MCP and agent packages
The packages that advisories about the Model Context Protocol and AI agents name, with what the Exposure Registry knows about each one: the LLM components it declares and the authority its dependencies grant (shell, files, browser, network, code execution).
Advisories are grouped by topic. The Model Context Protocol view counts the records that match that topic, and the AI agents view counts those that match the AI agents or the agent-to-agent protocols topic. Package names are those the advisory source lists. How authority is measured
- Advisories
- 160
- Critical or high
- 106
- Packages named
- 44
- Advisories listed as exploited (CISA KEV)
- 0
51 advisories were published in the last 90 days and 37 in the 90 days before. 74 of the 160 name no package, because their source lists none.
Advisories by month of publication
| Month | Items |
|---|---|
| May 2025 | 1 |
| Jun 2025 | 4 |
| Jul 2025 | 2 |
| Aug 2025 | 5 |
| Sep 2025 | 10 |
| Oct 2025 | 4 |
| Nov 2025 | 3 |
| Dec 2025 | 4 |
| Jan 2026 | 6 |
| Feb 2026 | 14 |
| Mar 2026 | 13 |
| Apr 2026 | 9 |
| May 2026 | 24 |
| Jun 2026 | 4 |
| Jul 2026 | 17 |
| Aug 2026 | 17 |
| Sep 2026 | 17 |
| Oct 2026 | 4 |
Latest advisories
- CriticalCVE-2026-108263: Astron Agent code-node execution as root through workflow run endpoints2026-10-09
- LowCVE-2026-107288: Pydantic AI web fetch bypasses blocked_domains via hostname variants2026-10-08
- HighCVE-2026-107286: Pydantic AI streamed requests leak concurrency slots, causing denial of service2026-10-08
- HighCVE-2026-82627: Uncanny Automator WordPress plugin PHP object injection via deserialization2026-10-08
- HighCVE-2026-55157: Token Optimizer MCP OS command injection through smart_user username argument2026-09-28
- MediumCVE-2026-55156: Token Optimizer MCP dashboard path traversal via sessionId in session endpoints2026-09-28
- CriticalCVE-2026-101065: Obot Docker quickstart exposes admin access without authentication2026-09-27
- HighCVE-2026-84462: Zammad security filter bypass in AI Agent configuration fields2026-09-25
Authority in the registry
282 registry packages declare an agent framework. Their dependencies grant:
- Outbound HTTP105Makes outbound requests, the precondition for server-side request forgery and exfiltration.
- MCP tools49Exposes or calls Model Context Protocol tools, which pass authority between agents and servers.
- File system23Reads or writes files, so path traversal and data exposure are in reach.
- Browser control16Drives a browser, so it can act on websites with the user's sessions.
- Code execution14Runs code it is given, so injected instructions can become arbitrary code.
- Shell commands4Starts processes on the host, the most direct path from a prompt to the operating system.
Advisories that name @anthropic-ai/claude-code
Closenpm. Every record that names the package, on any topic, newest first. RSS feed for this package
- HighCVE-2026-55607: Claude Code worktree handling allows sandbox escape via git directory confusion2026-06-29
- MediumGHSA-4vp2-6q8c-pvq2: @anthropic-ai/claude-code has an Insecure Temporary File in /copy Command that Enables Response Disclosure and Symlink-Based File Write2026-06-25
- MediumGHSA-fg94-h982-f3mm: Claude Code: Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetch2026-06-17
- HighGHSA-q5hj-mxqh-vv77: Claude Code: Trust Dialog Bypass via Git Worktree Spoofing Allows Arbitrary Code Execution2026-04-24
- HighCVE-2026-39861: Claude Code sandbox escape through symlinks outside the workspace2026-04-21
- MediumGHSA-5cwg-9f6j-9jvx: Claude Code: Insecure System-Wide Configuration Loading Enables Local Privilege Escalation on Windows2026-04-17
- HighGHSA-mmgp-wc2j-qcv7: Claude Code has a Workspace Trust Dialog Bypass via Repo-Controlled Settings File2026-03-19
- CriticalCVE-2026-25725: Claude Code bubblewrap sandbox escape by creating settings.json2026-02-06
- HighCVE-2026-25724: Claude Code deny rules bypassed through symbolic links2026-02-06
- MediumCVE-2026-25723: Claude Code file write restriction bypass via piped sed and echo commands2026-02-06
- CriticalCVE-2026-25722: Claude Code write protection bypass via cd into protected directories2026-02-06
- HighCVE-2026-24887: Claude Code confirmation prompt bypass via find command2026-02-03
- MediumCVE-2026-24053: Claude Code Bash validation flaw in ZSH clobber syntax allows file writes2026-02-03
- HighCVE-2026-24052: Claude Code WebFetch trusted domain check bypass via startsWith validation2026-02-03
- HighCVE-2026-21852: Claude Code project-load flow leaks API keys before trust prompt2026-01-22
- CriticalCVE-2025-66032: Claude Code command injection via shell parsing of $IFS and short flags2025-12-03
- CriticalCVE-2025-64755: Claude Code read-only validation bypass via sed command parsing2025-11-21
- CriticalCVE-2025-65099: Claude Code code execution via Yarn plugins in untrusted directories2025-11-19
- MediumCVE-2025-59829: Claude Code permission deny rules bypassed via symlinks2025-10-03
- HighCVE-2025-59536: Claude Code code injection through startup trust dialog2025-10-03
- CriticalCVE-2025-59828: Claude Code trust dialog bypass through Yarn plugin auto-execution2025-09-24
- CriticalCVE-2025-59041: Claude Code code execution via malicious git user email before workspace trust2025-09-10
- CriticalCVE-2025-58764: Claude Code confirmation prompt bypass through command parsing error2025-09-10
- HighCVE-2025-55284: Claude Code confirmation prompt bypass allows network file exfiltration2025-08-16
- CriticalCVE-2025-54795: Claude Code command parsing flaw bypasses confirmation prompt2025-08-05
- CriticalCVE-2025-54794: Claude Code path validation flaw exposes files outside working directory2025-08-05
- HighCVE-2025-52882: Claude Code IDE extensions allow unauthorized websocket connections2025-06-24
Packages named in advisories
44 packages
| Package | Advisories | Highest severity | Latest advisory | Exploited | Authority |
|---|---|---|---|---|---|
| @anthropic-ai/claude-codenpm | 22 | Critical | Not in the registry | ||
| github.com/pinchtab/pinchtabGo | 6 | High | Not in the registry | ||
| github.com/hatchet-dev/hatchetGo | 5 | Medium | Not in the registry | ||
| pydantic-aiPyPI | 4 | High | None detected | ||
| pydantic-ai-slimPyPI | 4 | High | Outbound HTTP | ||
| omnigentPyPI | 4 | Critical | Not in the registry | ||
| n8nnpm | 4 | High | Code execution, File system, MCP tools, Shell commands | ||
| @evomap/evolvernpm | 3 | Critical | Not in the registry | ||
| github.com/pinchtab/pinchtab/cmd/pinchtabGo | 3 | High | Not in the registry | ||
| @ooples/token-optimizer-mcpnpm | 2 | High | Not in the registry | ||
| @agenticmail/corenpm | 2 | High | Not in the registry | ||
| @agenticmail/apinpm | 2 | High | Not in the registry | ||
| apm-cliPyPI | 2 | High | Not in the registry | ||
| @paperclipai/servernpm | 2 | Critical | Not in the registry | ||
| @enclave-vm/corenpm | 2 | Critical | Not in the registry | ||
| enclave-vmnpm | 2 | Critical | Not in the registry | ||
| opencode-ainpm | 2 | High | Not in the registry | ||
| neuron-core/neuron-aicomposer | 2 | Critical | Not in the registry | ||
| hatchetGo | 1 | High | Not in the registry | ||
| hatchet-dev/hatchetGo | 1 | Medium | Not in the registry | ||
| @andrea9293/mcp-documentation-servernpm | 1 | High | Not in the registry | ||
| @apify/actors-mcp-servernpm | 1 | High | Not in the registry | ||
| @trigger.dev/corenpm | 1 | High | Not in the registry | ||
| @jshookmcp/jshooknpm | 1 | Medium | Not in the registry | ||
| n8nEcosystem not stated | 1 | High | Not in the registry | ||
| @agenticmail/claudecodenpm | 1 | High | Not in the registry | ||
| @agenticmail/codexnpm | 1 | High | Not in the registry | ||
| @agenticmail/openclawnpm | 1 | High | Not in the registry | ||
| agentic-flownpm | 1 | High | Not in the registry | ||
| @agenticmail/mcpnpm | 1 | High | Not in the registry | ||
| praisonaiPyPI | 1 | Critical | Not in the registry | ||
| github.com/safedep/gryphGo | 1 | Medium | Not in the registry | ||
| @yoda.digital/gitlab-mcp-servernpm | 1 | Critical | Not in the registry | ||
| apmPyPI | 1 | High | Not in the registry | ||
| paperclipainpm | 1 | Critical | Not in the registry | ||
| agixtPyPI | 1 | High | Not in the registry | ||
| openclawnpm | 1 | High | Not in the registry | ||
| langflowPyPI | 1 | Critical | None detected | ||
| github.com/agentgateway/agentgatewayGo | 1 | Medium | Not in the registry | ||
| microsoft-semantickernel-corenuget | 1 | Critical | Not in the registry | ||
| semantic-kernelPyPI | 1 | Critical | Outbound HTTP, MCP tools | ||
| @mastra/mcp-docs-servernpm | 1 | Medium | Not in the registry | ||
| @openai/codexnpm | 1 | High | Not in the registry | ||
| khojPyPI | 1 | Medium | Code execution, Outbound HTTP |
Topics are assigned by matching a record's title and summary against published patterns, so an advisory that never uses the words is missed and one that mentions them in passing is counted. An advisory that names several packages counts once for each. A package is listed with the ecosystem its advisory source states, and by name alone when the source states none.
Authority is read from the dependencies a package's latest release declares, and it is known only for packages the Exposure Registry tracks. It shows what a package's dependencies can do on the host. It does not show that a model is given that reach. Severity comes from the source advisory when it gives one, otherwise from the classifier. Dates are in UTC.