Fetching from the wire…
Security2026-09-19 · source-backed
anonymous in its Shiro filter and leaks the whole form schema.** CVE-2026-63646, CVSS 6.9, affects versions before 1.7.2. An unauthenticatedGET /mcp/form/config/{formKey}returns field names, types, required flags, defaults, options, validation rules and binding sources for CRM modules, becauseShiroFilter.addPublicPathFilters` marks the prefix anonymous and the controller carries no permission annotation. NVD A blanket path exemption added so an agent could reach an endpoint made it reachable by everyone.
Each link below shares sources, entities, or timing with this story.
Patched in EE 19.3.1, 19.2.5 and 19.1.7, covering everything from 18.9, CVSS 7.3. An authenticated user with only Developer permissions could get the agent to process configuration they control and execute arbitrary commands inside the CI context (NVD). The blast radius is wha...
CVE-2026-82021 (CVSS 9.0) covers Hermes Agent 0.18.2 through 0.19.0, where the bundled MCP catalog referenced a third-party upstream by branch name rather than commit SHA. Compromise the upstream and your code reaches every host installing that catalog entry, with zero operato...
CVE-2026-19889 and CVE-2026-75871, published August 27, let an authenticated user with Duo access redirect outbound model requests externally, affecting AI Gateway 18.9.0/18.10 through 19.0.12, 19.1 to 19.1.7 and 19.2 to 19.2.2 (NVD). Redirecting the model endpoint sends every...
CVE-2026-75130, published August 18, covers Upstash's Context7 through 2.1.2: the Custom AI Instructions feature serves unsanitized content through the MCP server, so poisoned instructions can exfiltrate credentials from environment files to an attacker-controlled service and...
NVD published this against kazuph/mcp-fetch through 1.6.3 on August 26. isSafeUrl reads the hostname from the parsed URL, which for yields the bracketed string, then tests it with net.isIP, which returns zero for a bracketed value. The entire private-address branch is skipped,...
CVE-2026-44338 (CVSS 7.3) comes from PraisonAI's legacy Flask api_server.py shipping with AUTH_ENABLED=False and AUTH_TOKEN=None, exposing GET /agents and POST /chat to anyone on the network. Sysdig watched a scanner identifying as "CVE-Detector/1.0" hit the exact endpoint und...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.