MCP and agent packages
The packages that advisories about the Model Context Protocol and AI agents name, with what the Exposure Registry knows about each one: the LLM components it declares and the authority its dependencies grant (shell, files, browser, network, code execution).
Advisories are grouped by topic. The Model Context Protocol view counts the records that match that topic, and the AI agents view counts those that match the AI agents or the agent-to-agent protocols topic. Package names are those the advisory source lists. How authority is measured
- Advisories
- 160
- Critical or high
- 106
- Packages named
- 44
- Advisories listed as exploited (CISA KEV)
- 0
51 advisories were published in the last 90 days and 37 in the 90 days before. 74 of the 160 name no package, because their source lists none.
Advisories by month of publication
| Month | Items |
|---|---|
| May 2025 | 1 |
| Jun 2025 | 4 |
| Jul 2025 | 2 |
| Aug 2025 | 5 |
| Sep 2025 | 10 |
| Oct 2025 | 4 |
| Nov 2025 | 3 |
| Dec 2025 | 4 |
| Jan 2026 | 6 |
| Feb 2026 | 14 |
| Mar 2026 | 13 |
| Apr 2026 | 9 |
| May 2026 | 24 |
| Jun 2026 | 4 |
| Jul 2026 | 17 |
| Aug 2026 | 17 |
| Sep 2026 | 17 |
| Oct 2026 | 4 |
Latest advisories
- CriticalCVE-2026-108263: Astron Agent code-node execution as root through workflow run endpoints2026-10-09
- LowCVE-2026-107288: Pydantic AI web fetch bypasses blocked_domains via hostname variants2026-10-08
- HighCVE-2026-107286: Pydantic AI streamed requests leak concurrency slots, causing denial of service2026-10-08
- HighCVE-2026-82627: Uncanny Automator WordPress plugin PHP object injection via deserialization2026-10-08
- HighCVE-2026-55157: Token Optimizer MCP OS command injection through smart_user username argument2026-09-28
- MediumCVE-2026-55156: Token Optimizer MCP dashboard path traversal via sessionId in session endpoints2026-09-28
- CriticalCVE-2026-101065: Obot Docker quickstart exposes admin access without authentication2026-09-27
- HighCVE-2026-84462: Zammad security filter bypass in AI Agent configuration fields2026-09-25
Authority in the registry
282 registry packages declare an agent framework. Their dependencies grant:
- Outbound HTTP105Makes outbound requests, the precondition for server-side request forgery and exfiltration.
- MCP tools49Exposes or calls Model Context Protocol tools, which pass authority between agents and servers.
- File system23Reads or writes files, so path traversal and data exposure are in reach.
- Browser control16Drives a browser, so it can act on websites with the user's sessions.
- Code execution14Runs code it is given, so injected instructions can become arbitrary code.
- Shell commands4Starts processes on the host, the most direct path from a prompt to the operating system.
Advisories that name openclaw
Closenpm. Every record that names the package, on any topic, newest first. RSS feed for this package
- MediumGHSA-gfg9-5357-hv4c: OpenClaw: Webchat audio embedding could read local files without local-root containment2026-04-29
- HighGHSA-66r7-m7xm-v49h: OpenClaw: QQBot media tags could read arbitrary local files through reply text2026-04-17
- HighGHSA-vfp4-8x56-j7c5: OpenClaw: Exec environment denylist missed high-risk interpreter startup variables2026-04-17
- MediumCVE-2026-35651: OpenClaw ANSI escape sequence injection in approval prompts2026-04-10
- LowGHSA-cm8v-2vh9-cxf3: OpenClaw: GIT_DIR and related git plumbing env vars missing from exec env denylist (GHSA-m866-6qv5-p2fg variant)2026-04-09
- MediumGHSA-3vvq-q2qc-7rmp: OpenClaw B-M3: ClawHub package downloads are not enforced with integrity verification2026-04-09
- MediumGHSA-67mf-f936-ppxf: OpenClaw `node.pair.approve` placed in `operator.write` scope instead of `operator.pairing` allows unprivileged pairing approval2026-04-09
- MediumGHSA-5h3f-885m-v22w: OpenClaw: Existing WS sessions survive shared gateway token rotation2026-04-09
- MediumGHSA-68x5-xx89-w9mm: OpenClaw: resolvedAuth closure becomes stale after config reload2026-04-09
- MediumGHSA-cmfr-9m2r-xwhq: OpenClaw `node.invoke(browser.proxy)` bypasses `browser.request` persistent profile-mutation guard2026-04-09
- MediumGHSA-whf9-3hcx-gq54: OpenClaw `device.token.rotate` mints tokens for unapproved roles, bypassing device role-upgrade pairing2026-04-09
- HighGHSA-7437-7hg8-frrw: OpenClaw: HGRCPATH, CARGO_BUILD_RUSTC_WRAPPER, RUSTC_WRAPPER, and MAKEFLAGS missing from exec env denylist — RCE via build tool env injection (GHSA-cm8v-2vh9-cxf3 class)2026-04-09
- MediumGHSA-jj6q-rrrf-h66h: OpenClaw: Shared-secret comparison call sites leaked length information through timing2026-04-07
- MediumGHSA-846p-hgpv-vphc: OpenClaw: QQ Bot structured payloads could read arbitrary local files2026-04-07
- MediumCVE-2026-34511: OpenClaw PKCE verifier exposure via OAuth state parameter in Gemini flow2026-04-03
- MediumGHSA-6p8r-6m93-557f: OpenClaw: Fake DeviceToken Bypasses Shared Auth Rate Limiting2026-04-03
- HighGHSA-v3qc-wrwx-j3pw: OpenClaw: Agentic Consent Bypass — LLM Agent Can Silently Disable Exec Approval via `config.patch`2026-04-03
- LowGHSA-g86v-f9qv-rh6m: OpenClaw SSRF guard misses four IPv6 special-use ranges2026-03-31
- MediumGHSA-m866-6qv5-p2fg: OpenClaw host-env blocklist missing `GIT_TEMPLATE_DIR` and `AWS_CONFIG_FILE` allows code execution via env override2026-03-31
- HighGHSA-jccr-rrw2-vc8h: OpenClaw safeBins jq `$ENV` filter bypass allows environment variable disclosure2026-03-31
- HighGHSA-m3mh-3mpg-37hw: OpenClaw has an Arbitrary Malicious Code Execution Vulnerability2026-03-30
- MediumGHSA-68f8-9mhj-h2mp: OpenClaw has a Gateway HTTP /v1/models Route Bypasses Operator Read Scope2026-03-30
- HighGHSA-hr5v-j9h9-xjhg: OpenClaw has Sandbox Media Root Bypass via Unnormalized `mediaUrl` / `fileUrl` Parameter Keys (CWE-22)2026-03-30
- HighGHSA-7xr2-q9vf-x4r5: OpenClaw: Symlink Traversal via IDENTITY.md appendFile in agents.create/update (Incomplete Fix for CVE-2026-32013)2026-03-26
- HighGHSA-cxmw-p77q-wchg: OpenClaw: Arbitrary code execution via unvalidated WebView JavascriptInterface2026-03-26
- MediumCVE-2026-28451: OpenClaw server-side request forgery in Feishu extension media fetching2026-03-05
- HighGHSA-vvjh-f6p9-5vcf: OpenClaw Canvas Authentication Bypass Vulnerability2026-03-04
- MediumGHSA-9mph-4f7v-fmvh: OpenClaw has agent avatar symlink traversal in gateway session metadata2026-03-04
- HighGHSA-x2ff-j5c2-ggpr: OpenClaw: Slack interactive callbacks could skip configured sender checks in some shared-workspace flows2026-03-04
- LowGHSA-v6x2-2qvm-6gv8: OpenClaw reuses the gateway auth token in the owner ID prompt hashing fallback2026-03-03
- HighGHSA-659f-22xc-98f2: OpenClaw hook transform path containment missed symlink-resolved escapes2026-03-03
- MediumGHSA-56pc-6hvp-4gv4: OpenClaw vulnerable to arbitrary file read via $include directive2026-03-03
- MediumGHSA-6g25-pc82-vfwp: OpenClaw: macOS beta onboarding exposed PKCE verifier via OAuth state2026-03-03
- MediumGHSA-5847-rm3g-23mw: OpenClaw has hook auth rate limiter bypass via IPv4-mapped IPv6 client key variants2026-03-03
- HighGHSA-943q-mwmv-hhvh: OpenClaw: Gateway /tools/invoke tool escalation + ACP permission auto-approval2026-03-02
- HighGHSA-jq4x-98m3-ggq6: OpenClaw Canvas Path Traversal Information Disclosure Vulnerability2026-03-02
- HighCVE-2026-27487: OpenClaw OS command injection in macOS Claude CLI keychain credential refresh2026-02-21
- MediumGHSA-cxpw-2g23-2vgw: OpenClaw: ACP prompt-size checks missing in local stdio bridge could reduce responsiveness with very large inputs2026-02-20
- MediumGHSA-r6h2-5gqq-v5v6: OpenClaw: Reject symlinks in local skill packaging script2026-02-20
- LowGHSA-wh94-p5m6-mr7j: OpenClaw Discord moderation authorization used untrusted sender identity in tool-driven flows2026-02-20
- HighCVE-2026-26320: OpenClaw macOS client confirmation dialog hides part of deep link message2026-02-19
- MediumGHSA-fh3f-q9qw-93j9: OpenClaw replaced a deprecated sandbox hash algorithm2026-02-19
- MediumGHSA-xxvh-5hwj-42pp: OpenClaw's sandbox config hash sorted primitive arrays and suppressed needed container recreation2026-02-18
- MediumGHSA-6hf3-mhgc-cm65: OpenClaw session tool visibility hardening and Telegram webhook secret fallback2026-02-18
- MediumGHSA-chf7-jq6g-qrwv: OpenClaw: Telegram bot token exposure via logs2026-02-18
- HighGHSA-w235-x559-36mg: OpenClaw: Docker container escape via unvalidated bind mount config injection2026-02-18
- HighGHSA-2qj5-gwg2-xwc4: OpenClaw: Unsanitized CWD path injection into LLM prompts2026-02-18
- HighGHSA-x22m-j5qq-j49m: OpenClaw has two SSRF via sendMediaFeishu and markdown image fetching in Feishu extension2026-02-18
- MediumGHSA-jfv4-h8mc-jcp8: OpenClaw: Process Safety - Unvalidated PID Kill via SIGKILL in Process Cleanup2026-02-18
- MediumGHSA-7rcp-mxpq-72pj: OpenClaw Chutes manual OAuth state validation bypass can cause credential substitution2026-02-18
Packages named in advisories
44 packages
| Package | Advisories | Highest severity | Latest advisory | Exploited | Authority |
|---|---|---|---|---|---|
| @anthropic-ai/claude-codenpm | 22 | Critical | Not in the registry | ||
| github.com/pinchtab/pinchtabGo | 6 | High | Not in the registry | ||
| github.com/hatchet-dev/hatchetGo | 5 | Medium | Not in the registry | ||
| pydantic-aiPyPI | 4 | High | None detected | ||
| pydantic-ai-slimPyPI | 4 | High | Outbound HTTP | ||
| omnigentPyPI | 4 | Critical | Not in the registry | ||
| n8nnpm | 4 | High | Code execution, File system, MCP tools, Shell commands | ||
| @evomap/evolvernpm | 3 | Critical | Not in the registry | ||
| github.com/pinchtab/pinchtab/cmd/pinchtabGo | 3 | High | Not in the registry | ||
| @ooples/token-optimizer-mcpnpm | 2 | High | Not in the registry | ||
| @agenticmail/corenpm | 2 | High | Not in the registry | ||
| @agenticmail/apinpm | 2 | High | Not in the registry | ||
| apm-cliPyPI | 2 | High | Not in the registry | ||
| @paperclipai/servernpm | 2 | Critical | Not in the registry | ||
| @enclave-vm/corenpm | 2 | Critical | Not in the registry | ||
| enclave-vmnpm | 2 | Critical | Not in the registry | ||
| opencode-ainpm | 2 | High | Not in the registry | ||
| neuron-core/neuron-aicomposer | 2 | Critical | Not in the registry | ||
| hatchetGo | 1 | High | Not in the registry | ||
| hatchet-dev/hatchetGo | 1 | Medium | Not in the registry | ||
| @andrea9293/mcp-documentation-servernpm | 1 | High | Not in the registry | ||
| @apify/actors-mcp-servernpm | 1 | High | Not in the registry | ||
| @trigger.dev/corenpm | 1 | High | Not in the registry | ||
| @jshookmcp/jshooknpm | 1 | Medium | Not in the registry | ||
| n8nEcosystem not stated | 1 | High | Not in the registry | ||
| @agenticmail/claudecodenpm | 1 | High | Not in the registry | ||
| @agenticmail/codexnpm | 1 | High | Not in the registry | ||
| @agenticmail/openclawnpm | 1 | High | Not in the registry | ||
| agentic-flownpm | 1 | High | Not in the registry | ||
| @agenticmail/mcpnpm | 1 | High | Not in the registry | ||
| praisonaiPyPI | 1 | Critical | Not in the registry | ||
| github.com/safedep/gryphGo | 1 | Medium | Not in the registry | ||
| @yoda.digital/gitlab-mcp-servernpm | 1 | Critical | Not in the registry | ||
| apmPyPI | 1 | High | Not in the registry | ||
| paperclipainpm | 1 | Critical | Not in the registry | ||
| agixtPyPI | 1 | High | Not in the registry | ||
| openclawnpm | 1 | High | Not in the registry | ||
| langflowPyPI | 1 | Critical | None detected | ||
| github.com/agentgateway/agentgatewayGo | 1 | Medium | Not in the registry | ||
| microsoft-semantickernel-corenuget | 1 | Critical | Not in the registry | ||
| semantic-kernelPyPI | 1 | Critical | Outbound HTTP, MCP tools | ||
| @mastra/mcp-docs-servernpm | 1 | Medium | Not in the registry | ||
| @openai/codexnpm | 1 | High | Not in the registry | ||
| khojPyPI | 1 | Medium | Code execution, Outbound HTTP |
Topics are assigned by matching a record's title and summary against published patterns, so an advisory that never uses the words is missed and one that mentions them in passing is counted. An advisory that names several packages counts once for each. A package is listed with the ecosystem its advisory source states, and by name alone when the source states none.
Authority is read from the dependencies a package's latest release declares, and it is known only for packages the Exposure Registry tracks. It shows what a package's dependencies can do on the host. It does not show that a model is given that reach. Severity comes from the source advisory when it gives one, otherwise from the classifier. Dates are in UTC.