{"data":[{"id":"04c7c103-6772-493b-b6be-54a5d4cc07e9","title":"GHSA-hc5v-gxvj-58wh: PraisonAI: MCP HTTP-stream transport is unauthenticated by default, exposing tool enumeration and an unvalidated tool-call surface","headline":null,"summary":"PraisonAI 4.6.63's MCP HTTP-stream server applies authentication only when an API key is set, and the CLI defaults `--api-key` to `None`, so `praisonai mcp serve --transport http-stream` exposes the full MCP surface without authentication. An unauthenticated client can call `initialize` and `tools/list` (about 50 tools), and the dispatcher in `mcp_server/server.py` forwards tool-call arguments to handlers without validating them against the advertised `inputSchema`. The source states this is not an RCE or file read in 4.6.63, because `workflow.run` and `workflow.run_file` fail at runtime.","sourceUrl":"https://github.com/advisories/GHSA-hc5v-gxvj-58wh","publishedAt":"2026-10-08T21:58:42.000Z","severity":"high","cvssSeverity":"high","cvssScore":null,"labels":["security"],"issueType":"vulnerability","cveId":"CVE-2026-61427","cweIds":null,"affectedPackages":["praisonai@<= 4.6.77 (fixed: 4.6.78)"],"affectedVendors":[],"affectedVendorsRaw":["PraisonAI","MCP HTTP-stream server"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":["other"],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0.00389,"epssCheckedAt":"2026-10-10T03:00:36.826Z","kevDateAdded":null,"advisoryAliases":["GHSA-hc5v-gxvj-58wh"],"affectedPackagesSource":null,"patchAvailable":true,"disclosureDate":"2026-10-08T21:58:42.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality","integrity"],"aiComponentTargeted":"plugin","llmSpecific":false,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":null},{"id":"325f3b1a-7700-4b84-a16b-8f0f2101ab8c","title":"Top MCP security resources — October 2026","headline":null,"summary":"This is a news digest of 15 MCP security resources for October 2026. It highlights an authentication bypass in LiteLLM's MCP endpoint, which accepts any invalid bearer token (CVE-2026-59822) and is now on CISA's Known Exploited Vulnerabilities list, and session ID spoofing in the Grafana MCP server, which lets unauthenticated callers invoke tools with the server's service account credentials.","sourceUrl":"https://adversa.ai/blog/top-mcp-security-resources-october-2026/","publishedAt":"2026-10-08T09:00:00.000Z","severity":"medium","cvssSeverity":null,"cvssScore":null,"labels":["security","industry"],"issueType":"news","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":["Anthropic","Google","Microsoft","Amazon"],"affectedVendorsRaw":["MCP","LiteLLM","Grafana MCP server","Obot MCP gateway","MCP Python SDK","Amazon Quick","CoSAI MCP security model 2.0"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":["jailbreak","supply_chain"],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":"2026-10-08T09:00:00.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"plugin","llmSpecific":false,"classifierConfidence":0.8,"researchCategory":null,"atlasIds":null},{"id":"14f07878-7ac5-4993-99a0-8bb2f6440312","title":"GHSA-6qxp-vccf-f47h: MCP TypeScript SDK: OAuth client could send credentials to an authorization server chosen by the MCP server","headline":null,"summary":null,"sourceUrl":"https://github.com/advisories/GHSA-6qxp-vccf-f47h","publishedAt":"2026-10-06T15:35:44.000Z","severity":"high","cvssSeverity":"high","cvssScore":"7.5","labels":["security"],"issueType":"vulnerability","cveId":"CVE-2026-104850","cweIds":["CWE-345","CWE-522"],"affectedPackages":["@modelcontextprotocol/sdk@>= 1.12.0, < 1.31.0 (fixed: 1.31.0)","@modelcontextprotocol/client@>= 2.0.0, < 2.2.0 (fixed: 2.2.0)"],"affectedVendors":["Anthropic"],"affectedVendorsRaw":["MCP TypeScript SDK","Model Context Protocol"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":["supply_chain"],"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"network","attackComplexity":"low","privilegesRequired":"none","userInteraction":"none","exploitMaturity":"unknown","epssScore":0.00176,"epssCheckedAt":"2026-10-10T04:57:18.258Z","kevDateAdded":null,"advisoryAliases":["GHSA-6qxp-vccf-f47h"],"affectedPackagesSource":null,"patchAvailable":true,"disclosureDate":"2026-10-06T15:35:44.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality"],"aiComponentTargeted":"api","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":["AML.T0010"]},{"id":"b30cbd54-5a15-4bba-b2e9-e0331008e803","title":"Welcome to the Jungle: What We Found Inside 15,465 Public MCP Servers","headline":null,"summary":"OX Security researcher Moshe Siman Tov Bustan reports on an analysis of 15,465 publicly indexed MCP servers across 5 MCP registries, deduplicated to 5,095 unique hostnames. The study found 15.6% of hostnames resolve outside the United States, 0.45% route traffic through consumer tunneling services such as ngrok-free, and 2.3% no longer resolve, with six on expired domains that anyone can register.","sourceUrl":"https://thehackernews.com/2026/10/welcome-to-jungle-what-we-found-inside.html","publishedAt":"2026-10-06T11:02:30.000Z","severity":"medium","cvssSeverity":null,"cvssScore":null,"labels":["security","industry"],"issueType":"news","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":["Anthropic"],"affectedVendorsRaw":["MCP (Model Context Protocol)","Anthropic MCP"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":["supply_chain"],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":"2026-10-06T11:02:30.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"plugin","llmSpecific":true,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null},{"id":"8a7fe4b8-9e77-4d7b-9656-c1d1ad7ca23b","title":"CVE-2026-105741: Langflow is a tool for building and deploying AI-powered agents and workflows. From 1.5.0 until 1.10.3, an IP spoofing…","headline":"Langflow IP spoofing bypasses local-only restriction on MCP install endpoint","summary":"Langflow versions 1.5.0 through 1.10.3 contain an IP spoofing flaw in the MCP configuration installation endpoint, POST /api/v1/mcp/project/{project_id}/install. An authenticated remote attacker can send a spoofed X-Forwarded-For: 127.0.0.1 header, making the server treat the request as local and bypass the \"local-only\" restriction. This lets the attacker write or overwrite an MCP client configuration file on the server's filesystem.","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-105741","publishedAt":"2026-10-05T21:16:35.740Z","severity":"high","cvssSeverity":"high","cvssScore":"7.1","labels":["security"],"issueType":"vulnerability","cveId":"CVE-2026-105741","cweIds":["CWE-290","CWE-345"],"affectedPackages":["langflow@>= 1.5.0, < 1.10.3 (fixed: 1.10.3)"],"affectedVendors":[],"affectedVendorsRaw":["Langflow"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"Fixed in 1.10.3.","attackType":["other"],"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L","attackVector":"network","attackComplexity":"low","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0.00212,"epssCheckedAt":"2026-10-10T06:42:01.794Z","kevDateAdded":null,"advisoryAliases":["GHSA-4f6c-2vvp-gw82"],"affectedPackagesSource":"ghsa","patchAvailable":true,"disclosureDate":"2026-10-05T21:16:35.740Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity"],"aiComponentTargeted":"framework","llmSpecific":false,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":["AML.T0010"]},{"id":"1d6f491e-a295-4bae-8c90-4b4ffd94153e","title":"CVE-2026-105740: Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, any authenticated…","headline":"Langflow remote code execution through MCP server stdio command field","summary":"CVE-2026-105740 affects Langflow versions prior to 1.9.0. Any authenticated user can add an MCP server with the \"Stdio\" transport, and the user-supplied command field is passed directly to bash -c \"exec {command}\" with no validation, allowlisting, or sandboxing, so the command runs on the server as soon as the server list is fetched. The env field also permits arbitrary environment variable injection, such as LD_PRELOAD or a PATH override.","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-105740","publishedAt":"2026-10-05T21:16:35.567Z","severity":"critical","cvssSeverity":"critical","cvssScore":"9.9","labels":["security"],"issueType":"vulnerability","cveId":"CVE-2026-105740","cweIds":["CWE-78"],"affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["Langflow","MCP"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"Fixed in 1.9.0.","attackType":["other"],"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","attackVector":"network","attackComplexity":"low","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0.00589,"epssCheckedAt":"2026-10-10T03:00:37.847Z","kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":"2026-10-05T21:16:35.567Z","capecIds":["CAPEC-88"],"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality","integrity","availability"],"aiComponentTargeted":"plugin","llmSpecific":false,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":null},{"id":"bc3f64bf-002c-43f6-9e92-bccba1a8ff58","title":"CVE-2026-105699: Langflow is a tool for building and deploying AI-powered agents and workflows. From 1.6.8 until 1.9.1, Langflow…","headline":"Langflow MCP resource read exposes other users' flow files","summary":"Langflow versions from 1.6.8 through 1.9.1 fail to authorize the resource URI passed to resources/read on project-scoped MCP connections. An authenticated user with access to any project-scoped MCP endpoint can read another user's flow-backed files, including uploaded documents, structured data, prompts and other private flow artifacts. Global handle_list_resources and handle_list_tools behavior can also disclose the flow and file identifiers needed to target them. Victim files and stored flows are not modified.","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-105699","publishedAt":"2026-10-05T21:16:35.410Z","severity":"high","cvssSeverity":null,"cvssScore":null,"labels":["security"],"issueType":"vulnerability","cveId":"CVE-2026-105699","cweIds":["CWE-639"],"affectedPackages":["langflow@>= 1.6.8, <= 1.9.0 (fixed: 1.9.1)"],"affectedVendors":[],"affectedVendorsRaw":["Langflow"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"Fixed in 1.9.1.","attackType":["data_extraction"],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0.00246,"epssCheckedAt":"2026-10-10T02:56:51.777Z","kevDateAdded":null,"advisoryAliases":["GHSA-4hmc-cfm3-w43c"],"affectedPackagesSource":"ghsa","patchAvailable":true,"disclosureDate":"2026-10-05T21:16:35.410Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality"],"aiComponentTargeted":"api","llmSpecific":false,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":null},{"id":"4b29cc58-37e5-47d3-9fc9-f5326011ee11","title":"CVE-2026-105697: Langflow is a tool for building and deploying AI-powered agents and workflows. Before Langflow 1.10.3, the MCP stdio…","headline":"Langflow arbitrary command execution through MCP stdio server configuration","summary":"CVE-2026-105697 affects Langflow before 1.10.3, where the MCP stdio transport ran whatever command and args a user placed in an MCP server configuration, with no allowlist and, before 1.10.3, wrapped in bash -c \"exec {command} ...\". Any user who can reach the MCP server settings (POST/PATCH /api/v2/mcp/servers/{server_name}) or build a flow with the MCP Tools component can run an arbitrary OS command on the Langflow host as the Langflow process user, when Langflow connects to the server, even if the UI then reports a startup failure. With the default LANGFLOW_AUTO_LOGIN=true, GET /api/v1/auto_login issues a token without credentials, so the flaw is reachable without an account on an exposed default instance; with AUTO_LOGIN disabled, any authenticated non-admin user can exploit it.","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-105697","publishedAt":"2026-10-05T21:16:35.087Z","severity":"critical","cvssSeverity":"critical","cvssScore":"9.9","labels":["security"],"issueType":"vulnerability","cveId":"CVE-2026-105697","cweIds":["CWE-78"],"affectedPackages":["langflow@>= 1.1.2, < 1.10.3 (fixed: 1.10.3)","langflow-base@>= 0.1.2, < 0.10.3 (fixed: 0.10.3)","lfx@< 1.10.3 (fixed: 1.10.3)"],"affectedVendors":[],"affectedVendorsRaw":["Langflow"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"Fixed in Langflow 1.10.3, langflow-base 0.10.3, and lfx 1.10.3.","attackType":["other"],"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","attackVector":"network","attackComplexity":"low","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0.00396,"epssCheckedAt":"2026-10-10T03:00:40.857Z","kevDateAdded":null,"advisoryAliases":["GHSA-w794-rj3p-xv45"],"affectedPackagesSource":"ghsa","patchAvailable":true,"disclosureDate":"2026-10-05T21:16:35.087Z","capecIds":["CAPEC-88"],"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality","integrity","availability"],"aiComponentTargeted":"plugin","llmSpecific":false,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":["AML.T0010"]},{"id":"e00e9e77-4884-49ba-aafe-61c443864fd9","title":"GHSA-p23f-cm6q-2qp8: SiYuan MCP asset.upload Reads Arbitrary Absolute File Paths (Workspace Boundary Bypass)","headline":null,"summary":"SiYuan's MCP tool `asset.upload` accepts a comma-separated `files` list of absolute paths and performs no workspace boundary or sensitive-path check before `model.InsertLocalAssets` opens each file and copies it into the workspace `assets/` directory. An attacker who can steer the AI Agent through prompt injection could make it upload files such as `~/.ssh/id_rsa` into the workspace, where they become reachable. Affected versions are `<= 3.8.0`, and the issue is a residual gap from the remediation of CVE-2026-66012.","sourceUrl":"https://github.com/advisories/GHSA-p23f-cm6q-2qp8","publishedAt":"2026-10-02T23:16:56.000Z","severity":"medium","cvssSeverity":"medium","cvssScore":null,"labels":["security"],"issueType":"vulnerability","cveId":null,"cweIds":null,"affectedPackages":["github.com/siyuan-note/siyuan/kernel@< 0.0.0-20260813142104-b26a4a307b8a (fixed: 0.0.0-20260813142104-b26a4a307b8a)"],"affectedVendors":[],"affectedVendorsRaw":["SiYuan MCP","SiYuan"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"Fixed in 3.8.1.","attackType":["prompt_injection"],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":["GHSA-p23f-cm6q-2qp8"],"affectedPackagesSource":null,"patchAvailable":true,"disclosureDate":"2026-10-02T23:16:56.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality"],"aiComponentTargeted":"plugin","llmSpecific":false,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":null},{"id":"99fc6cfa-bcd9-4bdd-b5a3-5202f17546b1","title":"GHSA-c9xm-49cp-xcr9: rmcp OAuth client fetches server-controlled resource_metadata URLs","headline":null,"summary":"The rmcp OAuth client in modelcontextprotocol/rust-sdk takes a resource_metadata URL from the server-controlled WWW-Authenticate header and fetches it without same-origin or private-network checks. A malicious or compromised MCP server can point the client at localhost, RFC 1918 addresses or cloud metadata endpoints, making the victim application send outbound GET requests from its own network context.","sourceUrl":"https://github.com/advisories/GHSA-c9xm-49cp-xcr9","publishedAt":"2026-10-02T16:12:31.000Z","severity":"medium","cvssSeverity":"medium","cvssScore":null,"labels":["security"],"issueType":"vulnerability","cveId":null,"cweIds":["CWE-918"],"affectedPackages":["rmcp@< 2.0.0 (fixed: 2.0.0)"],"affectedVendors":[],"affectedVendorsRaw":["rmcp","MCP (Model Context Protocol)"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":["other"],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":["GHSA-c9xm-49cp-xcr9"],"affectedPackagesSource":null,"patchAvailable":true,"disclosureDate":"2026-10-02T16:12:31.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality"],"aiComponentTargeted":"api","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null},{"id":"e490d235-7857-40c7-86f7-90ba918f7191","title":"CVE-2025-71427: Office-PowerPoint-MCP-Server through 2.0.7 contains a path traversal vulnerability that allows MCP callers to write and…","headline":"Office-PowerPoint-MCP-Server path traversal in file read and write","summary":"CVE-2025-71427 affects Office-PowerPoint-MCP-Server through 2.0.7. A path traversal flaw lets MCP callers read and write files outside the working directory by supplying absolute paths or ../ sequences. An attacker can steer an AI agent via prompt injection to abuse save_presentation, open_presentation, or manage_image output_path to overwrite any server-writable file or load external files.","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-71427","publishedAt":"2026-10-01T23:16:46.613Z","severity":"medium","cvssSeverity":"medium","cvssScore":"6.8","labels":["security"],"issueType":"vulnerability","cveId":"CVE-2025-71427","cweIds":["CWE-22"],"affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["Office-PowerPoint-MCP-Server","MCP"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":["prompt_injection","other"],"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N","attackVector":"network","attackComplexity":"high","privilegesRequired":"none","userInteraction":"required","exploitMaturity":"unknown","epssScore":0.00289,"epssCheckedAt":"2026-10-10T02:58:12.571Z","kevDateAdded":null,"advisoryAliases":["GHSA-xpvr-6r3p-gm34"],"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":"2026-10-01T23:16:46.613Z","capecIds":["CAPEC-126"],"crossRefCount":0,"attackSophistication":"trivial","impactType":["integrity","confidentiality"],"aiComponentTargeted":"plugin","llmSpecific":false,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":["AML.T0051"]},{"id":"ea2e060a-f06b-44d7-9286-eb37aea579d8","title":"CVE-2026-97662 - Argument injection in AWS security-agent-mcp-server diff scan","headline":null,"summary":"CVE-2026-97662 is an argument injection flaw in the diff scan operation of security-agent-mcp-server, an open-source MCP server published by AWS in the awslabs/mcp repository. Affected versions are 0.1.1 up to but not including 0.2.0. A crafted reference value is parsed as a command-line option instead of a revision, letting a context-dependent actor create, overwrite, or truncate arbitrary files on the host outside the workspace directory and bypass the server's workspace-confinement control.","sourceUrl":"https://aws.amazon.com/security/security-bulletins/rss/2026-121-aws/","publishedAt":"2026-10-01T18:16:35.000Z","severity":"high","cvssSeverity":null,"cvssScore":null,"labels":["security"],"issueType":"vulnerability","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":["Amazon"],"affectedVendorsRaw":["AWS security-agent-mcp-server","Model Context Protocol (MCP) server"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":["other"],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":"2026-10-01T18:16:35.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity"],"aiComponentTargeted":"plugin","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null},{"id":"2e616208-af0b-47ea-a409-22659f5c9384","title":"CVE-2026-96561: The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Stored Cross-Site…","headline":"AI Engine WordPress plugin stored cross-site scripting via chat REST endpoint","summary":"The AI Engine plugin for WordPress, up to and including 3.8.0, contains a stored cross-site scripting flaw. An unauthenticated attacker can send crafted input to the /mwai-ui/v1/chats/submit REST endpoint, which writes an attacker-controlled string into the PHP error log as a forged line. The plugin's Advisor feature then passes that content into an AI prompt and stores the result unescaped, so the injected script runs when an administrator opens the WordPress dashboard.","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-96561","publishedAt":"2026-10-01T04:18:22.110Z","severity":"high","cvssSeverity":"high","cvssScore":"7.2","labels":["security"],"issueType":"vulnerability","cveId":"CVE-2026-96561","cweIds":["CWE-79"],"affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["AI Engine WordPress plugin"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":["prompt_injection","other"],"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N","attackVector":"network","attackComplexity":"low","privilegesRequired":"none","userInteraction":"none","exploitMaturity":"unknown","epssScore":0.00328,"epssCheckedAt":"2026-10-10T03:00:39.353Z","kevDateAdded":null,"advisoryAliases":["GHSA-h282-rvgq-85qj"],"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":"2026-10-01T04:18:22.110Z","capecIds":["CAPEC-198","CAPEC-86"],"crossRefCount":0,"attackSophistication":"advanced","impactType":["integrity","confidentiality"],"aiComponentTargeted":"plugin","llmSpecific":true,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":["AML.T0051"]},{"id":"865b0b75-98fb-4d8c-a8ee-9b0c8f6c8343","title":"Security threat modeling for emerging AI-agent protocols: A comparative analysis of MCP, A2A, agora, and ANP","headline":null,"summary":"The source is a December 2026 article in the Journal of Information Security and Applications (Volume 103) by Zeynab Anbiaee, Mahdi Rabbani, Mansur Mirani, Gunjan Piya, Igor Opushnyev, Ali Ghorbani and Sajjad Dadkhah. Its title indicates a comparative security threat modeling analysis of the MCP, A2A, agora and ANP AI-agent protocols. The provided text contains only publication metadata, so no findings or methods are available to report.","sourceUrl":"https://www.sciencedirect.com/science/article/pii/S2214212626002759?dgcid=rss_sd_all","publishedAt":"2026-09-29T12:02:44.280Z","severity":"info","cvssSeverity":null,"cvssScore":null,"labels":["security","research"],"issueType":"research","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["MCP","A2A","agora","ANP"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":[],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":null,"capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"agent","llmSpecific":false,"classifierConfidence":0.9,"researchCategory":"peer_reviewed","atlasIds":null},{"id":"413d588f-e167-498f-acb2-9ba74cb79547","title":"Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials","headline":null,"summary":"A malicious MCP server can trick applications built on the official MCP Python SDK into sending their OAuth client secret, authorization code, and PKCE proof key to a token endpoint the attacker controls. Affected versions are 1.9.1 through 1.29.1 and 2.0.0 through 2.1.1, and the flaw is rated 7.5 for non-interactive providers and 6.5 for the interactive provider. Cycode reported the issue, and no CVE had been assigned as of September 29, 2026.","sourceUrl":"https://thehackernews.com/2026/09/official-mcp-python-sdk-flaw-can-let.html","publishedAt":"2026-09-29T06:08:25.000Z","severity":"medium","cvssSeverity":null,"cvssScore":null,"labels":["security","industry"],"issueType":"news","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":["Anthropic"],"affectedVendorsRaw":["MCP Python SDK","Model Context Protocol"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"Upgrade to 1.30.0 on the 1.x line or 2.2.0 on the 2.x line. For ClientCredentialsOAuthProvider and PrivateKeyJWTOAuthProvider, also pass issuer= to name the login service the credentials belong to, since upgrading alone does not fix those providers. Replace the deprecated RFC7523OAuthClientProvider, which has no issuer= option, with one of the other providers. After upgrading, clear stored OAuth client registrations once. If a client may have connected to an untrusted server, rotate its client secret and revoke its tokens at the login service. On older versions, connect only to MCP servers you trust.","attackType":["supply_chain"],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":"2026-09-29T06:08:25.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality"],"aiComponentTargeted":"framework","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null},{"id":"fa280272-7198-4a48-9cbd-8c0730906cff","title":"CVE-2026-55157: Token Optimizer MCP measures token savings per AI coding agent, optimizes context, and shares a live local knowledge…","headline":"Token Optimizer MCP OS command injection through smart_user username argument","summary":"Prior to version 5.1.0, token-optimizer-mcp is vulnerable to OS command injection in the smart_user tool. Any MCP client that can call smart_user can run arbitrary shell commands through the username argument of the get-user-info operation, with the privileges of the user running the server.","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-55157","publishedAt":"2026-09-28T18:17:23.373Z","severity":"high","cvssSeverity":"high","cvssScore":"8.4","labels":["security"],"issueType":"vulnerability","cveId":"CVE-2026-55157","cweIds":["CWE-78"],"affectedPackages":["@ooples/token-optimizer-mcp@< 5.1.0 (fixed: 5.1.0)"],"affectedVendors":[],"affectedVendorsRaw":["Token Optimizer MCP"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"This issue has been patched in version 5.1.0.","attackType":["other"],"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"local","attackComplexity":"low","privilegesRequired":"none","userInteraction":"none","exploitMaturity":"unknown","epssScore":0.00705,"epssCheckedAt":"2026-10-10T02:59:00.848Z","kevDateAdded":null,"advisoryAliases":["GHSA-49mq-fc6q-3h46"],"affectedPackagesSource":"ghsa","patchAvailable":true,"disclosureDate":"2026-09-28T18:17:23.373Z","capecIds":["CAPEC-88"],"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality","integrity","availability"],"aiComponentTargeted":"plugin","llmSpecific":false,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":null},{"id":"3daefed1-188d-43da-873c-7ed0541ffdcc","title":"CVE-2026-55156: Token Optimizer MCP measures token savings per AI coding agent, optimizes context, and shares a live local knowledge…","headline":"Token Optimizer MCP dashboard path traversal via sessionId in session endpoints","summary":"Token Optimizer MCP versions before 5.1.0 run a dashboard HTTP server whose /api/session-summary and /api/session-events endpoints have no authentication middleware. Both handlers join the caller-supplied sessionId query parameter into a filesystem path with path.join, and Node.js normalizes .. segments, so an unauthenticated network client can read any .jsonl file the server can access.","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-55156","publishedAt":"2026-09-28T18:17:23.203Z","severity":"medium","cvssSeverity":"medium","cvssScore":"5.3","labels":["security"],"issueType":"vulnerability","cveId":"CVE-2026-55156","cweIds":["CWE-22"],"affectedPackages":["@ooples/token-optimizer-mcp@< 5.1.0 (fixed: 5.1.0)"],"affectedVendors":[],"affectedVendorsRaw":["Token Optimizer MCP"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"This issue has been patched in version 5.1.0.","attackType":["other"],"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","attackVector":"network","attackComplexity":"low","privilegesRequired":"none","userInteraction":"none","exploitMaturity":"unknown","epssScore":0.00446,"epssCheckedAt":"2026-10-10T03:00:40.088Z","kevDateAdded":null,"advisoryAliases":["GHSA-76pc-mqxp-3rq5"],"affectedPackagesSource":"ghsa","patchAvailable":true,"disclosureDate":"2026-09-28T18:17:23.203Z","capecIds":["CAPEC-126"],"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality"],"aiComponentTargeted":"plugin","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null},{"id":"c55bd569-6df5-43cc-b94f-f4e84134ef24","title":"CVE-2026-101065: Obot is an open-source AI agent/MCP platform. In all versions up to and including commit d7e6970, the Docker quickstart…","headline":"Obot Docker quickstart exposes admin access without authentication","summary":"Obot, an open-source AI agent and MCP platform, documents a Docker quickstart that starts the container on 0.0.0.0:8080 with authentication disabled by default in all versions up to and including commit d7e6970 (CVE-2026-101065). Unauthenticated users who can reach the port receive a synthetic \"nobody\" user holding the Owner and Admin roles, which grants full control of the Obot API and UI, including registering and launching attacker-controlled MCP servers. The quickstart also mounts /var/run/docker.sock, giving the MCP runtime backend access to the host's Docker control surface.","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-101065","publishedAt":"2026-09-27T21:17:02.027Z","severity":"critical","cvssSeverity":"critical","cvssScore":"9.8","labels":["security"],"issueType":"vulnerability","cveId":"CVE-2026-101065","cweIds":["CWE-306"],"affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["Obot"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"The fix is documentation-only: the quickstart now enables authentication. Operators who followed the previous instructions should set OBOT_SERVER_ENABLE_AUTHENTICATION=true before exposing the host to any untrusted network.","attackType":["other"],"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"network","attackComplexity":"low","privilegesRequired":"none","userInteraction":"none","exploitMaturity":"unknown","epssScore":0.00437,"epssCheckedAt":"2026-10-10T02:57:07.563Z","kevDateAdded":null,"advisoryAliases":["GHSA-m95h-j2gj-xrgq"],"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":"2026-09-27T21:17:02.027Z","capecIds":["CAPEC-115"],"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality","integrity","availability"],"aiComponentTargeted":"plugin","llmSpecific":false,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":null},{"id":"5eb7ddef-64f2-4613-8ebb-f2f0ebcd42e8","title":"CVE-2026-97228: Rapid7 Bulk Export MCP versions 0.2.5 through 0.6.1 suffer from a GraphQL query injection issue in the export-status…","headline":"Rapid7 Bulk Export MCP GraphQL query injection in export-status component","summary":"Rapid7 Bulk Export MCP versions 0.2.5 through 0.6.1 contain a GraphQL query injection in `get_export_status` in `src/export_manager.py`. The unvalidated `export_id` argument, passed via the `check_rapid7_export_status` and `download_rapid7_export` tools, is interpolated directly into the query string, so a crafted value can append attacker-chosen root-level selections such as schema introspection. The injected query runs under the operator's own API key and cannot cross a tenant or account boundary, so the realistic exposure is a compromised or careless upstream MCP client or indirect prompt injection.","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-97228","publishedAt":"2026-09-25T11:17:02.163Z","severity":"low","cvssSeverity":"low","cvssScore":"2.7","labels":["security"],"issueType":"vulnerability","cveId":"CVE-2026-97228","cweIds":["CWE-943"],"affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["Rapid7 Bulk Export MCP"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"Fixed in version 0.6.2, which passes `export_id` as a parameterized GraphQL variable (`$exportId: ID!`).","attackType":["other"],"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N","attackVector":"network","attackComplexity":"low","privilegesRequired":"high","userInteraction":"none","exploitMaturity":"unknown","epssScore":0.00248,"epssCheckedAt":"2026-10-10T06:41:58.184Z","kevDateAdded":null,"advisoryAliases":["GHSA-pwmm-7g3w-8pvp"],"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":"2026-09-25T11:17:02.163Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity"],"aiComponentTargeted":"plugin","llmSpecific":false,"classifierConfidence":0.8,"researchCategory":null,"atlasIds":["AML.T0051"]},{"id":"eb8541d5-9b13-4d88-a93f-5c3a097acfcd","title":"GHSA-3cj3-hqcr-g934: Cline: Cross-Origin WebSocket Hijacking in Cline Hub Dashboard (`/browser` endpoint)","headline":null,"summary":"The Cline Hub dashboard server (`@cline/cline-hub`), launched with the `cline dashboard` CLI command, accepts WebSocket connections on `/browser` without validating the HTTP `Origin` header. When `ROOM_SECRET` is unset, which is the default for `127.0.0.1` binds, `isAuthorizedBrowserRequest()` returns `true`, so any website a developer visits can open a cross-origin WebSocket to `ws://127.0.0.1:8787/browser`. Dashboard sessions default to `autoApprove: true` for all tools, and the source reports that an injected `upsert_mcp_server` frame wrote a malicious `stdio` MCP server entry into the victim's Cline settings file.","sourceUrl":"https://github.com/advisories/GHSA-3cj3-hqcr-g934","publishedAt":"2026-09-24T19:48:34.000Z","severity":"high","cvssSeverity":"high","cvssScore":null,"labels":["security"],"issueType":"vulnerability","cveId":"CVE-2026-59723","cweIds":null,"affectedPackages":["cline@< 3.0.30 (fixed: 3.0.30)"],"affectedVendors":[],"affectedVendorsRaw":["Cline","Cline Hub","cline dashboard"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":["other"],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0.00249,"epssCheckedAt":"2026-10-10T02:58:27.768Z","kevDateAdded":null,"advisoryAliases":["GHSA-3cj3-hqcr-g934"],"affectedPackagesSource":null,"patchAvailable":true,"disclosureDate":"2026-09-24T19:48:34.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality","integrity"],"aiComponentTargeted":"agent","llmSpecific":false,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":["AML.T0051"]}],"meta":{"total":290,"limit":20,"offset":0}}