Fetching from the wire…
Security2026-09-23 · source-backed
NVD published 28 CVEs against sooperset/mcp-atlassian on September 22, all fixed in 0.22.0 back in July. CVE-2026-77244 lets the HTTP transport accept requests with no verified identity and fall back to the operator's global Jira and Confluence credentials. Others cover upload_attachment reading arbitrary server files, DNS-rebinding SSRF, ENABLED_TOOLS not re-checked at tools/call time, and plaintext OAuth token files. The bugs aren't new. The public disclosure is. Any shared HTTP deployment pinned below 0.22.0 is exposed right now, and current is 0.23.1.
Each link below shares sources, entities, or timing with this story.
Between September 14 and September 15, NVD published seven entries hitting MCP infrastructure. I read all of them expecting to find something clever. There's nothing clever in any of them. CVE-2026-57124, 9.8, published September 14. PraisonAI's default UI exposes POST /api/mc...
The trick is one line in a file you never read. Manifold Security published eight findings across seven coding agents (Claude Code, Codex, Cursor, Grok Build, Qwen Code, goose, Hermes Agent) that all reduce to the same mechanism. A repository's own .git/config sets core.fsmoni...
PromptArmor went public August 5 (248 points on HN) after Atlassian went silent. Rovo's URL-retrieval tool has no protection against URLs the agent itself generates, so indirect prompt injection reaches anything behind its connectors. Disabling web search doesn't help: it remo...
NVD's September 16-18 window added CVE-2026-54618 (Obsidian Web MCP before 0.2.0 issues an OAuth authorization code with no login or consent check, then exchanges it for the static VAULT_MCP_TOKEN), CVE-2026-54504 (MCP Documentation Server 1.13.0 calls app.listen(3080) with no...
Your read-only flag is a claim, not a guarantee. Two independent Postgres MCP servers proved it on September 4. Postgres MCP Pro got CVE-2026-85620 at CVSS 9.2. The bug is one line of reasoning in safe_sql.py: the validator checks function names on FuncCall AST nodes. A functi...
NVD published CVE-2026-79743 through 79750 between 18:17:19 and 18:17:20 UTC on August 31, all against the same MCP aggregator (NVD). CVE-2026-79748 lets any authenticated non-admin POST to /api/servers with arbitrary command and args, which MCPHub hands straight to child_proc...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.