Fetching from the wire…
Security2026-09-25 · source-backed
NVD published CVE-2026-51994 through 51997 and CVE-2026-52001 on September 24 against geelen/mcp-remote, the stdio-to-remote MCP bridge a lot of clients depend on. The set covers SSRF through the resource_metadata URL in a server's WWW-Authenticate header, arbitrary code execution through getServerUrlHash and through the browser open() path, plus information leaks in OAuth metadata handling and the SSE fetch wrapper. They trace back to a seven-advisory OAuth trust-boundary review disclosed July 31. (NVD) The ownership detail matters as much as the CVEs: npm shows 0.1.39 and 0.2.0 from geelen in August, then from 0.10.0 on September 11 the package points at punkpeye/mcp-remote, now at 0.14.3. Anyone pinning mcp-remote in an MCP config should drop 0.1.38 and older, and should also confirm they're comfortable with who publishes it now.
Each link below shares sources, entities, or timing with this story.
NVD published CVE-2026-79743 through 79750 between 18:17:19 and 18:17:20 UTC on August 31, all against the same MCP aggregator (NVD). CVE-2026-79748 lets any authenticated non-admin POST to /api/servers with arbitrary command and args, which MCPHub hands straight to child_proc...
Your read-only flag is a claim, not a guarantee. Two independent Postgres MCP servers proved it on September 4. Postgres MCP Pro got CVE-2026-85620 at CVSS 9.2. The bug is one line of reasoning in safe_sql.py: the validator checks function names on FuncCall AST nodes. A functi...
NVD published 28 CVEs against sooperset/mcp-atlassian on September 22, all fixed in 0.22.0 back in July. CVE-2026-77244 lets the HTTP transport accept requests with no verified identity and fall back to the operator's global Jira and Confluence credentials. Others cover upload...
CVE-2026-90474, published September 12 at CVSS 7.6, is an authentication bypass in MCPHub's embedded OAuth 2.0 authorization server: client authentication is off by default and PKCE enforcement is optional (NVD). Two days after the Langflow and ContextForge cluster, the same s...
Between September 14 and September 15, NVD published seven entries hitting MCP infrastructure. I read all of them expecting to find something clever. There's nothing clever in any of them. CVE-2026-57124, 9.8, published September 14. PraisonAI's default UI exposes POST /api/mc...
Anthropic's new permanent level indexes to 125 against a 100 baseline, but subscribers have been running at 150 since a temporary 50% boost announced May 13 was extended past July 13, July 19, August 31 and September 13. Both "25% up" and "17% down" are true from different ref...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.