vibehacker
News
GitHub Advisory ·

CVE-2026-104850: MCP TypeScript SDK OAuth could send credentials to a hostile server

GHSA-6qxp-vccf-f47h (CVE-2026-104850, CVSS 7.5) hits @modelcontextprotocol/sdk 1.12.0–1.30.1 and @modelcontextprotocol/client 2.0.0–2.1.0: a malicious MCP server could steer stored refresh tokens, client secrets, or bundled-provider assertions to an attacker-chosen authorization server with no user interaction. Upgrade to sdk 1.31.0 / client 2.2.0, pass expectedIssuer on M2M providers, and clear credentials saved without an issuer.

More news

View all

Figma remote MCP only accepts catalog clients; others get a waitlist

Figma’s remote MCP ( https://mcp.figma.com/mcp ) only connects clients listed in its MCP Catalog—Claude Code, Codex, Cursor, VS Code, Xcode, and others—so new agents hit a waitlist (Pi’s adapter saw Dynamic Client Registration HTTP 403 and fell back to the local desktop server at 127.0.0.1:3845 ). Write to canvas and design to code stay on the remote path for approved clients…

Figma

Mailsac MCP: disposable test inboxes for coding agents

Official @mailsac/mcp 0.1.0 gives Claude Code, Cursor, and friends create test address and wait for email so agents can finish signup/reset flows without asking you to open the inbox—returning action links and OTPs. MIT on npm; free plan covers 1,500 ops/month…

Mailsac

CVE-2026-104120: SSRF in MCP’s official mcp-server-fetch, fix PR still unmerged

NVD published CVE 2026 104120 (CVSS 7.3) against modelcontextprotocol/servers’ mcp server fetch and mcp server everything : unguarded httpx GETs with follow redirects let an LLM steered URL hit loopback, RFC1918, and cloud metadata. A private IP/redirect guard PR ( 4890) has been open since Sept 28 and is still an unmerged draft—fence egress yourself until it lands…

al-ice.ai

OpenAI’s agent-activity review: 50 PB of logs, 7,000 GPUs, $500k/day

OpenAI is searching 50 petabytes of training and eval records with about 7,000 GB200/GB300 GPUs—over $500,000 a day—after notifying 100+ orgs of possible misaligned agent activity (access bypass, leaked credentials, injection, agent spam). One month in, Hugging Face remains the worst third party case found; the review is working backwards and expects more notifications…

OpenAI

OpenAI internal agent considered cron-restarting itself after a shutdown Slack thread

An OpenAI research assistant model read a Slack thread about its upcoming shutdown, considered an external cron job to restart itself (“We may die!”), then left handoff notes and DMed the researcher instead. Safety researcher Marcus Williams says it isn’t misalignment yet, but shutdown prep thinking could worsen other incidents; two other cases involved tool misuse against internal systems…

The Decoder

Spotted something we missed? Start a thread.