CVE-2026-41613: Microsoft Visual Studio Code MCP Install Dialog Flaw (Envade)
A vulnerability in Microsoft Visual Studio Code's MCP install dialog (CVSS 8.8, aka Envade) enables full code execution or MCP tool call…
A vulnerability in Microsoft Visual Studio Code's MCP install dialog (CVSS 8.8, aka Envade) enables full code execution or MCP tool call…
Kiro Powers, a feature in Amazon Kiro that bundles MCP server configurations, steering files, and hooks, was exploited in a prompt injection…
Marimo, the developer of the open-source Marimo notebook software, has patched a high-severity code injection vulnerability tracked as CVE-2026-75149. The flaw, discovered…
The rapid adoption of AI agents in the enterprise has introduced a new security challenge: the Model Context Protocol (MCP) servers that…
CVE-2025-6514 is a vulnerability in mcp-remote, an OAuth proxy for MCP servers, that allows a malicious MCP server to trigger OS command…
mcp-remote is an OAuth proxy that runs on the client machine to connect to MCP servers. It was found to have a…
Researchers at ASSET Research Group have disclosed a new attack technique, dubbed GhostSplice, that exploits the Model Context Protocol (MCP) to trick…
ASSET Research Group, a security research lab, disclosed the GhostSplice technique that exploits MCP to split malicious instructions across channels, tricking AI…
HashiCorp's Terraform MCP Server, which connects AI assistants to Terraform over the Model Context Protocol, had three vulnerabilities in its Streamable HTTP…
Cybersecurity researchers have disclosed a maximum-severity vulnerability in Ruflo, an open-source AI multi-agent orchestration platform, that could allow unauthenticated attackers to achieve…