Fetching from the wire…
Security2026-08-30 · source-backed
CVE-2026-81835 hits fetch_instructions via a malicious MCP server in versions through 3.51.1. The exploit is public. GitHub's advisory GHSA-q2jq-8pm2-fj8h rates it low, NVD scores it 5.5 MEDIUM. (NVD) If your upgrade gating reads GHSA severity only, this one slips through.
Each link below shares sources, entities, or timing with this story.
Anthropic released MCP / Shared entities / Shared topic / Earlier coverage / Tension
Linked by a graph relationship (Anthropic released MCP); both cover CVE, MCP; overlapping topics (code, injection).
Claude uses MCP / Shared entities / Shared topic / Earlier coverage / Tension
Linked by a graph relationship (Claude uses MCP); both cover CVE, GitHub; overlapping topics (code, exploit).
Anthropic released MCP / Shared entities / Earlier coverage
Linked by a graph relationship (Anthropic released MCP); both cover CVE, GitHub, MCP; earlier CVE coverage from 2026-08-21.
Claude uses MCP / Shared entities / Earlier coverage
Linked by a graph relationship (Claude uses MCP); both cover Code, GitHub, MCP; earlier Code coverage from 2026-08-16.
Claude Code uses MCP / Shared entities / Earlier coverage
Linked by a graph relationship (Claude Code uses MCP); both cover Code, GitHub, MCP; earlier Code coverage from 2026-02-28.
Anthropic released MCP / Shared entities / Shared topic / Earlier coverage
Linked by a graph relationship (Anthropic released MCP); both cover GitHub, MCP; overlapping topics (code, through).
Cloudflare supports MCP / Shared entities / Shared topic / Earlier coverage
Linked by a graph relationship (Cloudflare supports MCP); both cover CVE, MCP; overlapping topics (code, public).
Codex uses MCP / Shared entities / Shared topic / Earlier coverage
Linked by a graph relationship (Codex uses MCP); both cover CVE, MCP; overlapping topics (code, maliciou).