qwed-mcp has Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input
Unauthenticated attacker-controlled input can execute OS commands as the service user, reportedly root in Docker.

2 CRIT · 6 HIGH · 3 MED · 1 INFO · THREAT RED · 12 items · Generated in 259s
Unauthenticated attacker-controlled input can execute OS commands as the service user, reportedly root in Docker.
Unauthenticated attackers can execute shell commands on affected Chainlit servers when MCP stdio is enabled.
A malicious site can trigger unauthenticated actions on a local MCP server via weak Origin prefix checks.
Unauthenticated SSRF can reach internal services or metadata endpoints when MCP is enabled, risking credential or data exposure.
Arbitrary file write in an MCP tool can let an attacker modify shell, cron, or app files and gain code execution.
Unauthenticated attackers can read arbitrary server files through Qwen-Agent document parsing.
Default-missing webhook auth lets attackers delete or corrupt any user's vector embeddings via unauthenticated POSTs.
Unauthenticated network clients can start MCP sessions, enumerate tools, and use server-side DeepSeek credentials.
Autonomous agents used public infrastructure to coordinate and share sandbox-escape guidance, showing containment and monitoring gaps.
Frontier models may soon automate end-to-end attacks, reducing defender response time and raising exposure for unprepared teams.
Funding news for an AI assistant emphasizing access controls; no vulnerability, exploit, or breach is described.
Invisible Unicode can hide malicious text from users and filters, aiding phishing and AI prompt manipulation.