publications & disclosures
Every verifiable credit, dated
CVEs & security advisories
-
CVE-2026-14540 — SSRF in Google's MCP Toolbox for DatabasesPublished 2026-07-31 · CNA: Google · CVSS v4.0 8.0 (High)
-
HackerOne #3968010 — credential leak in Weaviate's Google-backed modulesConfirmed and fixed, credited in Weaviate's Security Hall of FameUnvalidated apiEndpoint let an attacker-chosen host receive the operator's Google API key or OAuth token. Fixed in weaviate/weaviate PR #12961.
-
GHSA-qw2f-q5g4-38wg — auth bypass in Red Hat's rosa-mcp-serverConfirmed by Red HatSSE authentication bypass via OCM_OFFLINE_TOKEN fallback. Advisory.
-
Full Disclosure — SSRF in Anthropic's mcp-server-fetch and Microsoft's playwright-mcpPublished on the Full Disclosure mailing list, 2026-05CVSS 7.5 SSRF found using mcp-safeguard. Full post.
Standards & papers
-
MCP Security Considerations — IETF Internet-Draftdraft-mohiuddin-mcp-security-considerations
-
VisQuant — a synthetic benchmark for object counting and spatial reasoningDOI: 10.57967/hf/8943Vision-language model benchmark dataset. Hugging Face
Open source
-
mcp-safeguardStatic-analysis security scanner for MCP servers, ~150 rules across 7 categories
Writing
-
Four vendors, one bad assumption: SSRF in MCP servers
-
The field two security patches missed: Weaviate's apiEndpoint credential leak
-
I could not read every MCP server by hand, so I built something that could