yutu: Arbitrary File Write via MCP `caption-download` Tool
IBM Langflow OSS 1.0.0 through 1.9.6 contains a Server-Side
SearXNG MCP Server: DNS-resolved Private Hostname SSRF in `web
npm PraisonAI SandboxExecutor network-isolated mode does not block non
PraisonAI: Compute-bridged file tools allow shell command injection
Pi Agent: Potential XSS in HTML session exports via Markdown
PraisonAI ships and generates a legacy API server with authentication
wireshark-mcp vulnerable to arbitrary file write via export_objects
PPTAgent: Arbitrary Code Execution via Python eval() of LLM-Generated
OpenClaw's gateway config mutation guard allowed unsafe model-driven
OpenClaw: Agent gateway config mutations could change protected operator settings
Gemini CLI: Remote Code Execution via workspace trust and tool
SSH/SCP option injection allowing local RCE in @aiondadotcom/mcp-ssh
PraisonAIAgents: SSRF via unvalidated URL in `web_crawl` httpx fallback
PraisonAI: Hardcoded `approval_mode="auto"` in Chainlit UI Overrides Administrator