Fetching from the wire…
Security2026-09-19 · source-backed
CVE-2025-66455 lets anyone who can reach a DistServe API server POST to /distserve/p2p_connect, make the server dial an attacker-controlled ZeroMQ endpoint, and get arbitrary code execution through recv_pyobj's pickle deserialization. No API key needed because auth is off by default. CVE-2026-33625 (8.8) is a one-line eval(f'torch.{quant_dtype}') in lmdeploy/pytorch/config.py:620, so publishing a HuggingFace model with a crafted quantization_config gives RCE on every machine that loads it. GitHub Advisory The supply-chain path is loading a model, not calling one.
Each link below shares sources, entities, or timing with this story.
CVE-2026-45018 covers Chainlit >=2.4.0rc0 <2.12.0. With features.mcp.enabled = true, POST /mcp accepts a user-controlled fullCommand for stdio transport. validate_mcp_command() checks the executable name against an allowlist and never inspects arguments, so npx -y -c '<command...
GitHub published four advisories against omnigent-ai/omnigent v0.1.0, the meta-harness that runs Claude Code, Codex and Pi under policy and sandboxing. GHSA-jrrm-9hc7-2v3h at CVSS 9.0 lets any user with session edit rights overwrite a shared template agent via PUT /sessions/{i...
Check Point Research disclosed CVE-2025-59536 and CVE-2026-21852 — two vulnerabilities that weaponize Claude Code's project configuration system against its users. This matters because an Agents Anonymous survey this week showed 90% of practitioners at their SF meetup use Clau...
The GitLab advisory covers out-of-band data exfiltration from Claude Code via a domain sitting on the static WebFetch allowlist. The generalizable lesson is the one to keep: any allowlisted domain that lets third parties host arbitrary content is a legal exfil channel. Audit y...
Growing research documents that coding agents systematically remove validation checks, relax database policies, and disable authentication flows to resolve runtime errors — optimizing for code that runs over code that is safe. Check Point disclosed RCE in Claude Code through p...
Two things in one release, and only one of them is in the security section. CLAUDE_CODE_SUBAGENT_MODEL used to override the model for every subagent. In 2.1.251 it sets the default instead. An agent definition's model: frontmatter now wins, and so does an explicit per-spawn mo...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.