<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 16:50:26 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-328614</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-328614</link>
      <description>EUVD-2026-328614</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-328614</guid>
    </item>
    <item>
      <title>fkie_cve-2026-48814</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-48814</link>
      <description>&lt;p&gt;Network-AI is a TypeScript/Node.js multi-agent orchestrator. In versions 5.7.1 and earlier, the MCP SSE server allows unauthenticated cross-origin MCP tool invocation due to an empty default secret. This issue was partially addressed by CVE-2026-46701 in version 5.4.5 by closing the CORS flaw (with Access-Control-Allow-Origin now set only for localhost origins), but the empty-default-secret flaw described in the title remained: the SSE MCP server still defaulted to an empty secret, _isAuthorized() still returned true when the secret was empty, and a non-loopback bind only produced a warning. As a result, the server still ran fully unauthenticated by default. Any non-browser caller (for example, curl, SSRF, or a 0.0.0.0 bind) could invoke all 22 MCP tools (config_set, agent_spawn, blackboard_write, token_*) with no credentials. This issue was fixed in version 5.7.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Network-AI is a TypeScript/Node.js multi-agent orchestrator. In versions 5.7.1 and earlier, the MCP SSE server allows unauthenticated cross-origin MCP tool invocation due to an empty default secret. This issue was partially addressed by CVE-2026-46701 in version 5.4.5 by closing the CORS flaw (with Access-Control-Allow-Origin now set only for localhost origins), but the empty-default-secret flaw described in the title remained: the SSE MCP server still defaulted to an empty secret, _isAuthorized() still returned true when the secret was empty, and a non-loopback bind only produced a warning. As a result, the server still ran fully unauthenticated by default. Any non-browser caller (for example, curl, SSRF, or a 0.0.0.0 bind) could invoke all 22 MCP tools (config_set, agent_spawn, blackboard_write, token_*) with no credentials. This issue was fixed in version 5.7.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-48814</guid>
    </item>
    <item>
      <title>GHSA-r78r-rwrf-rjwp — Network-AI: CVE-2026-46701 fix incomplete — empty default secret still authorizes all requests</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-r78r-rwrf-rjwp</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: network-ai&lt;/p&gt;
&lt;p&gt;## Advisory / Disclosure&lt;/p&gt;
&lt;p&gt;# Network-AI — CVE-2026-46701 fix is incomplete: the &amp;#34;Empty Default Secret&amp;#34; unauth path survives&lt;/p&gt;
&lt;p&gt;**Target:** Jovancoding/Network-AI (npm `network-ai`), **latest v5.7.1**
**Status:** the advisory (&amp;#34;Unauthenticated Cross-Origin MCP Tool Invocation via Empty
Default Secret&amp;#34;) named three flaws. The fix (5.4.5) closed the **CORS** flaw
(`Access-Control-Allow-Origin` is now set only for localhost origins), but left the
**empty-default-secret** flaw the title is about: the SSE MCP server still defaults to an
empty secret, `_isAuthorized()` still returns `true` when the secret is empty, and a
non-loopback bind only **warns**. So the server still runs **fully unauthenticated by
default** — any non-browser caller (curl, SSRF, or a `0.0.0.0` bind) can invoke all 22 MCP
tools (`config_set`, `agent_spawn`, `blackboard_write`, `token_*`) with no credentials.
**Class:** CWE-306/CWE-862 Missing Authentication — incomplete fix.
**Methodology:** M1 incomplete-fix audit (anchor = the 5.4.5 fix; sibling-walk on latest v5.7.1, executed).
**Severity:** High (matches parent; the browser amplifier is removed, so exploitation now
needs non-browser reach — SSRF or a non-loopback bind, which the fix only warns about).&lt;/p&gt;
&lt;p&gt;## What the fix did and didn&amp;#39;t do (verified on latest v5.7.1)
| advisory flaw | latest v5.7.1 |
|---|---|
| wildcard CORS (`ACAO: *`) | **FIXED** — `lib/mcp-transport-sse.ts` sets `ACAO` only when `origin` matches `^https?://(localhost\|127\.0\.0\.1)(:\d+)?$`…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: network-ai&lt;/p&gt;
&lt;p&gt;## Advisory / Disclosure&lt;/p&gt;
&lt;p&gt;# Network-AI — CVE-2026-46701 fix is incomplete: the &amp;#34;Empty Default Secret&amp;#34; unauth path survives&lt;/p&gt;
&lt;p&gt;**Target:** Jovancoding/Network-AI (npm `network-ai`), **latest v5.7.1**
**Status:** the advisory (&amp;#34;Unauthenticated Cross-Origin MCP Tool Invocation via Empty
Default Secret&amp;#34;) named three flaws. The fix (5.4.5) closed the **CORS** flaw
(`Access-Control-Allow-Origin` is now set only for localhost origins), but left the
**empty-default-secret** flaw the title is about: the SSE MCP server still defaults to an
empty secret, `_isAuthorized()` still returns `true` when the secret is empty, and a
non-loopback bind only **warns**. So the server still runs **fully unauthenticated by
default** — any non-browser caller (curl, SSRF, or a `0.0.0.0` bind) can invoke all 22 MCP
tools (`config_set`, `agent_spawn`, `blackboard_write`, `token_*`) with no credentials.
**Class:** CWE-306/CWE-862 Missing Authentication — incomplete fix.
**Methodology:** M1 incomplete-fix audit (anchor = the 5.4.5 fix; sibling-walk on latest v5.7.1, executed).
**Severity:** High (matches parent; the browser amplifier is removed, so exploitation now
needs non-browser reach — SSRF or a non-loopback bind, which the fix only warns about).&lt;/p&gt;
&lt;p&gt;## What the fix did and didn&amp;#39;t do (verified on latest v5.7.1)
| advisory flaw | latest v5.7.1 |
|---|---|
| wildcard CORS (`ACAO: *`) | **FIXED** — `lib/mcp-transport-sse.ts` sets `ACAO` only when `origin` matches `^https?://(localhost\|127\.0\.0\.1)(:\d+)?$`…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-r78r-rwrf-rjwp</guid>
    </item>
  </channel>
</rss>
