Fetching from the wire…
Security2026-09-04 · source-backed
Published to NVD September 4. An unauthenticated remote attacker reads arbitrary files from any host running Google Cloud ADK for Python 1.9.0 through 1.21.0, via a crafted file_path query parameter on the builder endpoint. Thirteen minor versions in range. If you stood up the ADK builder UI on a reachable interface, treat every secret on that host as read. NVD
Each link below shares sources, entities, or timing with this story.
NVD posted nine advisories on August 25, clustering into one shape: a local server assuming a browser can't reach it. PraisonAI validated MCP origins with request_origin.startswith(allowed) against a localhost allowlist, so an attacker-registered localhost.attacker.com passes...
Google's Agent Development Kit for Python listed litellm>=1.75.5 as an optional dependency. No upper bound. No pin. During the week of March 24, LiteLLM versions 1.82.7 and 1.82.8 were compromised by the TeamPCP group with a three-stage payload: credential harvesting, Kubernet...
Published to NVD September 1, affecting Codex CLI on Windows, macOS and Linux plus Codex Desktop. The command-safety parser read PowerShell's stop-parsing token differently than PowerShell does, so commands got misclassified as safe. An attacker-prepared repository could get C...
Published to NVD and GitHub Security Advisories on August 27, this is a traversal in read_context in src/index.ts of bsmi021 mcp-file-context-server 1.0.0, remotely exploitable via the path argument, rated 5.5 MEDIUM (NVD). NVD's text notes the project was informed early throu...
On June 24, the two unveiled the Assurance Center suite: six specialized Gemini agents (router, event triage, KPI selector, anomaly reasoner, remediation, dashboard-generation) under an orchestration layer, with router and triage already in production at Nokia. Built on Google...
CVE-2026-81845, published August 28 at 6.3, covers arben-adm mcp-sequential-thinking through 0.5.0, where import_session and export_session accept a caller-supplied path with no boundary validation. Exploit is public. (NVD) Save and load is the most common place a path paramet...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.