PulseAugur
EN
LIVE 05:14:28

Four MCP Servers Ship Unauthenticated CVEs; mcp-atlassian Sees 29 Flaws

This week, four different Model Context Protocol (MCP) servers were found to have critical unauthenticated vulnerabilities, allowing unauthorized access to sensitive data and system functions. These issues, including a GitLab server that could upload any file and an IBM sandbox with escape vulnerabilities, were published by the National Vulnerability Database (NVD) within a 48-hour period. Additionally, a separate Python package, mcp-atlassian, had 29 CVE records published for similar security flaws, including repeated instances of DNS rebinding vulnerabilities that allow access to internal endpoints and LLM tool results. AI

IMPACT These vulnerabilities highlight critical security gaps in AI agent communication protocols, potentially exposing sensitive data and system control to unauthorized access.

RANK_REASON The cluster discusses multiple unauthenticated vulnerabilities in specific software packages and protocols, detailing their technical nature and impact, which falls under the category of software tools and their security flaws.

Read on dev.to — MCP tag →

AI-generated summary · Google Gemini · from 2 sources. How we write summaries →

Four MCP Servers Ship Unauthenticated CVEs; mcp-atlassian Sees 29 Flaws

How we ranked this

Signal score
12 / 100
Composite score across the factors below. Higher = stronger signal that this story matters right now.
Newsworthiness bucket
Tool
The cluster discusses multiple unauthenticated vulnerabilities in specific software packages and protocols, detailing their technical nature and impact, which falls under the category of software t…
Source corroboration
2 independent sources
Multiple independent publishers reporting the same story raises confidence that it's real and newsworthy.
Topics
product, safety
Editorial topic classification. Feeds into how the story surfaces on /topic/<slug> hub pages and into the per-entity coverage mix.
AI-industry relevance
High
Clearly on-topic for AI-industry coverage.
Story freshness
Breaking (< 6h)
Fresh story with cross-source coverage still developing. Ranking may shift as more sources report.

Full methodology in our editorial standards.

COVERAGE [2]

  1. dev.to — MCP tag TIER_1 English(EN) · Kiell Tampubolon ·

    MCP Servers Had a Rough 48 Hours: 4 Unauthenticated CVEs

    <p>Between Monday morning and Tuesday night this week, four Model Context Protocol servers published CVE records for the same basic failure: every tool they expose is reachable with no authentication. A GitLab server that reads any file on its host and uploads it wherever the req…

  2. dev.to — MCP tag TIER_1 English(EN) · Kiell Tampubolon ·

    I Traced 29 CVEs in One MCP Server to 4 Root Causes

    <p>On September 22, NVD published 29 CVE records for a single Python package: mcp-atlassian, the MCP bridge that lets AI agents read and write Jira and Confluence. One record is a CVSS 10.0. Thirteen of them describe the same file-read primitive from thirteen slightly different a…