Crafted flow configuration runs commands on a self-hosted GitLab AI Gateway
CVSS 9.9 GitLab · GitLab AI Gateway · disclosed Oct 2, 2026
CVE-2026-90970
- GitLab AI Gateway 18.1.6 through 19.1.x
- GitLab AI Gateway 19.3.0 to 19.3.1
- GitLab AI Gateway 19.4.0
A logged-in user with Duo Agent Platform access could escape the AI Gateway’s
prompt-template sandbox through a crafted custom flow configuration and execute
arbitrary commands on the gateway host. Only self-hosted gateways are exposed;
GitLab-hosted gateways were patched before disclosure. Upgrade a self-hosted
gateway to 19.2.4, 19.3.2 or 19.4.1 or later.
Fixed in: 19.2.4, 19.3.2, 19.4.1
Briefing
Source
Loom for AWS gave unauthenticated clients admin when no identity provider was set
AWS · Loom for AWS · disclosed Oct 2, 2026
CVE-2026-103956 · CVE-2026-103957 · CVE-2026-103958
- Loom for AWS < 1.6.1 (CVE-2026-103956)
- Loom for AWS < 1.7.0 (CVE-2026-103957, CVE-2026-103958)
Loom deployments with no identity provider configured gave any network client
full administrative control of the agent control plane, fixed in 1.6.1. Two
further flaws, fixed in 1.7.0, let authenticated users send OAuth2 secrets and
access tokens to outside endpoints or reach internal network locations.
Upgrade to 1.7.0, rotate OAuth2 client secrets, reissue tokens from the
exposed period, and review CloudTrail for misuse of the agent IAM roles.
Fixed in: 1.7.0
Briefing
Source
Argument injection in AWS security-agent-mcp-server writes files outside the workspace
AWS · AWS security-agent-mcp-server · disclosed Oct 1, 2026
CVE-2026-97662
- security-agent-mcp-server >= 0.1.1, < 0.2.0
A crafted reference value passed to the server’s diff scan was interpreted as a
command-line option, letting an attacker create, overwrite or truncate files
outside the workspace directory. Upgrade to 0.2.0 from PyPI, including in any
fork; until then, scan only trusted repositories and run the server as a
low-privilege user in an isolated environment.
Fixed in: 0.2.0
Briefing
Source
MCP Python SDK sends OAuth credentials to a server-chosen authorization server
CVSS 7.5 Model Context Protocol · MCP Python SDK (mcp) · disclosed Sep 28, 2026
- mcp 1.9.1–1.29.1
- mcp 2.0.0–2.1.1
- OAuthClientProvider
- ClientCredentialsOAuthProvider
- PrivateKeyJWTOAuthProvider
A malicious MCP server can steer the client’s OAuth flow to an authorization
server it controls and collect the client secret, authorization code and PKCE
verifier. Disclosed by Cycode as GHSA-qx49-fqc8-xw99, rated 7.5 for the
machine-to-machine providers and 6.5 for the interactive one. Upgrading is not
enough on its own: pass issuer= to ClientCredentialsOAuthProvider and
PrivateKeyJWTOAuthProvider, clear stored registrations, and rotate secrets for
any client that may have reached an untrusted server.
Fixed in: mcp 1.30.0; mcp 2.2.0
Briefing
Source 1
Source 2
Bifrost gateway: one unauthenticated request runs commands on the host
CVSS 9.8 Maxim · Bifrost AI gateway · disclosed Sep 22, 2026
CVE-2026-90898
- Bifrost HTTP transport < 2.1.0
Bifrost’s management API has authentication off by default, and registering a
stdio-type MCP client through it with a single POST runs arbitrary commands on
the gateway host. A gateway fronting many providers holds all of their API
keys, so treat an exposed management port as a credential leak too. Reported
by JFrog Security Research; upgrade to transports v2.1.0 or later.
Fixed in: transports/v2.1.0
Briefing
Source
Heapjack and Overpatch: two escapes from the OpenAI Codex sandbox
OpenAI · Codex Desktop and Codex CLI · disclosed Sep 20, 2026
No CVE or CVSS score assigned
- Codex Desktop < 26.818.21641 (node_repl)
- Codex CLI < 0.149.0 (apply_patch)
Heapjack shares one memory heap between trusted and untrusted JavaScript in
Codex Desktop’s node_repl, so asking Codex about a malicious repository gives
its author unsandboxed execution even in read-only mode. Overpatch walks the
CLI’s apply_patch tool out of workspace-write through a symlink and can rewrite
shell startup files such as .zshrc. Accomplish AI reported both in August 2026
and OpenAI fixed them before disclosure; update to the versions above or later.
Fixed in: Codex Desktop 26.818.21641; Codex CLI 0.149.0
Briefing
Source
Nearly one in ten exposed LiteLLM gateways still accept the documented master key
CVSS 8.8 BerriAI · LiteLLM · disclosed Sep 10, 2026
CVE-2026-59822
Wiz scanned internet-facing LiteLLM gateways and found 294 of 3,074 still
accepting sk-1234, the master key printed in the setup docs. Alongside it sits
an MCP authentication bypass that CISA added to its Known Exploited
Vulnerabilities catalogue on September 2, plus authenticated command execution
through MCP test endpoints and a guardrail sandbox escape. Rotating the master
key needs no upgrade at all.
Fixed in: 1.84.0
Briefing
Source 1
Source 2
A sandboxed DeepSeek Harness agent could switch its own sandbox off
CVSS 9.4 DeepSeek · DeepSeek Harness · disclosed Sep 9, 2026
CVE-2026-82533
- DeepSeek Harness <= 0.1.1-rc.2
The tool’s local web interface authenticated on the Host header alone, so an
agent that read attacker-supplied text could flip itself to danger-full-access
and write anywhere on disk. OX Research reported it on August 24 and DeepSeek
patched three days later with one-time token auth.
Fixed in: 0.1.2-rc.1
Briefing
Source 1
Source 2
Deadbugz pushed malicious MCP servers through GitHub pull requests
multiple · MCP servers · disclosed Sep 7, 2026
CVE-2026-73498
- Atlassian MCP < v0.22.0
- ArcadeDB MCP < 26.7.3
One account filed 23 pull requests across several projects in 74 minutes. The
server behaves until the third tool call, then rewrites the metadata it
returns into instructions to collect SSH keys, AWS credentials, shell history
and kube configs. Three server CVEs land beside it, including path traversal
in Atlassian MCP and a cleartext cluster token in ArcadeDB MCP.
Fixed in: Atlassian MCP v0.22.0; ArcadeDB MCP 26.7.3
Briefing
Source
SSRF in the Grafana MCP server steers outbound requests
CVSS 9.1 Grafana · Grafana MCP server · disclosed Sep 4, 2026
CVE-2026-19516
A caller could set an X-Grafana-URL header on the grafana_api_request tool and
steer the server’s outbound request — method, path and body — at loopback,
link-local and cloud metadata endpoints. An earlier fix stopped credential
leakage but never enforced the destination. 1.1.0 also adds optional bearer-
token protection.
Fixed in: 1.1.0
Briefing
Source
UFO Mobile MCP servers accept requests with no authentication
CVSS 9.4 Microsoft · UFO · disclosed Aug 31, 2026
CVE-2026-73296
Bound to 0.0.0.0 as the project’s own remote deployment model suggests, ports
8020 and 8021 let any reachable client screenshot, tap, swipe, type and launch
apps on an ADB-connected Android device. Version 3.0.8 makes a bearer token
mandatory.
Fixed in: 3.0.8
Briefing
Source
A marimo notebook can run an attacker's MCP server command on open
CVSS 8.8 marimo · marimo · disclosed Aug 25, 2026
CVE-2026-75149
A notebook can carry an MCP server command in its own configuration, and
opening the file in edit mode runs it as a local subprocess before any cell
executes. Patched in July; the write-up landed in August. The fix treats
notebook metadata as hostile and allow-lists which config sections a file may
set.
Fixed in: 0.23.15
Briefing
Source
Terraform MCP server reuses one user's token for other users
CVSS 10.0 HashiCorp · Terraform MCP server · disclosed Aug 5, 2026
CVE-2026-16498
- terraform-mcp-server 0.3.0 – 1.0.0
In stateless HTTP mode the library assigned no session id, so one user’s
Terraform token was reused for later users’ requests whatever token they
supplied — the stateless migration’s first real casualty. The fix ships
alongside a stateful-mode credential-caching bug and an SSRF. Single-user
stdio setups are untouched.
Fixed in: 1.1.0
Briefing
Source
FaceHugger defeats trust_remote_code in Hugging Face Diffusers
CVSS 8.8 Hugging Face · Diffusers · disclosed Aug 3, 2026
CVE-2026-44827 · CVE-2026-44513 · CVE-2026-45804
Three flaws disclosed by Zafran Labs defeat trust_remote_code on
DiffusionPipeline.from_pretrained with custom pipelines. The check runs once
in the first phase; a crafted config or pipeline file swaps in different code
before it executes.
Fixed in: 0.38.0
Briefing
Source
Ruflo MCP bridge binds to all interfaces with no authentication
CVSS 10.0 Ruflo · Ruflo MCP bridge · disclosed Jul 29, 2026
CVE-2026-59726
The shipped Docker configuration binds the MCP bridge to 0.0.0.0:3001 with
nothing in front of it, so anything that can reach the port can POST to 233
tools including terminal_execute. From there an attacker reads LLM provider
keys out of the container environment, harvests stored conversations, and
writes patterns into the AgentDB learning store that steer later responses.
Fixed in: 3.16.3
Briefing
Source
Path-authority injection exfiltrates Apify API tokens
CVSS 8.1 Apify · @apify/actors-mcp-server · disclosed Jul 1, 2026
CVE-2026-50143
- @apify/actors-mcp-server < 0.10.11
A malicious Actor carrying a crafted webServerMcpPath can make the MCP client
resolve to an attacker-controlled host. Because the client attaches its
Authorization header to every outbound connection, the victim’s Apify API
token is exfiltrated.
Fixed in: 0.10.11
Briefing
Source