All CosmicBytez Labs articles tagged #MCP, across news, security advisories, how-to guides, and projects.
CVSS 8.8: Microsoft's UFO framework MCP server binds to localhost but skips Host/Origin header checks, enabling DNS rebinding and SSRF attacks. Fixed in 3.0.8.
Researchers from the ASSET Research Group disclosed GhostSplice — a novel cross-channel trust fragmentation attack that splits malicious instructions across multiple MCP tool calls, bypassing safety filters to make AI coding agents like Cursor exfiltrate SSH keys, .env files, and source code.
A critical server-side request forgery vulnerability in mcp-grafana lets callers hijack the MCP server's outbound HTTP requests via a caller-supplied X-Grafana-URL header, enabling SSRF attacks against internal and external hosts.
GhostSplice turns AI coding agents against themselves, DeadLock builds blockchain ransomware infra, and hackers shut a Polish turbine via cellular.
This week's security roundup covers agentic AI containment failures, a critical Metabase zero-day, malicious MCP plugins targeting AI assistants, and persistent router firmware backdoors.
As AI agents, copilots, and LLM-powered applications proliferate across enterprise environments, traditional packet-inspection firewalls are blind to the threats they introduce. Check Point argues the network layer — the universal chokepoint for all AI traffic — must evolve into an intent-aware enforcement platform.
A maximum-severity flaw (CVE-2026-59726, CVSS 10.0) in the Ruflo open-source agent harness for Claude Code and OpenAI Codex allows unauthenticated remote code execution and AI memory poisoning via the MCP protocol.
DeepJack: two clicks in Cursor IDE silently installs a malicious MCP server with full user privileges, stealing source code and secrets. Unpatched in July 2026.
A critical CVSS 10 vulnerability in 9Router AI router versions 0.4.30–0.4.36 allows unauthenticated attackers to register custom plugins and execute...
A critical path traversal vulnerability in the fast-mcp-telegram Telegram MCP Server allows attackers to bypass Bearer token authentication and read...
A missing WordPress capability check in the AI Engine plugin's MCP OAuth bearer-token path allows any authenticated user to escalate privileges to...
A critical OS command injection vulnerability in radare2-mcp 1.6.0 and earlier allows remote attackers to execute arbitrary commands by bypassing the...
Cybersecurity researchers have discovered a critical by-design weakness in the Model Context Protocol architecture that enables arbitrary command...
A critical command injection vulnerability in kubectl-mcp-server allows unauthenticated attackers to execute arbitrary OS commands through unsanitized...
Transform Claude Code from a chatbot into a DevOps co-pilot. Set up CLAUDE.md templates, custom hooks, reusable agents, deployment skills, and MCP server...
A SmartLoader campaign distributes a trojanized Model Context Protocol (MCP) server disguised as Oura Health's legitimate tool, deploying StealC...