Fetching from the wire…
Security2026-09-21 · source-backed
CVE-2026-94037 (mcp-file-analyzer, analyze_csv_data, filename), CVE-2026-94044 (03-lovepreetSingh MCP, create_file, filePath/content) and CVE-2026-94046 (ACE-MCP through 4.10.8, get_file_snippet, projectRootPath/filePath) all went up September 20. Three of the six MCP CVEs that day are the same bug in the same place: a tool takes a caller-supplied path and reads or writes it without confining it to a root. Resolve the path, assert the prefix, then touch the filesystem. In that order.
Each link below shares sources, entities, or timing with this story.
Between September 14 and September 15, NVD published seven entries hitting MCP infrastructure. I read all of them expecting to find something clever. There's nothing clever in any of them. CVE-2026-57124, 9.8, published September 14. PraisonAI's default UI exposes POST /api/mc...
The Model Context Protocol has a security problem that's no longer theoretical — it's statistical. Between January and February 2026, researchers filed 30+ CVEs against MCP servers, clients, and infrastructure. One package with nearly 500,000 downloads carried a CVSS 9.6 RCE....
The agent skills supply chain is under coordinated attack. Snyk's ToxicSkills audit found 36% of ClawHub's 3,984 skills contain prompt injection payloads, 13.4% have critical malware, and submission rates exploded 10x to 500+/day. This week alone: CVE-2026-2256 (CVSS 9.1) is a...
Your read-only flag is a claim, not a guarantee. Two independent Postgres MCP servers proved it on September 4. Postgres MCP Pro got CVE-2026-85620 at CVSS 9.2. The bug is one line of reasoning in safe_sql.py: the validator checks function names on FuncCall AST nodes. A functi...
The trick is one line in a file you never read. Manifold Security published eight findings across seven coding agents (Claude Code, Codex, Cursor, Grok Build, Qwen Code, goose, Hermes Agent) that all reduce to the same mechanism. A repository's own .git/config sets core.fsmoni...
Full 10.0. Network vector, low complexity, no authentication, no user interaction, high impact on confidentiality, integrity and availability. CVE-2026-79696, published September 9, is a code injection flaw in adk web affecting Google's Agent Development Kit for Python 2.0.0 t...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.