UI-TARS-desktop MCP servers bind to all interfaces without authentication
The mcp-http-server package in UI-TARS-desktop defaulted to listening on all interfaces ('::') without requiring authentication, allowing unauthenticated remote attackers to execute arbitrary commands or access files on the host system.
Disclosed 27 August 2026 · Record updated 13 September 2026
Impact
Unauthenticated remote code execution and file access via exposed MCP servers (commands and filesystem) when no authentication middleware is supplied.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-81735
