Fetching from the wire…
Security2026-09-19 · source-backed
All affect versions through v0.22.1. GHSA-xwmw-prc4-v3cr (8.8) accepted unauthenticated OAuth dynamic client registration with an arbitrary external redirect URI and auto-completed the flow with no consent screen, minting a token carrying the victim's full group set against the whole Obot API instead of the one MCP server requested. A second fetches attacker-registered remote MCP server URLs server-side with no destination validation, reaching loopback, RFC1918 and [redacted]. The third: OBOT_SERVER_ENABLE_REGISTRY_AUTH=true never protected /v0.1/*, because the authorizer default-allowed any prefix not on its known-protected list. GitHub Advisory
Each link below shares sources, entities, or timing with this story.
GHSA-9g45-5xwm-f3wc, published September 17, follows the two rmcp advisories from September 16 covering OAuth token theft and a permanent session-table leak. This one is client-side: custom headers set on the MCP client, which in practice carry API keys and bearer tokens, get...
GitHub published four advisories against omnigent-ai/omnigent v0.1.0, the meta-harness that runs Claude Code, Codex and Pi under policy and sandboxing. GHSA-jrrm-9hc7-2v3h at CVSS 9.0 lets any user with session edit rights overwrite a shared template agent via PUT /sessions/{i...
CVE-2026-63127 (8.2) covers crates/rmcp/src/transport/auth.rs omitting the RFC 9728 resource field and never confirming the returned resource identifier matches the configured MCP server, so a hostile server publishes metadata for a different legitimate resource and you finish...
NVD posted nine advisories on August 25, clustering into one shape: a local server assuming a browser can't reach it. PraisonAI validated MCP origins with request_origin.startswith(allowed) against a localhost allowlist, so an attacker-registered localhost.attacker.com passes...
1. OWASP MCP Top 10 Security Audit (Intermediate) Systematically audit your MCP servers against the OWASP MCP Top 10. Download the checklist, inventory all servers, test each against 10 categories (injection, auth bypass, confused deputy), prioritize by CVSS, remediate critica...
StreamableHTTPClientTransport and SSEClientTransport applied caller-supplied headers after the SDK's own. An Authorization placeholder from an environment variable therefore replaced the OAuth token and broke refresh once it expired (PR #2475). The PR names Atlassian Rovo, whe...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.