Vulnerabilities

Summary — last 7 days

New vulnerabilities3,042▲ 436 vs. last week
Critical / high1,431▲ 190 vs. last week
New active exploitation (KEV)8▼ 2 vs. last week
Unscored (no CVSS)383▲ 168 vs. last week
–

11 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
Awaiting AnalysisMedium (6.8)0.50%—Rust RmcpAI9/16/20269/23/2026
RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.1.0, the rmcp crate's StreamableHttpClientTransport in crates/rmcp/src/transport/common/reqwest/streamable_http_client.rs builds its default_http_client with reqwest's automatic redirect policy and applies caller-supplied values from…
DeferredHigh (7.5)0.63%—RmcpAI9/16/20269/30/2026
RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.0.0, the rmcp crate's stateful Streamable HTTP server in crates/rmcp/src/transport/streamable_http_server/tower.rs allows an unauthenticated client to send a well-formed JSON-RPC POST that is not an initialization request, or an initialization…
DeferredHigh (8.2)0.20%—Rust RmcpAI9/16/20269/30/2026
RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.0.0, the rmcp crate's OAuth implementation in crates/rmcp/src/transport/auth.rs omits the RFC 9728 resource field from ResourceServerMetadata and allows discover_oauth_server_via_resource_metadata to use protected-resource metadata without…
DeferredMedium (6)0.42%—BlendermcpAI7/24/20267/30/2026
BlenderMCP before commit 30a3308 contains a path traversal vulnerability in the download_polyhaven_asset method that allows attackers to write arbitrary files by injecting traversal sequences in API response include keys. Attackers performing MITM attacks or prompt injection can supply malicious paths like…
DeferredLow (2.1)0.35%—Wonderwhy-er DesktopcommandermcpAI6/3/20267/22/2026
A security flaw has been discovered in wonderwhy-er DesktopCommanderMCP up to 0.2.38. This impacts an unknown function of the file src/search-manager.ts of the component start_search. Performing a manipulation of the argument SearchResult[] results in inefficient regular expression complexity. It is possible to…
DeferredLow (2.1)0.22%—Wonderwhy-er DesktopcommandermcpAI6/3/20267/22/2026
A vulnerability was identified in wonderwhy-er DesktopCommanderMCP 0.2.37. This affects the function readFileFromUrl of the file src/tools/filesystem.ts of the component read_file. Such manipulation of the argument url leads to server-side request forgery. The attack may be performed from remote. The exploit is…
DeferredHigh (8.8)0.24%—RmcpAI5/14/20266/17/2026
RMCP is an official Rust SDK for the Model Context Protocol. Prior to version 1.4.0, the rmcp crate's Streamable HTTP server transport (crates/rmcp/src/transport/streamable_http_server/) did not validate the incoming Host header. This allowed a malicious public website, via a DNS rebinding attack, to send…
DeferredMedium (5.5)0.59%—Florensiawidjaja BioinformcpAI4/29/20266/17/2026
A weakness has been identified in florensiawidjaja BioinfoMCP up to 7ada7918b9e515604d3c0ae264d3a9af10bf6e54. This vulnerability affects the function Upload of the file bioinfo_mcp_platform/app.py of the component Upload Endpoint. This manipulation of the argument Name causes path traversal. The attack can be…
AnalyzedLow (2.1)4.3%—Wonderwhy-er Desktopcommandermcp10/8/20256/17/2026
A vulnerability was found in wonderwhy-er DesktopCommanderMCP up to 0.2.13. The impacted element is the function CommandManager of the file src/command-manager.ts. Performing manipulation results in os command injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used.
AnalyzedLow (2.1)3.5%—Wonderwhy-er Desktopcommandermcp10/8/20256/17/2026
A vulnerability has been found in wonderwhy-er DesktopCommanderMCP up to 0.2.13. The affected element is the function extractBaseCommand of the file src/command-manager.ts of the component Absolute Path Handler. Such manipulation leads to os command injection. The attack may be performed from remote. The exploit has…
AnalyzedLow (1.1)0.25%—Wonderwhy-er Desktopcommandermcp10/8/20256/17/2026
A security vulnerability has been detected in wonderwhy-er DesktopCommanderMCP up to 0.2.13. This vulnerability affects the function isPathAllowed of the file src/tools/filesystem.ts. The manipulation leads to symlink following. The attack can only be performed from a local environment. The attack's complexity is…