Fetching from the wire…
Security2026-09-05 · source-backed
AgentScope through 2.0.7.post1 has a path traversal in LocalWorkspace.add_skill, which copies arbitrary server directories into the agent workspace via an unconfined skill_path parameter (CVE-2026-85685). An attacker names any directory and its files land in the skills directory, which is the one place an agent is designed to read from and trust. Skill installation being a file-copy primitive pointed at the trusted directory is a design problem, not an implementation slip (NVD).
Each link below shares sources, entities, or timing with this story.
The trick is one line in a file you never read. Manifold Security published eight findings across seven coding agents (Claude Code, Codex, Cursor, Grok Build, Qwen Code, goose, Hermes Agent) that all reduce to the same mechanism. A repository's own .git/config sets core.fsmoni...
Your read-only flag is a claim, not a guarantee. Two independent Postgres MCP servers proved it on September 4. Postgres MCP Pro got CVE-2026-85620 at CVSS 9.2. The bug is one line of reasoning in safe_sql.py: the validator checks function names on FuncCall AST nodes. A functi...
CVE-2026-82021 (CVSS 9.0) covers Hermes Agent 0.18.2 through 0.19.0, where the bundled MCP catalog referenced a third-party upstream by branch name rather than commit SHA. Compromise the upstream and your code reaches every host installing that catalog entry, with zero operato...
Published to NVD September 4. An unauthenticated remote attacker reads arbitrary files from any host running Google Cloud ADK for Python 1.9.0 through 1.21.0, via a crafted file_path query parameter on the builder endpoint. Thirteen minor versions in range. If you stood up the...
The http_request and web_fetch agent tools in SiYuan before v3.8.1 validate only the safety-check resolution, so an attacker answers the guard lookup with a public address and the real lookup with an internal one (NVD). The paired CVE-2026-82233 is a path traversal in the asse...
Anthropic invented a file convention. It's now shipping GA inside a competitor's product. Nobody wrote a spec, nobody held a standards meeting, it just happened. On July 29, GitHub made agent skills and MCP server support generally available in Copilot code review for all Pro,...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.