, so this is a cross-tenant boundary failure in shared agent infrastructure rather than in a single-user dev tool. 0.91.1 fixes it. (NVD)
Each link below shares sources, entities, or timing with this story.
The executor inspected submitted source against a denied list of attribute names and calls, leaving the attribute-access escapes that always defeat that approach, with no authentication in front of it (NVD). Denylist sandboxing of Python loses reliably. The boundary has to be...
The http_request and web_fetch agent tools in SiYuan before v3.8.1 validate only the safety-check resolution, so an attacker answers the guard lookup with a public address and the real lookup with an internal one (NVD). The paired CVE-2026-82233 is a path traversal in the asse...
CVE-2026-19889 and CVE-2026-75871, published August 27, let an authenticated user with Duo access redirect outbound model requests externally, affecting AI Gateway 18.9.0/18.10 through 19.0.12, 19.1 to 19.1.7 and 19.2 to 19.2.2 (NVD). Redirecting the model endpoint sends every...
Patched in EE 19.3.1, 19.2.5 and 19.1.7, covering everything from 18.9, CVSS 7.3. An authenticated user with only Developer permissions could get the agent to process configuration they control and execute arbitrary commands inside the CI context (NVD). The blast radius is wha...
NVD published this against kazuph/mcp-fetch through 1.6.3 on August 26. isSafeUrl reads the hostname from the parsed URL, which for yields the bracketed string, then tests it with net.isIP, which returns zero for a bracketed value. The entire private-address branch is skipped,...
NVD posted nine advisories on August 25, clustering into one shape: a local server assuming a browser can't reach it. PraisonAI validated MCP origins with request_origin.startswith(allowed) against a localhost allowlist, so an attacker-registered localhost.attacker.com passes...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.