Fetching from the wire…
Security2026-09-19 · source-backed
CVE-2026-58197, published September 18, affects ToolHive CLI before 0.30.1 and Studio before 0.38.0. Locally run MCP server containers use the default network permission profile with no isolation, so they reach host.docker.internal, while the ToolHive API and MCP proxy endpoints require no authentication. A compromised MCP server uses the Docker gateway to contact host-local services and other ToolHive-managed servers. NVD The container was the thing you thought was the boundary, and it wasn't one.
Each link below shares sources, entities, or timing with this story.
CVE-2026-90474, published September 12 at CVSS 7.6, is an authentication bypass in MCPHub's embedded OAuth 2.0 authorization server: client authentication is off by default and PKCE enforcement is optional (NVD). Two days after the Langflow and ContextForge cluster, the same s...
Your read-only flag is a claim, not a guarantee. Two independent Postgres MCP servers proved it on September 4. Postgres MCP Pro got CVE-2026-85620 at CVSS 9.2. The bug is one line of reasoning in safe_sql.py: the validator checks function names on FuncCall AST nodes. A functi...
Full 10.0. Network vector, low complexity, no authentication, no user interaction, high impact on confidentiality, integrity and availability. CVE-2026-79696, published September 9, is a code injection flaw in adk web affecting Google's Agent Development Kit for Python 2.0.0 t...
Versions before 0.30.0 don't validate filesystem paths in MCP tool arguments, so traversal sequences let an attacker read, create, overwrite and delete any Markdown file the server process can reach. NVD published it September 7 under CWE-22. Upgrade to 0.30.0. This is the fou...
Between September 14 and September 15, NVD published seven entries hitting MCP infrastructure. I read all of them expecting to find something clever. There's nothing clever in any of them. CVE-2026-57124, 9.8, published September 14. PraisonAI's default UI exposes POST /api/mc...
The trick is one line in a file you never read. Manifold Security published eight findings across seven coding agents (Claude Code, Codex, Cursor, Grok Build, Qwen Code, goose, Hermes Agent) that all reduce to the same mechanism. A repository's own .git/config sets core.fsmoni...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.