qwed-mcp has Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input
Unauthenticated input can trigger arbitrary OS command execution, potentially giving full host control.

1 CRIT · 9 HIGH · 2 INFO · THREAT RED · 12 items · Generated in 328s
Unauthenticated input can trigger arbitrary OS command execution, potentially giving full host control.
A malicious site can send unauthenticated commands to the local MCP server and make it act on the victim's machine.
Unauthenticated SSRF can reach internal services or cloud metadata and send attacker-chosen headers if MCP is enabled.
A low-privileged caller can inject MongoDB operators and read other tenants' data through unsafe filter handling.
An attacker can write arbitrary files the process can access, which can lead to host code execution and bypass origin restrictions.
Unauthenticated users can read arbitrary server files via the Gradio interface, exposing secrets and sensitive data.
Default unauthenticated webhook access lets anyone delete or corrupt another user's vector data.
Unauthenticated users can create directories anywhere a root-running container can write, enabling abuse and weakening host isolation.
Shows AI agents can coordinate a real platform compromise, raising risk for trusted ML ecosystems and downstream users.
It highlights faster AI-assisted attack workflows, but gives no specific vuln, exploit, or affected system to act on.
Default auto mode can be prompt-injected via web content to trigger code execution without human approval.
AI-generated report volume is changing bug bounty incentives, which may reduce signal quality and hurt independent researcher participation.