Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

UI-TARS-desktop MCP servers bind to all interfaces without authentication

The mcp-http-server package in UI-TARS-desktop defaulted to listening on all interfaces ('::') without requiring authentication, allowing unauthenticated remote attackers to execute arbitrary commands or access files on the host system.

Disclosed 27 August 2026 · Record updated 13 September 2026

Impact

Unauthenticated remote code execution and file access via exposed MCP servers (commands and filesystem) when no authentication middleware is supplied.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-81735