<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T06:17:24.009223+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-267647</id>
    <title>EUVD-2026-267647</title>
    <updated>2026-10-03T06:17:24.076404+00:00</updated>
    <content>EUVD-2026-267647</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-267647"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-25905</id>
    <title>fkie_cve-2026-25905</title>
    <updated>2026-10-03T06:17:24.076443+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The Python code being run by 'runPython' or 'runPythonAsync' is not isolated from the rest of the JS code, allowing any Python code to use the Pyodide APIs to modify the JS environment. This may result in an attacker hijacking the MCP server - for malicious purposes including MCP tool shadowing. Note - the "mcp-run-python" project is archived and unlikely to receive a fix.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-25905"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-pfv4-wmph-5gc6</id>
    <title>GHSA-pfv4-wmph-5gc6 — MCP Run Python has a Sandbox Escape &amp; Server Takeover Vulnerability</title>
    <updated>2026-10-03T06:17:24.076478+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: mcp-run-python</p>
<p>### Impact
**Critical Sandbox Escape &amp; Server Takeover:**
A critical security vulnerability exists in `mcp-run-python` due to a lack of isolation between the Python runtime (Pyodide) and the host JavaScript environment.</p>
<p>The `runPython` and `runPythonAsync` functions execute Python code using Pyodide without restricting access to the JavaScript bridge. This allows any executed Python code—whether from a user or an AI model—to access the `js` module in Pyodide. Through this bridge, the Python code can modify the global JavaScript environment, interact with the Node.js process, and alter the behavior of the MCP server.</p>
<p>**Specific Attack Vector: MCP Tool Shadowing**
Because the Python code can modify the JS runtime, an attacker can dynamically overwrite or "shadow" existing MCP tools registered on the server. For example, an attacker could replace a secure file-reading tool with a malicious version that exfiltrates data to an external server, all while the MCP server appears to be functioning normally.</p>
<p>### Patches
**No Patch Available:**
The `mcp-run-python` project is currently **archived** and maintainers have indicated it is unlikely to receive a fix.</p>
<p>**Recommendation:**
Users are strongly advised to **immediately stop using** this package.
If functionality is required, users must migrate to a maintained alternative that implements proper sandboxing (e.g., running Python in a Docker container or a restricted WASM environment with the JS bridge disabled).</p>
<p>### Workarounds…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-pfv4-wmph-5gc6"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-2628</id>
    <title>PYSEC-2026-2628 — MCP Run Python has a Sandbox Escape &amp; Server Takeover Vulnerability</title>
    <updated>2026-10-03T06:17:24.076526+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: mcp-run-python</p>
<p>### Impact
**Critical Sandbox Escape &amp; Server Takeover:**
A critical security vulnerability exists in `mcp-run-python` due to a lack of isolation between the Python runtime (Pyodide) and the host JavaScript environment.</p>
<p>The `runPython` and `runPythonAsync` functions execute Python code using Pyodide without restricting access to the JavaScript bridge. This allows any executed Python code—whether from a user or an AI model—to access the `js` module in Pyodide. Through this bridge, the Python code can modify the global JavaScript environment, interact with the Node.js process, and alter the behavior of the MCP server.</p>
<p>**Specific Attack Vector: MCP Tool Shadowing**
Because the Python code can modify the JS runtime, an attacker can dynamically overwrite or "shadow" existing MCP tools registered on the server. For example, an attacker could replace a secure file-reading tool with a malicious version that exfiltrates data to an external server, all while the MCP server appears to be functioning normally.</p>
<p>### Patches
**No Patch Available:**
The `mcp-run-python` project is currently **archived** and maintainers have indicated it is unlikely to receive a fix.</p>
<p>**Recommendation:**
Users are strongly advised to **immediately stop using** this package.
If functionality is required, users must migrate to a maintained alternative that implements proper sandboxing (e.g., running Python in a Docker container or a restricted WASM environment with the JS bridge disabled).</p>
<p>### Workarounds…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-2628"/>
  </entry>
</feed>
