Fetching from the wire…
Security2026-09-23 · source-backed
GitHub published seven lightrag-hku advisories on September 22: an SSRF-guard bypass via NAT64, 6to4 and IPv4-compatible addresses in the image downloader, stored XSS in the chat renderer from ingested documents, and a missing rate limit on /login. The same IPv6-transition bypass hit Cloudreve that day. Any agent or RAG fetch allowlist should be checked for those address forms specifically.
Each link below shares sources, entities, or timing with this story.
CVE-2026-59973: the fix for CVE-2026-39885 added a hostname denylist for OpenAPI external $ref dereferencing, but mcp-from-openapi 2.3.0 still reaches loopback via hostname resolution, redirects, or IPv4-mapped IPv6 syntax. FrontMCP 1.2.1 and current main both pin that depende...
GitHub published four medium-severity vLLM advisories on September 4 against the inference server most self-hosted agent stacks run on. GHSA-pr7f-p5mw-fc87 shows the CVE-2025-62164 remediation can be bypassed using concurrent prompt parts. GHSA-48jh-3gj7-fg8v is a ReDoS throug...
IBM's bulletin lists CVE-2026-85025, rated CVSS 9.8, which allows unauthenticated code execution through publicly shared MCP project endpoints in Langflow 1.0.0 through 1.11.5. CVE-2026-78575 and CVE-2026-81941 let authenticated users run OS commands through the MCP stdio serv...
PR #29081, merged August 26 and in nightly v0.59.0-nightly.20260827, enforces RFC 9728 §7.7 and RFC 8414 constraints across MCP OAuth metadata discovery, dynamic client registration, and token exchange. It requires HTTPS for remote endpoints with HTTP allowed only for loopback...
v2.44.0 fixes an IPv6 zone identifier bypassing the cloud-metadata and private-IP blocklists (GHSA-vmxc-h2x2-jmf3), superlinear HTML conversion and charset decode running on the event loop so one attacker-chosen page stalls every agent in the process (GHSA-fpf4-vwcp-v4hp), dom...
GHSA-9g45-5xwm-f3wc, published September 17, follows the two rmcp advisories from September 16 covering OAuth token theft and a permanent session-table leak. This one is client-side: custom headers set on the MCP client, which in practice carry API keys and bearer tokens, get...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.