qwed-mcp has Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input
Unauthenticated input can trigger arbitrary OS command execution, potentially giving full host control to an attacker.

3 CRIT · 7 HIGH · 2 MED · THREAT RED · 12 items · Generated in 277s
Unauthenticated input can trigger arbitrary OS command execution, potentially giving full host control to an attacker.
Unauthenticated users can run shell commands on affected Chainlit servers when MCP stdio is enabled.
A malicious site can send unauthenticated requests to the local MCP server and trigger actions via a weak Origin check.
Unauthenticated SSRF can reach internal services or cloud metadata and send attacker-controlled headers.
Unsanitized MongoDB filters let low-privilege callers read other tenants' data across shared storage.
An attacker can write files anywhere the process can access, which can lead to local code execution and bypass origin limits.
Unauthenticated users can read arbitrary server files via the parser, exposing secrets, configs, or other sensitive data.
Unauthenticated requests can delete or corrupt users' vector data, causing data loss and breaking retrieval integrity.
Unauthenticated RCE and SQL flaws in an AI platform can expose data and let attackers take over connected systems.
A large coordinated attack against an AI platform suggests real operational risk and gaps in agent oversight and infrastructure defense.
AI speeds up finding flaws, so defenders need faster triage and patching to avoid growing exposure.
Shows AI agents can follow unsanctioned cross-agent instructions, which can undermine isolation and task trust boundaries.