Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Multiple vulnerabilities disclosed in MCP Registry and rmcp Rust SDK

Five CVEs published on 14 May 2026 describe flaws in the Model Context Protocol ecosystem: stored XSS, open redirect, SSRF blocklist bypass, cross-deployment GitHub OIDC token reuse and fail-open OCI ownership validation in the MCP Registry, plus a missing Host-header check enabling DNS rebinding against local MCP servers in the rmcp Rust SDK. All issues were fixed in later releases (registry 1.7.5/1.7.6/1.7.7/1.7.9 and rmcp 1.4.0).

Disclosed 14 May 2026 · Record updated 13 September 2026

Impact

Attackers could hijack MCP server namespaces by binding them to OCI images they do not control, plant persistent scripts on the public registry homepage seen by all visitors, reuse publish tokens across registry deployments, reach internal/cloud-metadata services via IPv6 transition addresses, redirect users to external sites, and reach loopback or private-network MCP servers from a malicious website via DNS rebinding.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-42559
  2. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-44429
  3. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-44430
  4. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-45781
  5. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-44427
  6. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-44428