Fetching from the wire…
Security2026-08-28 · source-backed
startServer.ts defaulted the listen address to :: when no host was given, so startSseAndStreamableHttpMcpServer exposed both Streamable HTTP and SSE on all interfaces, with authentication middleware applied only when the caller supplied it (NVD). Any unauthenticated client with network reach gets command execution as the service user, or arbitrary file read and write. A 10.0 in an agent desktop tool is about as bad as this gets.
Each link below shares sources, entities, or timing with this story.
Shared entities / Same source domain / Shared topic / Earlier coverage
Both cover CVE, CVSS, NVD; reported by the same outlet (nvd.nist.gov); overlapping topics (agent, arbitrary, command).
Both cover CVE, CVSS, NVD; reported by the same outlet (nvd.nist.gov); overlapping topics (agent, cvss).
Shared entities / Same source domain / Earlier coverage / Tension
Both cover CVE, CVSS, NVD; reported by the same outlet (nvd.nist.gov); earlier CVE coverage from 2026-08-27.
Shared entities / Shared topic / Earlier coverage
Both cover CVE, CVSS; overlapping topics (agent, arbitrary, authentication, command, cvss); earlier CVE coverage from 2026-02-27.
Both cover CVE, CVSS, NVD; overlapping topics (agent, command, cvss); earlier CVE coverage from 2026-08-09.
Shared entities / Same source domain / Earlier coverage
Both cover CVE, CVSS, NVD; reported by the same outlet (nvd.nist.gov); earlier CVE coverage from 2026-08-25.
Shared entities / Shared topic / Earlier coverage
Both cover CVE, CVSS, SSE; overlapping topics (client, cvss); earlier CVE coverage from 2026-08-07.
Shared entities / Same source domain / Shared topic / Earlier coverage
Both cover CVE, NVD; reported by the same outlet (nvd.nist.gov); overlapping topics (arbitrary, file).