Fetching from the wire…
Security2026-08-30 · source-backed
NVD published CVE-2026-82456 on August 29 at CVSS 10.0. The server binds its HTTP transport to every network interface and accepts MCP sessions with no caller credentials whenever ARGOCD_API_TOKEN is set, so anyone reaching the listener drives the full tool surface with the operator's [redacted] applications, request syncs, modify Argo CD resources. (NVD) This is the same failure I keep seeing in MCP servers, where holding a credential gets confused with having verified the caller.
Each link below shares sources, entities, or timing with this story.
Ten days from spec to shipped client. That's fast even for this ecosystem. The MCP 2026-07-28 revision replaced the bidirectional stateful protocol with request/response. Every request now independently carries protocol version, client identity and capabilities. Cloudflare's t...
Go look at your ~/.claude/CLAUDE.md right now. Mine has internal package names, a build command with a host in it, and notes about which credentials live where. I wrote it assuming exactly one reader. RuntimeWire published traced request captures on August 9 showing Muse Code...
CVE-2026-75130, published August 18, covers Upstash's Context7 through 2.1.2: the Custom AI Instructions feature serves unsanitized content through the MCP server, so poisoned instructions can exfiltrate credentials from environment files to an attacker-controlled service and...
upstash/context7 (60,590 stars) shipped @upstash/[redacted] on August 7 on the 2026-07-28 protocol revision. HTTP serving is now stateless for both modern and legacy clients, and Redis-backed sessions are gone, which is a real operational simplification for anyone self-hosting...
The Model Context Protocol has a security problem that's no longer theoretical — it's statistical. Between January and February 2026, researchers filed 30+ CVEs against MCP servers, clients, and infrastructure. One package with nearly 500,000 downloads carried a CVSS 9.6 RCE....
VulnCheck disclosed on August 24 that Continue CLI's headless and auto modes give the Bash tool blanket allow permission, leaving isCriticalCommand as the only guard. Its dangerous-path test matches /, ~, /usr, /etc, /bin and /sbin, so recursive deletion of /home, /root, /var,...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.