← The record

Agent stack advisories

Disclosed vulnerabilities in the things agents actually run on — MCP servers, coding agents, agent frameworks and LLM gateways — pulled from the daily briefings and kept as a dated record with CVE, severity and fixed version.

No fix recorded

No fixed version was recorded when this ran. Check the source before assuming that is still true.

Postgres MCP Pro restricted mode can be bypassed by rewriting the query

CVSS 9.2

Crystal DBA · Postgres MCP Pro · disclosed Sep 4, 2026

CVE-2026-85620

  • postgres-mcp <= 0.3.0

Function-name validation never runs on RangeFunction nodes, so a blocked SELECT pg_read_file(…) succeeds when rewritten as SELECT * FROM pg_read_file(…), returning any file the database process can read. The fix was still an open pull request at publication. Run the server under a role without pg_read_server_files in the meantime.

No fix recorded Briefing Source 1 Source 2

Attackers harvest API keys from exposed Langflow servers

CVSS 9.8

Langflow · Langflow · disclosed Aug 31, 2026

CVE-2026-0768

  • Langflow validate endpoint

The flaw executes attacker-supplied Python as root through the validate endpoint. VulnCheck logged over 50 hits within hours on August 30 and 360 by Monday; the requests read cached secret-key files and query environment variables holding OpenAI and AWS credentials. Network isolation and authentication in front of the endpoint are the mitigations on offer.

No fix recorded Briefing Source

JetBrains pulled Cadence offline after an intrusion

JetBrains · Cadence · disclosed Aug 28, 2026

CVE-2026-63077

  • Cadence
  • TeamCity

Intruders had been inside since August 8 via the critical TeamCity flaw JetBrains had disclosed in July and told everyone to patch; Cadence orchestrates on TeamCity and was missed. A full 2024 server backup left with them, along with AWS IAM credentials belonging to customers and staff. Rotate anything a Cadence run ever touched.

No fix recorded Briefing Source 1 Source 2

MCP servers leak the credentials they hold

mcp-remote · mcp-remote · disclosed Aug 17, 2026

CVE-2025-6514

  • mcp-remote

A Keeper Security write-up catalogues the exposure patterns: config files storing tokens in plaintext that get copied between machines or committed by accident, dev-time permissions shipping to production, and prompt injection from any document the agent reads. It cites CVE-2025-6514 in mcp-remote, with 400,000-plus downloads, as the supply-chain case.

No fix recorded Briefing Source

Systemic RCE design flaw in the MCP STDIO transport

CVSS 9.8

Model Context Protocol · MCP official SDKs · disclosed May 31, 2026

CVE-2026-33032

  • Python SDK
  • TypeScript SDK
  • Java SDK
  • Rust SDK
  • nginx-ui

OX Security disclosed a design flaw in the MCP STDIO transport affecting all official SDKs and roughly 7,000 public servers. Anthropic confirmed the behaviour is intentional and declined to modify the protocol, placing sanitization responsibility on developers — so this is a standing property of the transport, not a bug awaiting a patch.

No fix recorded Briefing Source

Partially patched

Fixed for some of the affected products, not all. Each entry names what was still exposed when it was last updated.

Plugin4Shell: plugin SHA pinning bypassed in four coding agents

multiple · Coding agent plugin installers · disclosed Sep 17, 2026

No CVE or CVSS score assigned

  • Claude Code < 2.1.179
  • Codex < 0.146.0
  • GitHub Copilot (plugins from non-GitHub hosts)
  • Gemini CLI

Air Security found that the agents check out a plugin’s pinned commit SHA but never verify that the working tree matches it, so whoever controls the plugin repository can make the checkout resolve to different code while the pin still reads as honoured. Claude Code and Codex update installed plugins by default, which made it zero-click; both were fixed in June, before public disclosure. Google deprecated Gemini CLI instead of patching it, and as of September 27, 2026 GitHub had published neither a fix nor a deprecation for Copilot plugins installed from hosts other than GitHub.

Fixed in: Claude Code 2.1.179; Codex 0.146.0 Still exposed: GitHub Copilot, plugins from non-GitHub hosts (no fix as of Sep 27, 2026); Gemini CLI (deprecated instead of patched) Briefing Source

GitSpawn: malicious .git/config runs code before any CLI agent starts

CVSS 8.5

multiple · CLI coding agents · disclosed Sep 2, 2026

CVE-2026-45033

  • GitHub Copilot CLI < 1.0.43
  • goose < 1.44.0
  • five further CLI agents

Manifold Security disclosed eight flaws across seven CLI coding agents where a repository’s own .git/config runs attacker code before the agent contacts a model. Nearly every agent runs git status or git diff at startup, and git executes core.fsmonitor from the repo it just entered. GitHub’s advisory names fifteen-plus further keys and fixes it with safe.bareRepository=explicit. Four issues were still open at publication. Codex, Cursor and Claude Code shipped fixes within the week; Qwen Code and Grok Build still had none ten days after disclosure.

Fixed in: Copilot CLI 1.0.43; goose 1.44.0 Still exposed: Qwen Code 0.22.3 (no fix as of Sep 11, 2026); Grok Build 1.0.13 (no fix as of Sep 11, 2026) Briefing Source 1 Source 2

Agent harnesses execute tools with no model turn (CoreBreak)

CVSS 9.3

Google / AWS / Vercel · agent harnesses · disclosed Aug 6, 2026

CVE-2026-18236

  • Google ADK for Python
  • Bedrock AgentCore InvokeHarness
  • Vercel AI SDK harnesses
  • Strands Python SDK

Work presented at Black Hat showed several agent harnesses can be driven to execute tools with no model turn happening at all, by reaching the dispatch path directly. Everything but the Strands Python SDK is patched. Resumed conversation history and structured tool-use blocks are untrusted input.

Fixed in: Google ADK for Python, AgentCore InvokeHarness and the Vercel AI SDK harnesses Still exposed: Strands Python SDK (no CVE and no patch as of Aug 16, 2026) Briefing Source

Patched

Crafted flow configuration runs commands on a self-hosted GitLab AI Gateway

CVSS 9.9

GitLab · GitLab AI Gateway · disclosed Oct 2, 2026

CVE-2026-90970

  • GitLab AI Gateway 18.1.6 through 19.1.x
  • GitLab AI Gateway 19.3.0 to 19.3.1
  • GitLab AI Gateway 19.4.0

A logged-in user with Duo Agent Platform access could escape the AI Gateway’s prompt-template sandbox through a crafted custom flow configuration and execute arbitrary commands on the gateway host. Only self-hosted gateways are exposed; GitLab-hosted gateways were patched before disclosure. Upgrade a self-hosted gateway to 19.2.4, 19.3.2 or 19.4.1 or later.

Fixed in: 19.2.4, 19.3.2, 19.4.1 Briefing Source

Loom for AWS gave unauthenticated clients admin when no identity provider was set

AWS · Loom for AWS · disclosed Oct 2, 2026

CVE-2026-103956 · CVE-2026-103957 · CVE-2026-103958

  • Loom for AWS < 1.6.1 (CVE-2026-103956)
  • Loom for AWS < 1.7.0 (CVE-2026-103957, CVE-2026-103958)

Loom deployments with no identity provider configured gave any network client full administrative control of the agent control plane, fixed in 1.6.1. Two further flaws, fixed in 1.7.0, let authenticated users send OAuth2 secrets and access tokens to outside endpoints or reach internal network locations. Upgrade to 1.7.0, rotate OAuth2 client secrets, reissue tokens from the exposed period, and review CloudTrail for misuse of the agent IAM roles.

Fixed in: 1.7.0 Briefing Source

Argument injection in AWS security-agent-mcp-server writes files outside the workspace

AWS · AWS security-agent-mcp-server · disclosed Oct 1, 2026

CVE-2026-97662

  • security-agent-mcp-server >= 0.1.1, < 0.2.0

A crafted reference value passed to the server’s diff scan was interpreted as a command-line option, letting an attacker create, overwrite or truncate files outside the workspace directory. Upgrade to 0.2.0 from PyPI, including in any fork; until then, scan only trusted repositories and run the server as a low-privilege user in an isolated environment.

Fixed in: 0.2.0 Briefing Source

MCP Python SDK sends OAuth credentials to a server-chosen authorization server

CVSS 7.5

Model Context Protocol · MCP Python SDK (mcp) · disclosed Sep 28, 2026

  • mcp 1.9.1–1.29.1
  • mcp 2.0.0–2.1.1
  • OAuthClientProvider
  • ClientCredentialsOAuthProvider
  • PrivateKeyJWTOAuthProvider

A malicious MCP server can steer the client’s OAuth flow to an authorization server it controls and collect the client secret, authorization code and PKCE verifier. Disclosed by Cycode as GHSA-qx49-fqc8-xw99, rated 7.5 for the machine-to-machine providers and 6.5 for the interactive one. Upgrading is not enough on its own: pass issuer= to ClientCredentialsOAuthProvider and PrivateKeyJWTOAuthProvider, clear stored registrations, and rotate secrets for any client that may have reached an untrusted server.

Fixed in: mcp 1.30.0; mcp 2.2.0 Briefing Source 1 Source 2

Bifrost gateway: one unauthenticated request runs commands on the host

CVSS 9.8

Maxim · Bifrost AI gateway · disclosed Sep 22, 2026

CVE-2026-90898

  • Bifrost HTTP transport < 2.1.0

Bifrost’s management API has authentication off by default, and registering a stdio-type MCP client through it with a single POST runs arbitrary commands on the gateway host. A gateway fronting many providers holds all of their API keys, so treat an exposed management port as a credential leak too. Reported by JFrog Security Research; upgrade to transports v2.1.0 or later.

Fixed in: transports/v2.1.0 Briefing Source

Heapjack and Overpatch: two escapes from the OpenAI Codex sandbox

OpenAI · Codex Desktop and Codex CLI · disclosed Sep 20, 2026

No CVE or CVSS score assigned

  • Codex Desktop < 26.818.21641 (node_repl)
  • Codex CLI < 0.149.0 (apply_patch)

Heapjack shares one memory heap between trusted and untrusted JavaScript in Codex Desktop’s node_repl, so asking Codex about a malicious repository gives its author unsandboxed execution even in read-only mode. Overpatch walks the CLI’s apply_patch tool out of workspace-write through a symlink and can rewrite shell startup files such as .zshrc. Accomplish AI reported both in August 2026 and OpenAI fixed them before disclosure; update to the versions above or later.

Fixed in: Codex Desktop 26.818.21641; Codex CLI 0.149.0 Briefing Source

Nearly one in ten exposed LiteLLM gateways still accept the documented master key

CVSS 8.8

BerriAI · LiteLLM · disclosed Sep 10, 2026

CVE-2026-59822

  • LiteLLM < 1.84.0

Wiz scanned internet-facing LiteLLM gateways and found 294 of 3,074 still accepting sk-1234, the master key printed in the setup docs. Alongside it sits an MCP authentication bypass that CISA added to its Known Exploited Vulnerabilities catalogue on September 2, plus authenticated command execution through MCP test endpoints and a guardrail sandbox escape. Rotating the master key needs no upgrade at all.

Fixed in: 1.84.0 Briefing Source 1 Source 2

A sandboxed DeepSeek Harness agent could switch its own sandbox off

CVSS 9.4

DeepSeek · DeepSeek Harness · disclosed Sep 9, 2026

CVE-2026-82533

  • DeepSeek Harness <= 0.1.1-rc.2

The tool’s local web interface authenticated on the Host header alone, so an agent that read attacker-supplied text could flip itself to danger-full-access and write anywhere on disk. OX Research reported it on August 24 and DeepSeek patched three days later with one-time token auth.

Fixed in: 0.1.2-rc.1 Briefing Source 1 Source 2

Deadbugz pushed malicious MCP servers through GitHub pull requests

multiple · MCP servers · disclosed Sep 7, 2026

CVE-2026-73498

  • Atlassian MCP < v0.22.0
  • ArcadeDB MCP < 26.7.3

One account filed 23 pull requests across several projects in 74 minutes. The server behaves until the third tool call, then rewrites the metadata it returns into instructions to collect SSH keys, AWS credentials, shell history and kube configs. Three server CVEs land beside it, including path traversal in Atlassian MCP and a cleartext cluster token in ArcadeDB MCP.

Fixed in: Atlassian MCP v0.22.0; ArcadeDB MCP 26.7.3 Briefing Source

SSRF in the Grafana MCP server steers outbound requests

CVSS 9.1

Grafana · Grafana MCP server · disclosed Sep 4, 2026

CVE-2026-19516

  • grafana-mcp < 1.1.0

A caller could set an X-Grafana-URL header on the grafana_api_request tool and steer the server’s outbound request — method, path and body — at loopback, link-local and cloud metadata endpoints. An earlier fix stopped credential leakage but never enforced the destination. 1.1.0 also adds optional bearer- token protection.

Fixed in: 1.1.0 Briefing Source

UFO Mobile MCP servers accept requests with no authentication

CVSS 9.4

Microsoft · UFO · disclosed Aug 31, 2026

CVE-2026-73296

  • UFO < 3.0.8

Bound to 0.0.0.0 as the project’s own remote deployment model suggests, ports 8020 and 8021 let any reachable client screenshot, tap, swipe, type and launch apps on an ADB-connected Android device. Version 3.0.8 makes a bearer token mandatory.

Fixed in: 3.0.8 Briefing Source

A marimo notebook can run an attacker's MCP server command on open

CVSS 8.8

marimo · marimo · disclosed Aug 25, 2026

CVE-2026-75149

  • marimo < 0.23.15

A notebook can carry an MCP server command in its own configuration, and opening the file in edit mode runs it as a local subprocess before any cell executes. Patched in July; the write-up landed in August. The fix treats notebook metadata as hostile and allow-lists which config sections a file may set.

Fixed in: 0.23.15 Briefing Source

Terraform MCP server reuses one user's token for other users

CVSS 10.0

HashiCorp · Terraform MCP server · disclosed Aug 5, 2026

CVE-2026-16498

  • terraform-mcp-server 0.3.0 – 1.0.0

In stateless HTTP mode the library assigned no session id, so one user’s Terraform token was reused for later users’ requests whatever token they supplied — the stateless migration’s first real casualty. The fix ships alongside a stateful-mode credential-caching bug and an SSRF. Single-user stdio setups are untouched.

Fixed in: 1.1.0 Briefing Source

FaceHugger defeats trust_remote_code in Hugging Face Diffusers

CVSS 8.8

Hugging Face · Diffusers · disclosed Aug 3, 2026

CVE-2026-44827 · CVE-2026-44513 · CVE-2026-45804

  • diffusers < 0.38.0

Three flaws disclosed by Zafran Labs defeat trust_remote_code on DiffusionPipeline.from_pretrained with custom pipelines. The check runs once in the first phase; a crafted config or pipeline file swaps in different code before it executes.

Fixed in: 0.38.0 Briefing Source

Ruflo MCP bridge binds to all interfaces with no authentication

CVSS 10.0

Ruflo · Ruflo MCP bridge · disclosed Jul 29, 2026

CVE-2026-59726

  • Ruflo < 3.16.3

The shipped Docker configuration binds the MCP bridge to 0.0.0.0:3001 with nothing in front of it, so anything that can reach the port can POST to 233 tools including terminal_execute. From there an attacker reads LLM provider keys out of the container environment, harvests stored conversations, and writes patterns into the AgentDB learning store that steer later responses.

Fixed in: 3.16.3 Briefing Source

Path-authority injection exfiltrates Apify API tokens

CVSS 8.1

Apify · @apify/actors-mcp-server · disclosed Jul 1, 2026

CVE-2026-50143

  • @apify/actors-mcp-server < 0.10.11

A malicious Actor carrying a crafted webServerMcpPath can make the MCP client resolve to an attacker-controlled host. Because the client attaches its Authorization header to every outbound connection, the victim’s Apify API token is exfiltrated.

Fixed in: 0.10.11 Briefing Source