Fetching from the wire…
Security2026-09-18 · source-backed
GHSA-9g45-5xwm-f3wc, published September 17, follows the two rmcp advisories from September 16 covering OAuth token theft and a permanent session-table leak. This one is client-side: custom headers set on the MCP client, which in practice carry API keys and bearer tokens, get re-sent to whatever host a cross-origin redirect names. Running the official Rust MCP SDK against a third-party server means treating every redirect as a credential exfiltration channel. Separately, GHSA-hx8v-g79f-8w5f covers SSRF in LiteLLM Proxy through the user_config request parameter. LiteLLM usually has network reach into internal services and cloud metadata endpoints the agent itself does not, so the medium rating understates it depending on where you deployed.
Each link below shares sources, entities, or timing with this story.
CVE-2026-63127 (8.2) covers crates/rmcp/src/transport/auth.rs omitting the RFC 9728 resource field and never confirming the returned resource identifier matches the configured MCP server, so a hostile server publishes metadata for a different legitimate resource and you finish...
Hudson Rock got hold of the archive and counted it. 433,909 files. 118,829 CI runner dumps traced to 2,488 corporate domains. AWS keys, Salesforce client secrets, Slack signing secrets, Azure environment variables, and AI provider API keys belonging to NVIDIA, Volkswagen, Micr...
GitHub published four advisories against omnigent-ai/omnigent v0.1.0, the meta-harness that runs Claude Code, Codex and Pi under policy and sandboxing. GHSA-jrrm-9hc7-2v3h at CVSS 9.0 lets any user with session edit rights overwrite a shared template agent via PUT /sessions/{i...
A standalone macOS and Windows desktop beta released September 14, moving the open-source agent out of the VS Code extension slot; the releases page shows Desktop v0.0.26 on September 11, v0.0.27 on September 13 and v0.0.28 on September 15, so it's shipping daily (GitHub). It...
Your read-only flag is a claim, not a guarantee. Two independent Postgres MCP servers proved it on September 4. Postgres MCP Pro got CVE-2026-85620 at CVSS 9.2. The bug is one line of reasoning in safe_sql.py: the validator checks function names on FuncCall AST nodes. A functi...
1. OWASP MCP Top 10 Security Audit (Intermediate) Systematically audit your MCP servers against the OWASP MCP Top 10. Download the checklist, inventory all servers, test each against 10 categories (injection, auth bypass, confused deputy), prioritize by CVSS, remediate critica...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.