NewsMCP Server Security Audit 14 Critical High Findings Across 194 PackagesDEV Community·high signalXBlueskyLinkedInCopy linkAgentAudit audited 194 MCP packages. 14 critical/high findings including command injection and credential leakage.SourceSource pageDEV Community↳ Follow the threadShared entity / Policy dependencyMicrosoft Agent Framework dotnet-1.21.0 lands four breaking changes at once, including limiting MCP skill archives to ZIPGitHubPolicy dependency / Stack layerPattern: four coding-agent CLIs shipped sandbox or trust work in the same weekGitHubStack layer / Threat patternAgentsDock Open-Sources an IDE That Collapses Termius, Cursor and Claude Code Into One DockAgentsDock (surfaced on Hacker News item 49678435)Policy dependency / Stack layerSGLang Hit With Unauthenticated Pickle RCE via /update_weights_from_tensor, the Fourth Critical Inference-Stack CVE in Four WeeksCERT Coordination CenterStack layer / Threat patternElva Launches Against Postman With Flat Workspace Pricing and Specs Generated From Repo CommitsElva (surfaced via the Product Hunt daily leaderboard for 2026-09-14)Policy dependency / Stack layerAgent Framework stops forwarding headers across redirects and revalidates file skill paths before useGitHubStack layer / Threat patternUnlearning Methods That Pass TOFU and MUSE Still Leak the Secret on 22-86% of Queries Once the Model Is an AgentarXiv 2609.12808Stack layer / Threat patternGemini CLI ships an external-context processor to stop indirect prompt injection through build filesGitHub