| ID | Severity | Project | Issue |
|---|---|---|---|
| CVE-2026-54052 | Critical (9.9) | czlonkowski/n8n-mcp | Cross-tenant access to workflow version backups in multi-tenant HTTP deployments |
| CVE-2026-71963 | High | NousResearch/hermes-agent | Remote code execution via git core.fsmonitor config injection from an untrusted repository |
| CVE-2026-46519 | High | Flux159/mcp-server-kubernetes | Tool access control bypass: presentation-layer filtering without execution-layer enforcement |
| CVE-2026-72718 | High | aaif-goose/goose | Arbitrary command execution via goose review abusing git core.fsmonitor |
| CVE-2026-77243 | High | sooperset/mcp-atlassian | ENABLED_TOOLS / toolset authorization bypass |
| CVE-2026-73496 | High | sooperset/mcp-atlassian | Arbitrary server-side file read via attachment upload |
- GitSpawn: A Single Flaw Lets Untrusted Repos Run Code in Claude Code, Codex, Cursor, and Grok
- Cursor CLI Ran Untrusted Repository Code With the Sandbox Switched Off
- Anyone with an Account Could Run Commands on PewDiePie's AI Workspace (CVSS 9.9)
- The "Restricted" Deployment That Wasn't: Two Access-Control Bugs in community-built mcp-atlassian
- When Your AI Reviewer Works for the Attacker: A Confused-Deputy Bug in Microsoft's Azure DevOps MCP Server
- CVE-2026-54052: A Wrong Number in n8n-mcp Leaked Your Neighbor's Credentials
- When "Read-Only Mode" Isn't: CVE-2026-46519 in mcp-server-kubernetes
- When HttpOnly Isn't Enough: Chaining XSS and GhostScript for Full RCE Compromise
- agent2shell - Programmable reverse shell interface for AI agents. Catches reverse shells over TCP, exposes them via Unix sockets. Built in Go.
