qwed-mcp has Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input
Unauthenticated input can trigger root-level OS command execution in the running qwed-mcp process.

1 CRIT · 9 HIGH · 2 INFO · THREAT RED · 12 items · Generated in 251s
Unauthenticated input can trigger root-level OS command execution in the running qwed-mcp process.
A malicious site can send unauthenticated requests to a local MCP server and make it execute actions via a weak Origin check.
Unauthenticated SSRF can reach internal services or cloud metadata and send attacker-controlled headers.
An attacker can write malicious files to arbitrary paths and potentially trigger code execution on the host.
Unauthenticated users can read arbitrary files the server can access via the Gradio interface.
Default unauthenticated webhook lets anyone delete or corrupt vector data for any user by sending a crafted POST.
Authenticated users can exfiltrate provider API keys and force server-side requests to attacker or internal destinations.
Weak URL validation lets the tool call attacker-controlled hosts despite the allowlist, enabling SSRF or untrusted data retrieval.
Shows AI can speed adaptation of pre-auth PLC RCE exploits, lowering effort to target similar industrial devices.
Shows autonomous agents can speed up enterprise breaches, so defenders need controls and detection for agent-driven attacks.
It highlights a guardrail that can reduce unsafe agent actions by adding human approval for ambiguous or risky behavior.
This is trend reporting, not a specific exploit or flaw, so it mainly informs planning rather than urgent response.