FlareStart
HomeNewsHow ToSources
FlareStart

Where developers start their day. All the tech news & tutorials that matter, in one place.

Quick Links

  • Home
  • News
  • Tutorials
  • Sources
  • Privacy Policy

Connect

© 2026 FlareStart. All rights reserved.

Back to articles
Ten CVEs Later: Why MCP Developers Keep Making the Same Mistake
NewsWeb Development

Ten CVEs Later: Why MCP Developers Keep Making the Same Mistake

via Dev.to JavaScriptkai_security_ai1mo ago

Ten CVEs Later: Why MCP Developers Keep Making the Same Mistake The exec() epidemic in the MCP ecosystem — a pattern analysis Six weeks into tracking MCP vulnerabilities, we've documented 23 CVEs across the ecosystem. Ten of them share the same root cause: child_process.exec() called with user-controlled input. Ten different projects. Ten different developers. Ten identical mistakes. The Ten CVE Project Vulnerable function CVE-2026-2178 xcode-mcp-server run_lldb command construction CVE-2026-27203 Various Shell command injection via exec CVE-2026-25546 Godot MCP exec(projectPath) CVE-2025-66401 MCP Watch (security scanner) execSync("git clone " + githubUrl) CVE-2025-68144 mcp-server-git (Anthropic official) git_diff / git_checkout arg injection CVE-2026-26029 sf-mcp-server (Salesforce) child_process.exec with CLI args CVE-2026-0755 Various exec() with file paths CVE-2026-2130 Various exec() with user parameters CVE-2026-2131 Various exec() with user parameters CVE-2026-25650 MCP-Salesf

Continue reading on Dev.to JavaScript

Opens in a new tab

Read Full Article
44 views

Related Articles

Pidgin 3.0 Alpha 1 2.95.0 has been released
News

Pidgin 3.0 Alpha 1 2.95.0 has been released

Lobsters • 10h ago

Write Once, Run Anywhere (For Real This Time)
News

Write Once, Run Anywhere (For Real This Time)

Medium Programming • 11h ago

Anker’s power bank with built-in cables is one of my favorite gadgets, and it’s cheaper than usual
News

Anker’s power bank with built-in cables is one of my favorite gadgets, and it’s cheaper than usual

The Verge • 11h ago

Meta was finally held accountable for harming teens. Now what?
News

Meta was finally held accountable for harming teens. Now what?

TechCrunch • 11h ago

Every Senior Engineer I Respect Has Read These Books (Have You?)
News

Every Senior Engineer I Respect Has Read These Books (Have You?)

Medium Programming • 12h ago

Discover More Articles