AgentsVulnerable MCP Project Catalogs Critical CVEsVulnerable MCP Project·high signalXBlueskyLinkedInCopy linkvulnerablemcp.info catalogs CVE-2026-25536 TypeScript SDK cross-client leak, CVE-2026-23744 MCPJam RCE, chained mcp-server-git CVEs. Adversa AI MCP Security TOP 25 most comprehensive taxonomy.SourceSource pageVulnerable MCP Project↳ Follow the threadStack layer / Threat patternHermes Agent Shipped an MCP Catalog Pinned to a Mutable Branch, Turning Any Upstream Compromise Into RCE (CVE-2026-82021, 9.0)NVDStack layer / Threat patternCodex rust-v0.151.0 Lets Extensions Inspect or Replace MCP Tool Results Before the Model Sees ThemGitHubStack layer / Threat patternJetBrains Failed to Patch Its Own TeamCity Server and Its Cadence Cloud Coding Service Leaked Customer Source Code and Cloud CredentialsJetBrains Blog (corroborated by The New Stack, 2026-08-28)Stack layer / Threat patternPromptfoo adds a Codex Security SDK provider and hardens its code-scan GitHub Action supply chainGitHubStack layer / Threat patternClaude Code Now Requires Approval for Settings That Terminate Sandbox TLS or Inject Credential HeadersClaude Code ChangelogPolicy dependency / Stack layerZero data retention, not price, is what stalled Fable 5 adoptionJamin Ball (Clouded Judgment)Threat pattern / ContrastOCaml maintainer sees traversal probes ten minutes after opening a fix PR, and rclone logs 40 disclosures in a monthAnil Madhavapeddy, via Simon Willison and Hacker News (339 points)Stack layer / Threat patternRoo-Code up to 3.51.1 has a code-injection hole in its MCP integration trust model, disclosed publicly and scored only 5.5NVD