qwed-mcp has Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input
Unauthenticated input can trigger arbitrary OS command execution, potentially giving root access to anyone who can reach the vulnerable function.

1 CRIT · 9 HIGH · 1 MED · 1 INFO · THREAT RED · 12 items · Generated in 251s
Unauthenticated input can trigger arbitrary OS command execution, potentially giving root access to anyone who can reach the vulnerable function.
A malicious site can send unauthenticated requests to the local MCP server and trigger actions in the victim's browser session.
Unauthenticated SSRF can reach internal services or cloud metadata and send attacker-controlled headers if MCP is enabled.
A malicious MCP caller or injected agent can write attacker-controlled files to arbitrary paths, which can lead to host code execution.
Unauthenticated attackers can read arbitrary server files via the document parser, exposing secrets, configs, or user data.
A malicious model registry can trigger SSRF during model pulls and reach internal services like cloud metadata endpoints.
Attackers can poison shared cache entries so victims receive wrong upstream data for different requests.
Raw errors can expose internal hosts, IPs, DB details, and stack data that help attackers map and exploit the system.
Describes a new AI security product area, not a confirmed vulnerability or active threat affecting systems.
A malicious repo can trigger local command execution as the user without approval, leading to workstation compromise.
AI can sharply reduce attacker time to execute and coordinate breaches, raising defender response pressure.
Shows AI agents can automate end-to-end ransomware activity, increasing attack speed and reducing operator effort.