Fetching from the wire…
Security2026-09-04 · source-backed
Published to NVD September 4. An unauthenticated remote attacker reads arbitrary files from any host running Google Cloud ADK for Python 1.9.0 through 1.21.0, via a crafted file_path query parameter on the builder endpoint. Thirteen minor versions in range. If you stood up the ADK builder UI on a reachable interface, treat every secret on that host as read. NVD
Each link below shares sources, entities, or timing with this story.
NVD published it on September 5. Rowboat through 0.9.1 doesn't validate custom MCP server and webhook URLs, so an authenticated user configures an arbitrary destination and makes the server reach internal services and metadata endpoints, enumerating your network topology from...
AgentScope through 2.0.7.post1 has a path traversal in LocalWorkspace.add_skill, which copies arbitrary server directories into the agent workspace via an unconfined skill_path parameter (CVE-2026-85685). An attacker names any directory and its files land in the skills directo...
NVD posted nine advisories on August 25, clustering into one shape: a local server assuming a browser can't reach it. PraisonAI validated MCP origins with request_origin.startswith(allowed) against a localhost allowlist, so an attacker-registered localhost.attacker.com passes...
Google's Agent Development Kit for Python listed litellm>=1.75.5 as an optional dependency. No upper bound. No pin. During the week of March 24, LiteLLM versions 1.82.7 and 1.82.8 were compromised by the TeamPCP group with a three-stage payload: credential harvesting, Kubernet...
Your read-only flag is a claim, not a guarantee. Two independent Postgres MCP servers proved it on September 4. Postgres MCP Pro got CVE-2026-85620 at CVSS 9.2. The bug is one line of reasoning in safe_sql.py: the validator checks function names on FuncCall AST nodes. A functi...
Published to NVD September 1, affecting Codex CLI on Windows, macOS and Linux plus Codex Desktop. The command-safety parser read PowerShell's stop-parsing token differently than PowerShell does, so commands got misclassified as safe. An attacker-prepared repository could get C...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.