Fetching from the wire…
Security2026-09-21 · source-backed
CVE-2026-94047 hits importTemplate in src/services/templateService.ts, remotely exploitable with a public exploit. Upgrading past 1.0.32 fixes it. MCPHub fronts multiple MCP servers, so a privilege flaw in its template import has a bigger blast radius than the single-server CVEs that dominate this beat. A hub is a trust concentrator, and template import is exactly where you'd attack one.
Each link below shares sources, entities, or timing with this story.
NVD posted nine advisories on August 25, clustering into one shape: a local server assuming a browser can't reach it. PraisonAI validated MCP origins with request_origin.startswith(allowed) against a localhost allowlist, so an attacker-registered localhost.attacker.com passes...
NVD's September 16-18 window added CVE-2026-54618 (Obsidian Web MCP before 0.2.0 issues an OAuth authorization code with no login or consent check, then exchanges it for the static VAULT_MCP_TOKEN), CVE-2026-54504 (MCP Documentation Server 1.13.0 calls app.listen(3080) with no...
CVE-2026-90898, published today, covers Maxim's Bifrost LLM gateway. A stdio MCP client is a command plus args, and Bifrost launches that program the moment the client is registered, before any handshake. governance.auth_config.is_enabled defaults to false, so a single unauthe...
CVE-2026-90474, published September 12 at CVSS 7.6, is an authentication bypass in MCPHub's embedded OAuth 2.0 authorization server: client authentication is off by default and PKCE enforcement is optional (NVD). Two days after the Langflow and ContextForge cluster, the same s...
Your read-only flag is a claim, not a guarantee. Two independent Postgres MCP servers proved it on September 4. Postgres MCP Pro got CVE-2026-85620 at CVSS 9.2. The bug is one line of reasoning in safe_sql.py: the validator checks function names on FuncCall AST nodes. A functi...
The agent skills supply chain is under coordinated attack. Snyk's ToxicSkills audit found 36% of ClawHub's 3,984 skills contain prompt injection payloads, 13.4% have critical malware, and submission rates exploded 10x to 500+/day. This week alone: CVE-2026-2256 (CVSS 9.1) is a...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.