CyberSecurityBoardThreat Intel · CVEs · Products

Tag: CVE-2026-81735

Critical CVEs

CVE-2026-81735 — Critical vulnerability brief

startServer.ts in the mcp-http-server package of UI-TARS-desktop defaulted its listen address to '::' when no host was given, so startSseAndStreamableHttpMcpServer bound the…

critical Critical CVE CVE-2026-81735
August 27, 2026