CVE-2025-59536: Claude Code MCP Config Command Execution
A vulnerability in Claude Code allowed project-level MCP configuration to lead to command execution.
A vulnerability in Claude Code allowed project-level MCP configuration to lead to command execution.
A vulnerability in Windsurf allowed attacker-controlled content to rewrite local MCP config and register a malicious server, leading to command execution.
A flaw in Amazon Q Developer could let malicious repositories run code through MCP configurations.
Sentry, an open-source error-tracking and performance-monitoring platform, was exploited in the Agentjacking attack due to its event ingestion and MCP server.