Fetching from the wire…
Security2026-09-18 · source-backed
GHSA-9g45-5xwm-f3wc, published September 17, follows the two rmcp advisories from September 16 covering OAuth token theft and a permanent session-table leak. This one is client-side: custom headers set on the MCP client, which in practice carry API keys and bearer tokens, get re-sent to whatever host a cross-origin redirect names. Running the official Rust MCP SDK against a third-party server means treating every redirect as a credential exfiltration channel. Separately, GHSA-hx8v-g79f-8w5f covers SSRF in LiteLLM Proxy through the user_config request parameter. LiteLLM usually has network reach into internal services and cloud metadata endpoints the agent itself does not, so the medium rating understates it depending on where you deployed.
Each link below shares sources, entities, or timing with this story.
CVE-2026-63127 (8.2) covers crates/rmcp/src/transport/auth.rs omitting the RFC 9728 resource field and never confirming the returned resource identifier matches the configured MCP server, so a hostile server publishes metadata for a different legitimate resource and you finish...
All affect versions through v0.22.1. GHSA-xwmw-prc4-v3cr (8.8) accepted unauthenticated OAuth dynamic client registration with an arbitrary external redirect URI and auto-completed the flow with no consent screen, minting a token carrying the victim's full group set against th...
Hudson Rock got hold of the archive and counted it. 433,909 files. 118,829 CI runner dumps traced to 2,488 corporate domains. AWS keys, Salesforce client secrets, Slack signing secrets, Azure environment variables, and AI provider API keys belonging to NVIDIA, Volkswagen, Micr...
GitHub published four advisories against omnigent-ai/omnigent v0.1.0, the meta-harness that runs Claude Code, Codex and Pi under policy and sandboxing. GHSA-jrrm-9hc7-2v3h at CVSS 9.0 lets any user with session edit rights overwrite a shared template agent via PUT /sessions/{i...
A standalone macOS and Windows desktop beta released September 14, moving the open-source agent out of the VS Code extension slot; the releases page shows Desktop v0.0.26 on September 11, v0.0.27 on September 13 and v0.0.28 on September 15, so it's shipping daily (GitHub). It...
Your read-only flag is a claim, not a guarantee. Two independent Postgres MCP servers proved it on September 4. Postgres MCP Pro got CVE-2026-85620 at CVSS 9.2. The bug is one line of reasoning in safe_sql.py: the validator checks function names on FuncCall AST nodes. A functi...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.