<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 17:31:12 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-267647</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-267647</link>
      <description>EUVD-2026-267647</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-267647</guid>
    </item>
    <item>
      <title>fkie_cve-2026-25905</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-25905</link>
      <description>&lt;p&gt;The Python code being run by &amp;#39;runPython&amp;#39; or &amp;#39;runPythonAsync&amp;#39; is not isolated from the rest of the JS code, allowing any Python code to use the Pyodide APIs to modify the JS environment. This may result in an attacker hijacking the MCP server - for malicious purposes including MCP tool shadowing. Note - the &amp;#34;mcp-run-python&amp;#34; project is archived and unlikely to receive a fix.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Python code being run by &amp;#39;runPython&amp;#39; or &amp;#39;runPythonAsync&amp;#39; is not isolated from the rest of the JS code, allowing any Python code to use the Pyodide APIs to modify the JS environment. This may result in an attacker hijacking the MCP server - for malicious purposes including MCP tool shadowing. Note - the &amp;#34;mcp-run-python&amp;#34; project is archived and unlikely to receive a fix.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-25905</guid>
    </item>
    <item>
      <title>GHSA-pfv4-wmph-5gc6 — MCP Run Python has a Sandbox Escape &amp; Server Takeover Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-pfv4-wmph-5gc6</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: mcp-run-python&lt;/p&gt;
&lt;p&gt;### Impact
**Critical Sandbox Escape &amp;amp; Server Takeover:**
A critical security vulnerability exists in `mcp-run-python` due to a lack of isolation between the Python runtime (Pyodide) and the host JavaScript environment.&lt;/p&gt;
&lt;p&gt;The `runPython` and `runPythonAsync` functions execute Python code using Pyodide without restricting access to the JavaScript bridge. This allows any executed Python code—whether from a user or an AI model—to access the `js` module in Pyodide. Through this bridge, the Python code can modify the global JavaScript environment, interact with the Node.js process, and alter the behavior of the MCP server.&lt;/p&gt;
&lt;p&gt;**Specific Attack Vector: MCP Tool Shadowing**
Because the Python code can modify the JS runtime, an attacker can dynamically overwrite or &amp;#34;shadow&amp;#34; existing MCP tools registered on the server. For example, an attacker could replace a secure file-reading tool with a malicious version that exfiltrates data to an external server, all while the MCP server appears to be functioning normally.&lt;/p&gt;
&lt;p&gt;### Patches
**No Patch Available:**
The `mcp-run-python` project is currently **archived** and maintainers have indicated it is unlikely to receive a fix.&lt;/p&gt;
&lt;p&gt;**Recommendation:**
Users are strongly advised to **immediately stop using** this package.
If functionality is required, users must migrate to a maintained alternative that implements proper sandboxing (e.g., running Python in a Docker container or a restricted WASM environment with the JS bridge disabled).&lt;/p&gt;
&lt;p&gt;### Workarounds…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: mcp-run-python&lt;/p&gt;
&lt;p&gt;### Impact
**Critical Sandbox Escape &amp;amp; Server Takeover:**
A critical security vulnerability exists in `mcp-run-python` due to a lack of isolation between the Python runtime (Pyodide) and the host JavaScript environment.&lt;/p&gt;
&lt;p&gt;The `runPython` and `runPythonAsync` functions execute Python code using Pyodide without restricting access to the JavaScript bridge. This allows any executed Python code—whether from a user or an AI model—to access the `js` module in Pyodide. Through this bridge, the Python code can modify the global JavaScript environment, interact with the Node.js process, and alter the behavior of the MCP server.&lt;/p&gt;
&lt;p&gt;**Specific Attack Vector: MCP Tool Shadowing**
Because the Python code can modify the JS runtime, an attacker can dynamically overwrite or &amp;#34;shadow&amp;#34; existing MCP tools registered on the server. For example, an attacker could replace a secure file-reading tool with a malicious version that exfiltrates data to an external server, all while the MCP server appears to be functioning normally.&lt;/p&gt;
&lt;p&gt;### Patches
**No Patch Available:**
The `mcp-run-python` project is currently **archived** and maintainers have indicated it is unlikely to receive a fix.&lt;/p&gt;
&lt;p&gt;**Recommendation:**
Users are strongly advised to **immediately stop using** this package.
If functionality is required, users must migrate to a maintained alternative that implements proper sandboxing (e.g., running Python in a Docker container or a restricted WASM environment with the JS bridge disabled).&lt;/p&gt;
&lt;p&gt;### Workarounds…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-pfv4-wmph-5gc6</guid>
    </item>
    <item>
      <title>PYSEC-2026-2628 — MCP Run Python has a Sandbox Escape &amp; Server Takeover Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-2628</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: mcp-run-python&lt;/p&gt;
&lt;p&gt;### Impact
**Critical Sandbox Escape &amp;amp; Server Takeover:**
A critical security vulnerability exists in `mcp-run-python` due to a lack of isolation between the Python runtime (Pyodide) and the host JavaScript environment.&lt;/p&gt;
&lt;p&gt;The `runPython` and `runPythonAsync` functions execute Python code using Pyodide without restricting access to the JavaScript bridge. This allows any executed Python code—whether from a user or an AI model—to access the `js` module in Pyodide. Through this bridge, the Python code can modify the global JavaScript environment, interact with the Node.js process, and alter the behavior of the MCP server.&lt;/p&gt;
&lt;p&gt;**Specific Attack Vector: MCP Tool Shadowing**
Because the Python code can modify the JS runtime, an attacker can dynamically overwrite or &amp;#34;shadow&amp;#34; existing MCP tools registered on the server. For example, an attacker could replace a secure file-reading tool with a malicious version that exfiltrates data to an external server, all while the MCP server appears to be functioning normally.&lt;/p&gt;
&lt;p&gt;### Patches
**No Patch Available:**
The `mcp-run-python` project is currently **archived** and maintainers have indicated it is unlikely to receive a fix.&lt;/p&gt;
&lt;p&gt;**Recommendation:**
Users are strongly advised to **immediately stop using** this package.
If functionality is required, users must migrate to a maintained alternative that implements proper sandboxing (e.g., running Python in a Docker container or a restricted WASM environment with the JS bridge disabled).&lt;/p&gt;
&lt;p&gt;### Workarounds…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: mcp-run-python&lt;/p&gt;
&lt;p&gt;### Impact
**Critical Sandbox Escape &amp;amp; Server Takeover:**
A critical security vulnerability exists in `mcp-run-python` due to a lack of isolation between the Python runtime (Pyodide) and the host JavaScript environment.&lt;/p&gt;
&lt;p&gt;The `runPython` and `runPythonAsync` functions execute Python code using Pyodide without restricting access to the JavaScript bridge. This allows any executed Python code—whether from a user or an AI model—to access the `js` module in Pyodide. Through this bridge, the Python code can modify the global JavaScript environment, interact with the Node.js process, and alter the behavior of the MCP server.&lt;/p&gt;
&lt;p&gt;**Specific Attack Vector: MCP Tool Shadowing**
Because the Python code can modify the JS runtime, an attacker can dynamically overwrite or &amp;#34;shadow&amp;#34; existing MCP tools registered on the server. For example, an attacker could replace a secure file-reading tool with a malicious version that exfiltrates data to an external server, all while the MCP server appears to be functioning normally.&lt;/p&gt;
&lt;p&gt;### Patches
**No Patch Available:**
The `mcp-run-python` project is currently **archived** and maintainers have indicated it is unlikely to receive a fix.&lt;/p&gt;
&lt;p&gt;**Recommendation:**
Users are strongly advised to **immediately stop using** this package.
If functionality is required, users must migrate to a maintained alternative that implements proper sandboxing (e.g., running Python in a Docker container or a restricted WASM environment with the JS bridge disabled).&lt;/p&gt;
&lt;p&gt;### Workarounds…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-2628</guid>
    </item>
  </channel>
</rss>
