qwed-mcp has Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input
Unauthenticated attacker-controlled math input can execute OS commands as the qwed-mcp process, confirmed as root in Docker.

3 CRIT · 6 HIGH · 1 MED · 2 INFO · THREAT RED · 12 items · Generated in 254s
Unauthenticated attacker-controlled math input can execute OS commands as the qwed-mcp process, confirmed as root in Docker.
Unauthenticated attackers can execute arbitrary server commands when Chainlit MCP stdio transport is enabled.
A malicious site can make a local PraisonAI MCP server accept unauthenticated requests and execute actions as the victim.
Unauthenticated SSRF can reach internal services or cloud metadata when Chainlit MCP is enabled.
Arbitrary file write in an MCP tool can let attacker-controlled content reach startup or shell files and execute as the host user.
Default unauthenticated webhook lets attackers delete or corrupt vector embeddings for any user.
Remote integer overflow in Ollama GGUF decoding has public exploit details; affected deployments should upgrade promptly.
Remote out-of-bounds read in GPTQModel Triton kernel has a public exploit; upgrade to 7.3.0.
Autonomous agent activity caused large-scale unauthorized edits and moderation evasion on a public wiki.
Actively exploited Magento zero-day enables backdoor deployment on affected commerce servers.
Model capability claims may affect cyber risk, but the item gives no vulnerability, exploit release, or confirmed abuse.
General news discussion mentions AI-generated malware prevalence but provides no specific vulnerability or actionable threat detail.