qwed-mcp has Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input
Unauthenticated input can trigger arbitrary OS command execution in the running process, enabling full host or container compromise.

3 CRIT · 7 HIGH · 2 INFO · THREAT RED · 12 items · Generated in 253s
Unauthenticated input can trigger arbitrary OS command execution in the running process, enabling full host or container compromise.
A malicious site can send unauthenticated requests to the local MCP server and trigger actions by abusing weak Origin validation.
Unauthenticated SSRF can reach internal services or cloud metadata and send attacker-controlled headers.
A low-privileged caller can inject MongoDB operators into filters and read other tenants' data across the shared store.
Arbitrary file write can let attackers place malicious files and potentially gain code execution on the host.
Unauthenticated users can read arbitrary server files via the document parser, exposing secrets, configs, or other sensitive data.
A malicious model artifact can trigger code execution during load even when the pickle safety control is set to block it.
Remote model code can persist on disk without consent and may be executed later from cache during trusted loads.
Shows AI can help adapt exploits across PLC models, which may lower effort for attackers targeting industrial systems.
Unauthenticated RCE in Langflow lets attackers steal OpenAI and AWS keys and take over connected AI workflows.
Product announcement about faster vuln detection, not a specific AI vulnerability or incident.
An exploited critical flaw in Langflow can let attackers compromise AI app environments and hit exposed platform users now.