What changed in AI security, Jun 30 to Jul 6, 2025
Jun 30 to Jul 6, 2025 (ISO week 2025-W27). Weeks run Monday to Sunday in UTC.
7 records published, -6 on the previous week: 5 vulnerabilities (-6), 0 incidents (no change), 1 research item (+1), 1 news item (-1), 0 policy items (no change).
Critical and high advisories
Vulnerability records rated critical or high, newest first.- High
GHSA-3qhf-m339-9g5v: MCP Python SDK vulnerability in the FastMCP Server causes validation error, leading to DoS
CVE-2025-53366GitHub Advisory Database - High
GHSA-j975-95f5-7wqh: MCP Python SDK has Unhandled Exception in Streamable HTTP Transport, Leading to Denial of Service
CVE-2025-53365GitHub Advisory Database - High
CVE-2025-34072: Anthropic Slack MCP Server data exfiltration via automatic link unfurling
CVE-2025-34072NVD/CVE Database - High
CVE-2025-53107: @cyanheads/git-mcp-server command injection via unsanitized input
CVE-2025-53107NVD/CVE Database
Exploitation signals
Vulnerabilities published in the week that are listed in the CISA Known Exploited Vulnerabilities catalog or have an EPSS score of 10% or more.| Advisory | Exploitation | EPSS | Published |
|---|---|---|---|
| CVE-2025-53107: @cyanheads/git-mcp-server command injection via unsanitized input CVE-2025-53107NVD/CVE Database | Not listed | 24.5% |
Packages that began delegating to a language model
Exposure Registry packages whose first release declaring an LLM SDK, agent framework or MCP dependency was published in the week.| Package | Ecosystem | LLM SDKs | Release | Released |
|---|---|---|---|---|
| github.com/modelcontextprotocol/go-sdk | Go | Model Context Protocol SDK | v0.1.0 | |
| llm-sandbox | PyPI | Model Context Protocol SDK | 0.3.14 |
Topics that moved
Largest increases over the mean of the 4 previous weeks, for topics with at least 3 records in the week.| Topic | Records | Weekly mean, previous 4 | Difference |
|---|---|---|---|
| Model Context Protocol | 4 | 1.0 | +3.0 |
Research
Peer-reviewed first, then newest.Policy and regulation
Newest first.No regulatory or policy records were published in this week.
Generated from the AI Sec Watch database at . Every item links to its record.