Fetching from the wire…
Security2026-09-07 · source-backed
CVE-2026-84173 (v0.5.1 through v1.0.1) mis-evaluates multi-segment allow rules whose first path segment is a wildcard, so a workload can send a CompleteStateRequest or UpdateStateRequest with an empty field mask and read or replace state outside its scope (NVD). CVE-2026-85201 is the companion: the agent doesn't bound the declared length of a length-delimited protobuf on the Control Interface FIFO, so a workload forces an unbounded allocation and aborts the agent. If Ankaios is your orchestration layer under agent workloads, the confinement you were relying on is what failed.
Each link below shares sources, entities, or timing with this story.
CVE-2026-54746 (6.4) affects Hatchet from 0.40.0 until 0.91.1: the Dispatcher gRPC service didn't verify that a request's worker ID belonged to the tenant in the bearer-token context, in UpsertWorkerLabels and related calls. Hatchet orchestrates background tasks, AI agents and...
startServer.ts defaulted the listen address to :: when no host was given, so startSseAndStreamableHttpMcpServer exposed both Streamable HTTP and SSE on all interfaces, with authentication middleware applied only when the caller supplied it (NVD). Any unauthenticated client wit...
The http_request and web_fetch agent tools in SiYuan before v3.8.1 validate only the safety-check resolution, so an attacker answers the guard lookup with a public address and the real lookup with an internal one (NVD). The paired CVE-2026-82233 is a path traversal in the asse...
Patched in EE 19.3.1, 19.2.5 and 19.1.7, covering everything from 18.9, CVSS 7.3. An authenticated user with only Developer permissions could get the agent to process configuration they control and execute arbitrary commands inside the CI context (NVD). The blast radius is wha...
VulnCheck disclosed on August 24 that Continue CLI's headless and auto modes give the Bash tool blanket allow permission, leaving isCriticalCommand as the only guard. Its dangerous-path test matches /, ~, /usr, /etc, /bin and /sbin, so recursive deletion of /home, /root, /var,...
CVE-2026-84885, -84886 and -84887 published September 3 against 0.3.1/0.3.2, covering code_agent.py, the OCR HTTP API's ImageData handler via img_bytes, and the model-generated GUI action execution workflow in grounding.py. Same 48-hour window produced the same non-response pa...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.