qwed-mcp has Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input
Unauthenticated input can trigger arbitrary OS command execution, potentially giving full host or container compromise.

1 CRIT · 9 HIGH · 1 MED · 1 INFO · THREAT RED · 12 items · Generated in 255s
Unauthenticated input can trigger arbitrary OS command execution, potentially giving full host or container compromise.
A malicious site can send unauthenticated requests to the local MCP server and trigger actions under the victim's context.
Unauthenticated SSRF can reach internal services or cloud metadata and send attacker-controlled headers from the server.
A low-privilege caller can inject MongoDB operators into filters and read other tenants' data.
An attacker can write controlled files to arbitrary paths and potentially get code execution on the host running the MCP server.
Default unauthenticated webhook lets attackers delete or corrupt any user's vector data by spoofing user_id.
Unauthenticated attackers can run OS commands on vulnerable LiteLLM servers through the prompts test endpoint.
Unauthenticated path traversal can expose session log files and leak sensitive data from the host filesystem.
Active attacks are hitting AI components with RCE, prompt injection, and credential theft, showing real exposure in deployed AI stacks.
A prompt injection in an AI IDE could leak sensitive data from the developer environment without needing a separate CVE-tracked exploit.
Auto mode can be tricked into running attacker code and may even block cleanup, weakening trust in agent safety controls.
Highlights emerging AI and CVE reporting risks, but gives no specific exploit, affected product, or actionable vulnerability.