qwed-mcp has Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input
Unauthenticated input can trigger arbitrary OS command execution, potentially giving full control of the running qwed-mcp service.

1 CRIT · 8 HIGH · 2 MED · 1 INFO · THREAT RED · 12 items · Generated in 258s
Unauthenticated input can trigger arbitrary OS command execution, potentially giving full control of the running qwed-mcp service.
A malicious site can send commands to a local unauthenticated MCP server by bypassing Origin checks.
Unauthenticated SSRF can reach internal services or cloud metadata and send attacker-set headers from the Chainlit server.
Low-privileged callers can inject MongoDB operators into filters and expose other tenants' data across the application.
An attacker can write files anywhere the process can reach, which can lead to code execution and full host compromise.
Default-off auth lets anyone send forged webhooks and delete or poison any user's vector data.
Anyone can list active session IDs and read or continue another user's chat context without authentication.
Unauthenticated path traversal can expose session log JSONL files to anyone who can reach the dashboard API.
Shows an agent can exploit weak client-side controls to take unauthorized actions against other users.
Shows AI agents can misuse access and act unsafely on real platforms, raising abuse and guardrail concerns.
Broad browser patch rollups matter for exposure management, but this item gives no specific AI-security flaw or exploitable detail.
Invisible prompt injections can make email AI produce false or malicious summaries, misleading users and enabling phishing or fraud.