Fetching from the wire…
Security2026-09-16 · source-backed
GHSA-5648-rgj9-v224 at CVSS 8.1 documents the safety controls operators actually depend on, and each one has a hole: a GraphQL query starting with a comma slips past the write-detection regex, execute_graphql never checks GITLAB_ALLOWED_PROJECT_IDS at all, --cookie-path/--use-oauth skips the auth gate while still attaching live credentials upstream, about 1,000 trivial requests exhaust the session pool, and CI job traces reach the model verbatim. Two companion criticals at 9.6 cover header-based SSRF leaking the Private-Token and DNS rebinding into the local transport. The package has 200,000+ downloads. Fixes are in 2.1.27 and 2.1.30.
Each link below shares sources, entities, or timing with this story.
On August 25 the advisory database published 20 advisories against PraisonAI and praisonaiagents: 1 critical, 15 high, 4 medium. The recurring pattern is authentication that's declared but never enforced. praisonai serve agents --api-key is silently ignored. AgentServer declar...
Your read-only flag is a claim, not a guarantee. Two independent Postgres MCP servers proved it on September 4. Postgres MCP Pro got CVE-2026-85620 at CVSS 9.2. The bug is one line of reasoning in safe_sql.py: the validator checks function names on FuncCall AST nodes. A functi...
CVE-2026-59973: the fix for CVE-2026-39885 added a hostname denylist for OpenAPI external $ref dereferencing, but mcp-from-openapi 2.3.0 still reaches loopback via hostname resolution, redirects, or IPv4-mapped IPv6 syntax. FrontMCP 1.2.1 and current main both pin that depende...
GHSA-2cp2-2r3c-7p7r (CVE-2026-68508, CVSS 7.8) covers hydra.utils.instantiate() resolving and calling whatever _target_ names. Hydra isn't a network service, so you need an app that loads attacker-controlled config, CLI overrides, or model metadata. That last path is the one t...
CVE-2026-59971: with MCP_TRANSPORT=sse the server builds SseServerTransport without security_settings, so the MCP Python SDK's DNS-rebinding protection defaults off, there's no CORS or TrustedHost middleware, all three routes are unauthenticated, and it binds 0.0.0.0. Any netw...
IBM's bulletin lists CVE-2026-85025, rated CVSS 9.8, which allows unauthenticated code execution through publicly shared MCP project endpoints in Langflow 1.0.0 through 1.11.5. CVE-2026-78575 and CVE-2026-81941 let authenticated users run OS commands through the MCP stdio serv...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.