Fetching from the wire…
Security2026-09-11 · source-backed
Under CVE-2026-89094, variable expansion in a template repo's .forgejo/template files could create a new .git folder, which git then adopted when it initialized the generated repo (LWN). That allowed arbitrary file reads and process execution on the host. The fix deletes any .git folder after expansion, and 15.0.8 includes it too. If you self-host Forgejo with template repos enabled, patch today.
Each link below shares sources, entities, or timing with this story.
Check Point Research disclosed CVE-2025-59536 and CVE-2026-21852 — two vulnerabilities that weaponize Claude Code's project configuration system against its users. This matters because an Agents Anonymous survey this week showed 90% of practitioners at their SF meetup use Clau...
Praetorian's open-source tool validates 6 attack vectors against your MCP servers: prompt injection, RCE, C2, data exfiltration, config manipulation, file execution. Clone, set API key, test, harden. Source: GitHub
NVD, September 4. DocsGPT 0.15.0 and below runs its custom-prompt feature through Jinja with no sanitization or sandbox, so template injection escalates to full code execution with no auth. Any "bring your own system prompt" feature that formats prompts with a real template en...
The Express server on port 3444 calls app.listen with no host argument so it binds all interfaces, sends Access-Control-Allow-Origin: *, requires no auth, and passes the prompt and agentName request-body fields into child_process.spawn with shell: true. Any host on your LAN, o...
The steering committee accepted the policy July 29, declining any legally significant contribution containing or derived from LLM-generated content, using the GNU maintainer threshold of about 15 lines of code and/or text. Trivial LLM-generated changes are acceptable if disclo...
This is the one that should make you check your own setup tonight. June MCP-security roundups flag roughly 12,520 internet-exposed MCP services, about 40% of them with no authentication at all. On top of that, Adversa AI's TrustFall and SymJack research shows that Claude Code,...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.