Fetching from the wire…
Security2026-09-23 · source-backed
CVE-2026-95660 covers Moonshot AI Kimi Code through 0.31.0, where the MCP config loader spawned servers from a workspace's .mcp.json with no trust prompt. Opening a repo was OS command injection. The 0.31.1 fix adds a prompt and resolves fd and stty to absolute paths so a workspace can't plant bare-name executables on $PATH. NVD notes a public exploit exists. Moonshot archived kimi-cli the same week and turned its entry points into a Kimi Code installer, so check what version you got after the migration.
Each link below shares sources, entities, or timing with this story.
The trick is one line in a file you never read. Manifold Security published eight findings across seven coding agents (Claude Code, Codex, Cursor, Grok Build, Qwen Code, goose, Hermes Agent) that all reduce to the same mechanism. A repository's own .git/config sets core.fsmoni...
CVE-2026-90898, published today, covers Maxim's Bifrost LLM gateway. A stdio MCP client is a command plus args, and Bifrost launches that program the moment the client is registered, before any handshake. governance.auth_config.is_enabled defaults to false, so a single unauthe...
CVE-2026-90474, published September 12 at CVSS 7.6, is an authentication bypass in MCPHub's embedded OAuth 2.0 authorization server: client authentication is off by default and PKCE enforcement is optional (NVD). Two days after the Langflow and ContextForge cluster, the same s...
Between September 14 and September 15, NVD published seven entries hitting MCP infrastructure. I read all of them expecting to find something clever. There's nothing clever in any of them. CVE-2026-57124, 9.8, published September 14. PraisonAI's default UI exposes POST /api/mc...
Oren Yomtov of Accomplish AI disclosed two Codex sandbox escapes on September 20, and the first one bothers me more than any agent CVE I've read this month. BleepingComputer has the writeup. Heapjack abuses node_repl, a helper that Codex Desktop writes into the global ~/.codex...
Patched in EE 19.3.1, 19.2.5 and 19.1.7, covering everything from 18.9, CVSS 7.3. An authenticated user with only Developer permissions could get the agent to process configuration they control and execute arbitrary commands inside the CI context (NVD). The blast radius is wha...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.