Fetching from the wire…
Public story · 2026-09-11 · high
Three of the flaws trace to how MCP stdio servers are configured, letting authenticated users run arbitrary OS commands.
Why now: GitHub published its ContextForge advisory on September 11, alongside IBM's bulletin on the Langflow CVEs.
IBM disclosed a critical flaw in Langflow's MCP project endpoints, tracked as CVE-2026-85025. Anyone who can reach a publicly shared Langflow project, no login required, can execute code on it, per IBM's bulletin. The flaw rates 9.8 on CVSS and covers Langflow versions 1.0.0 through 1.11.5.
Two more Langflow CVEs in the same bulletin, 78575 and 81941, let authenticated users run OS commands through the MCP stdio server configuration. CVE-2026-81941 also slips past LANGFLOW_BLOCK_CODE_INTERPRETER, the one setting meant to stop exactly this.
A GitHub advisory published September 11 covers IBM's ContextForge MCP Gateway. It adds a path-traversal RCE, an SSRF, and a bug where API keys keep authorizing flows after the owner's account is deactivated. ContextForge Gateway 1.0.0 through 1.0.7 also ships with default credentials. Upgrading past 1.11.5 closes the Langflow holes; rotating offboarded users' keys closes the ContextForge one.
Seven CVEs across two products in two days share one design flaw, not a coincidence of timing. MCP's stdio transport runs a local process and pipes commands into it. Any project that lets an authenticated user define that command lets them define bash or curl instead of a real tool call. Nothing in the protocol gates who can set it.
Each link below shares sources, entities, or timing with this story.
Your read-only flag is a claim, not a guarantee. Two independent Postgres MCP servers proved it on September 4. Postgres MCP Pro got CVE-2026-85620 at CVSS 9.2. The bug is one line of reasoning in safe_sql.py: the validator checks function names on FuncCall AST nodes. A functi...
Full 10.0. Network vector, low complexity, no authentication, no user interaction, high impact on confidentiality, integrity and availability. CVE-2026-79696, published September 9, is a code injection flaw in adk web affecting Google's Agent Development Kit for Python 2.0.0 t...
GitHub published four advisories against omnigent-ai/omnigent v0.1.0, the meta-harness that runs Claude Code, Codex and Pi under policy and sandboxing. GHSA-jrrm-9hc7-2v3h at CVSS 9.0 lets any user with session edit rights overwrite a shared template agent via PUT /sessions/{i...
The Model Context Protocol has a security problem that's no longer theoretical — it's statistical. Between January and February 2026, researchers filed 30+ CVEs against MCP servers, clients, and infrastructure. One package with nearly 500,000 downloads carried a CVSS 9.6 RCE....
OX Security disclosed a systemic vulnerability on June 16 in core Model Context Protocol implementations that enables arbitrary command execution, exposing API keys, internal databases, and chat histories on any vulnerable MCP host. This isn't one bad server. It's a protocol-l...
Check Point Research disclosed CVE-2025-59536 and CVE-2026-21852 — two vulnerabilities that weaponize Claude Code's project configuration system against its users. This matters because an Agents Anonymous survey this week showed 90% of practitioners at their SF meetup use Clau...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.