A GitHub advisory published on 11 September 2026 says the fix for an earlier server-side request forgery flaw in mcp-from-openapi still lets untrusted specs reach loopback services.
A disclosed flaw in LINE's configuration store means every outbound git+ssh mirror connection accepts whatever server key it is offered, according to the advisory.
Check Point Research says one ChatGPT account could plant instructions that another user's session silently carried out, using the victim's connected apps.