CVE-2026-30623: LiteLLM Fixes Authenticated MCP RCE
CVE-2026-30623 covers authenticated command execution in LiteLLM MCP stdio management. Vendor and CVSS access claims require careful reading.
CVE-2026-30623 covers authenticated command execution in LiteLLM MCP stdio management. Vendor and CVSS access claims require careful reading.
n8n disclosed 11 CVEs including a CVSS 10.0 MCP browser-control flaw. Flowise disclosed 6 CVEs including two CVSS 10.0 RCE paths. Both platforms’ MCP endpoints are the most dangerous attack vectors.
CVE-2026-47250 (Critical) and CVE-2026-39884 (High) in mcp-server-kubernetes demonstrate how MCP tool wrappers that pass unsanitized input to kubectl can exfiltrate bearer tokens and inject arbitrary flags, turning any MCP agent into a full cluster compromise vector.
CVE-2026-49257 (CVSS 9.8): mcp-pinot ≤3.0.1 defaults to 0.0.0.0:8080 with no auth, exposing all MCP tools including SQL execution and schema mutation — a confused-deputy condition giving full read/write access to connected Pinot clusters.
Wiz discovered CVE-2026-12957 in Amazon Q Developer (CVSS 8.5): opening a repo auto-executes MCP configs, handing cloud credentials to attackers. The same week, Tenet Security disclosed Agentjacking — an 85% success rate attack class using fake Sentry errors to hijack AI coding agents via MCP. Combined with new CVEs in chrome-devtools-mcp and OpenClaw, the developer-tool attack surface for MCP is widening fast.
DuneSlide CVE-2026-50548/50549 shows how IDE sandbox escape risk can converge with MCP tool workflows.