Vibe Coding
Pattern: the MCP aggregator is now the soft target, not the individual MCP server
Every MCP CVE in this run's window lands on a layer that sits in front of servers rather than on a server itself: eight in MCPHub (multi-tenant routing, bearer-key scoping, SSRF egress, spawn authorization), the ash_ai origin-validation bypass reported yesterday, and an SSRF in sdcb chats' fetch-tools endpoint (CVE-2026-82905, 6.3, exploit public, vendor never responded). The pattern is that hubs inherit the union of every downstream server's capability, filesystem, HTTP fetch, cloud APIs with the owner's keys, while enforcing authorization written for a single-user tool. If you centralize MCP servers behind a gateway to simplify config, you have concentrated blast radius, not reduced it.
Source
↳ Follow the thread