CVE-2026-58500: MCP Appium Fixes XSS in Locator Generator UI
A high-severity XSS in MCP Appium’s createLocatorGeneratorUI lets attacker-controlled mobile-app element attributes drive arbitrary tool execution through the MCP-UI resource. Review the affected versions, fix, and exposure conditions.