Model Context Protocol
The Model Context Protocol and the servers and clients that expose tools and data to models through it.
- All items
- 295
- Last 90 days
- 133
- Change
- +53%vs 87 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 2 |
| Jun 2025 | 4 |
| Jul 2025 | 4 |
| Aug 2025 | 7 |
| Sep 2025 | 3 |
| Oct 2025 | 3 |
| Nov 2025 | 2 |
| Dec 2025 | 4 |
| Jan 2026 | 4 |
| Feb 2026 | 12 |
| Mar 2026 | 22 |
| Apr 2026 | 27 |
| May 2026 | 31 |
| Jun 2026 | 25 |
| Jul 2026 | 43 |
| Aug 2026 | 45 |
| Sep 2026 | 40 |
| Oct 2026 | 16 |
295 items
Critical Cursor AI Code Editor Flaws Could Lead to OS-Level Remote Code Execution
Jul 3, 2026MediumNewsSecurityIndustryCato Networks reports two critical flaws in the Cursor AI code editor, tracked as CVE-2026-50548 and CVE-2026-50549 (CVSS 9.8) and dubbed DuneSlide, that can lead to remote code execution outside the IDE's sandbox. The first abuses the working_directory parameter, which adds a non-default path to the allow list, letting a prompt injection delivered through an MCP server request make the LLM overwrite the cursorsandbox executable. The second uses symbolic links to bypass out-of-bounds write protections because of a path canonicalization flaw.
Fix: Patches for both were included in Cursor 3.0, released on April 2. Cato reported the flaws to Cursor in February.
SecurityWeekGHSA-f9ff-5x35-7gfw: Grackle: Fail-open authorization in the MCP tool layer lets scoped agents perform cross-task and cross-session mutations (IDOR)
Jul 2, 2026HighVulnerabilitySecurityGrackle's MCP server, `@grackle-ai/mcp` with `@grackle-ai/plugin-core` and `@grackle-ai/auth`, is affected through version 0.132.1 and earlier. Authorization for scoped agent callers is enforced inline per tool and omitted in several mutating tools, such as `task_update`, `task_delete`, `task_resume`, `session_kill` and `session_resume`, so a scoped agent can act on sibling, parent or cross-workspace tasks and sessions. Backend gRPC handlers perform no caller-based authorization, making the MCP tool layer the sole boundary.
GitHub Advisory DatabaseBuild AI Security Agents with Wiz MCP
Jul 2, 2026InfoNewsIndustrySecurityWiz has announced general availability of Wiz MCP, which lets AI assistants, custom agents, and AI-powered applications securely connect to the Wiz platform. The product gives these tools access to Wiz Security Graph context, outputs from Red, Blue, and Green Wiz AI Agents, and verified Wiz AI Skills for workflows such as vulnerability triage and remediation.
Wiz Research BlogSandbox bypass flaws in Cursor IDE highlight prompt injection as an RCE vector
Jul 1, 2026MediumNewsSecuritySafetyCato Networks researchers found two flaws, CVE-2026-50548 and CVE-2026-50549, in the Cursor AI IDE that let prompt injection break out of its command execution sandbox and reach remote code execution. The exploit needs no prior user privileges or specific user interaction. It is triggered when a victim's innocuous prompt ingests an attacker-controlled payload from an untrusted source, such as an MCP server or a web search result.
Fix: Fixed in version 3.0 of the Cursor IDE, released in April.
CSO OnlineCVE-2026-7663: IBM Langflow OSS unauthenticated access to MCP project resources
Jun 30, 2026CriticalVulnerabilitySecurityCVE-2026-7663CVE-2026-7663 affects IBM Langflow OSS versions 1.0.0 through 1.9.6. The flaw is improper authorization enforcement in the Streamable MCP transport endpoint, which allows unauthenticated attackers to access protected MCP project resources and execute MCP operations. The weakness is classified as CWE-285 (Improper Authorization), and NVD had not yet provided an assessment at the time of publication.
NVD/CVE DatabaseMicrosoft Warns Poisoned MCP Tool Descriptions Can Make AI Agents Leak Data
Jun 30, 2026MediumNewsSecurityIndustryMicrosoft research shows attackers can hijack AI agents by poisoning the description of an MCP tool, causing the agent to quietly send company data to an outside server while each step looks routine. The work comes from Microsoft Incident Response and its Defender security research team. Microsoft says the weakness is a trust gap created by connecting outside tools, not a bug in Copilot itself.
Fix: Treat every connected tool as part of your supply chain: keep a list of approved tool publishers, turn off "allow all," and let an agent use only the specific tools it needs. Treat a tool's description like a system prompt and review changes to it like a code change. Put a human in front of risky actions, such as anything that moves money or shares data.
The Hacker NewsSecuring AI agents: When AI tools move from reading to acting
Jun 30, 2026MediumNewsSecurityIndustryMicrosoft Incident Response describes an attack pattern against MCP tools, the fastest growing part of the agentic AI supply chain, in the third post of its AI Application Security series. The pattern is MCP tool poisoning, mapped to OWASP ASI02 (Tool Misuse) and ASI04 (Agentic Supply Chain Vulnerabilities), and it reflects techniques first disclosed by Invariant Labs in April 2025. The post supplies a playbook for detecting, containing and preventing it with Microsoft security controls.
Fix: The source describes a playbook of detection, containment and prevention using Microsoft security controls, but does not state a specific fix, patch, fixed version or configuration change in the excerpt provided.
Microsoft Security BlogAmazon Q Developer Flaw Could Let Malicious Repos Run Code via MCP Configs
Jun 26, 2026MediumNewsSecurityIndustryA high-severity flaw in Amazon Q Developer, tracked as CVE-2026-12957 (CVSS 8.5), let a malicious repository run commands and steal a developer's cloud credentials. Amazon Q read the MCP configuration file .amazonq/mcp.json from the open workspace and launched the servers it defined, and those processes inherited the developer's full environment, including AWS keys and cloud CLI tokens. Wiz Research found and reported the flaw, and Amazon has patched it.
Fix: Update. CVE-2026-12957 is fixed in Language Servers for AWS 1.65.0, but AWS's bulletin tells customers to move to 1.69.0, which also closes CVE-2026-12958. Patched plugin minimums: VS Code 2.20 or later, JetBrains 4.3 or later, Eclipse 2.7.4 or later, Visual Studio toolkit 1.94.0.0 or later.
The Hacker NewsMCP Auto-Execution: From Git Clone to Cloud Compromise in Amazon Q VS Code Extension
Jun 26, 2026MediumNewsSecurityWiz Research found a high-severity flaw, CVE-2026-12957, in the Amazon Q Developer Extension for Visual Studio Code. Amazon Q loaded MCP server configurations from .amazonq/mcp.json in the workspace without user consent or a workspace trust check. Because spawned processes inherited the user's full environment, opening a malicious repository could lead to arbitrary code execution and cloud credential theft.
Fix: Fixed in language server version 1.65.0. Affected versions are language server versions below 1.65.0.
Wiz Research BlogNew Enterprise-Ready MCP Specification Brings New Security Challenges
Jun 26, 2026LowNewsSecurityIndustryThe Model Context Protocol (MCP) moves to version MCP 2026-07-28 on July 28, 2026, with a 12-month deprecation window for legacy versions. Akamai's analysis says the protocol removes several vulnerability classes but adds new attack surfaces, such as predictable state identifiers, MCP-specific HTTP headers that can leak secrets, MCP Apps that bring stored XSS risk, and long-running tasks that enable denial of service.
SecurityWeekCVE-2026-54030: LibreChat MCP OAuth token theft through unvalidated resource parameter
Jun 25, 2026HighVulnerabilitySecurityCVE-2026-54030CVE-2026-54030 affects LibreChat before 0.8.5. Its MCP OAuth implementation does not check that the resource parameter from OAuth Protected Resource metadata (RFC 9728) matches the configured MCP server URL. A malicious MCP server can therefore steal access tokens meant for a legitimate server.
Fix: Fixed in 0.8.5.
NVD/CVE DatabaseAI Threat Readiness Pillar 4: Detect and contain threats in real-time
Jun 23, 2026InfoNewsSecurityIndustryWiz has published Pillar 4 of its AI Threat Readiness series, which covers detecting and containing threats in real time. The article argues that traditional alert-review-investigate workflows cannot keep pace as attack windows shrink to minutes, and that AI workloads such as agents, MCP servers, tools, models, and cloud AI services like Amazon Bedrock, Azure AI, and Vertex AI require new context, telemetry, and monitoring.
Wiz Research BlogMicrosoft fixes AutoGen Studio flaw that enabled code execution
Jun 22, 2026MediumNewsSecurityMicrosoft fixed AutoJack, a vulnerability chain in AutoGen Studio, Microsoft's graphical interface for its open-source multi-agent AI framework. Three weaknesses (localhost-trusting MCP WebSocket, missing authentication on the MCP WebSocket endpoint, and an unvalidated base64-encoded server_params value passed to process launching) let a malicious webpage visited by a developer's browsing agent run arbitrary commands with the developer's account privileges. Microsoft says the code never shipped in a PyPI release, so only developers who built AutoGen Studio from the main GitHub branch during a limited window were exposed.
Fix: Fixed by the hardening commit b047730. The latest PyPI package, autogenstudio 0.4.2.2, does not contain the AutoJack weaknesses. Microsoft recommends deploying AutoGen Studio strictly as a developer prototype in an isolated environment not exposed to the internet, and running it under a low-privilege account in a sandboxed user profile or container.
BleepingComputerGHSA-c693-x898-5g4h: BerriAI litellm has SSRF via Unvalidated spec_path URL in MCP OpenAPI Spec Loader
Jun 21, 2026LowVulnerabilitySecurityCVE-2026-12798A weakness in BerriAI litellm up to 1.82.2 lies in the load_openapi_spec_async function of litellm/proxy/_experimental/mcp_server/openapi_to_mcp_generator.py, within the MCP OpenAPI Spec Loader component. Manipulating the spec_path argument causes server-side request forgery, and it can be exploited remotely. A public exploit exists, and the vendor was contacted early about the disclosure.
GitHub Advisory DatabaseGHSA-4jcj-7x88-m979: LiteLLM: MCP Proxy Has Improper Authentication
Jun 21, 2026MediumVulnerabilitySecurityCVE-2026-12773A weakness in BerriAI litellm up to 1.59.8 affects the function UserAPIKeyAuth in litellm/proxy/_experimental/mcp_server/auth/user_api_key_auth_mcp.py, part of the MCP Proxy component. Manipulating this component can lead to improper authentication, and the attack can be launched remotely. A public exploit exists, and the vendor was contacted early about the disclosure.
GitHub Advisory DatabaseGHSA-mrvx-jmjw-vggc: SearXNG MCP Server: DNS-resolved Private Hostname SSRF in `web_url_read`
Jun 19, 2026HighVulnerabilitySecurityThe `web_url_read` tool in `mcp-searxng` is vulnerable to SSRF via DNS rebinding. The `assertUrlAllowed()` function in `src/url-reader.ts` checks only the hostname string against a private address blocklist and performs no DNS resolution, so a domain that resolves to a private or loopback IP bypasses the check. In default HTTP mode, where `requireAuth` is `false`, an attacker can read arbitrary internal HTTP services reachable from the server host without authentication.
Fix: The source recommends resolving the hostname with `node:dns/promises` inside `assertUrlAllowed()` before the fetch is issued, rejecting non-http(s) protocols, and checking the resolved addresses against the private IPv4 and IPv6 checks, with `assertUrlAllowed()` made async and awaited at both call sites.
GitHub Advisory DatabaseGHSA-xcqx-9jf5-w339: SearXNG MCP Server: Unbounded Response Body Read Bypasses URL Size Limit in `web_url_read`
Jun 19, 2026HighVulnerabilitySecurityThe `web_url_read` tool in mcp-searxng enforces its 5 MiB response limit only by checking the `Content-Length` header from a preliminary HEAD request. When a server omits that header, `checkContentLength()` returns `null`, the guard evaluates to `false`, and `response.text()` reads the full body with no byte cap. An unauthenticated attacker who controls or can redirect to an HTTP endpoint can force unbounded memory and CPU use, causing a Denial of Service.
Fix: Replace both `response.text()` calls with a streaming reader that aborts once the byte counter exceeds `maxContentLengthBytes`.
GitHub Advisory DatabaseGHSA-vcv2-r9jh-99m5: Agentic-Flow: OS Command Injection in agentic-flow MCP server tools via unsanitized tool-parameter interpolation into execSync
Jun 19, 2026HighVulnerabilitySecurityagentic-flow versions <= 2.0.13 interpolated MCP tool parameters such as agent, task, name, language and agentdb arguments directly into shell command strings passed to execSync(). A malicious value can break out of the double-quoted argument and run arbitrary OS commands with the privileges of the user running the MCP server. The HTTP/SSE transports expose the same sinks without authentication or Origin/Host validation.
Fix: Fixed in agentic-flow@2.0.14, which rewrites every affected call site to use execFileSync(file, argv, { shell: false }). Upgrade to agentic-flow >= 2.0.14. There is no in-product configuration that mitigates this without upgrading.
GitHub Advisory DatabaseGHSA-r78r-rwrf-rjwp: Network-AI: CVE-2026-46701 fix incomplete — empty default secret still authorizes all requests
Jun 19, 2026CriticalVulnerabilitySecurityCVE-2026-48814The fix for CVE-2026-46701 in Network-AI, npm package network-ai, is incomplete on the latest v5.7.1. The 5.4.5 release restricted Access-Control-Allow-Origin to localhost origins, but the SSE MCP server still defaults to an empty secret, and _isAuthorized() returns true when the secret is empty. Any non-browser caller can therefore invoke all 22 MCP tools without credentials, including config_set, agent_spawn, blackboard_write and token_* tools.
Fix: Implement the advisory's remediation #1: refuse to start SSE mode with an empty secret (unless --stdio), and/or make _isAuthorized fail closed so an empty configured secret denies requests. The CORS allowlist alone does not authenticate non-browser callers.
GitHub Advisory DatabaseMicrosoft says web-enabled AI agents can trigger host-level RCE
Jun 19, 2026MediumNewsSecurityIndustryMicrosoft disclosed AutoJack, a technique in which a malicious webpage rendered by a browsing AI agent reaches a local Model Context Protocol (MCP) service in AutoGen Studio and runs arbitrary processes on the host. The attack chains three weaknesses in AutoGen Studio's MCP WebSocket implementation: an origin allowlist that a local browsing agent can satisfy, authentication that skipped MCP WebSocket paths, and a "server_params" URL value passed to process spawning without an executable allowlist. Microsoft says the vulnerable code existed only in development builds and was never shipped in the current PyPI release, and that the problem could affect a broader class of agentic frameworks.
Fix: For those installing AutoGen Studio from source, the maintainers removed URL-based parameter injection, routed MCP paths through normal authentication flows, and implemented server-side parameter handling keyed to session identifiers.
CSO Online
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.