Skip to content
Threat Feed

Tag

Llm-Security

5 briefs RSS
high advisory

mcp-shell Insecure Configuration and Allowlist Bypass

mcp-shell versions prior to 0.6.0 suffer from default-disabled security settings and insecure allowlists, enabling unauthenticated arbitrary command execution via connected LLM agents.

PoC mcp-shell vulnerability rce mcp llm-security
2t
high advisory

Contentful MCP Tools SSRF via LLM-Controlled Parameters

The Contentful MCP tools 'export_space' and 'import_space' are vulnerable to Server-Side Request Forgery (SSRF) due to the unsafe passing of LLM-controlled 'host' and 'proxy' arguments directly to the Contentful Management API client, enabling credential exfiltration.

Contentful MCP Tools +1 ssrf llm-security credential-theft mcp
2t
critical advisory

Automated LLM-Based User Account Compromise Triage

An automated detection framework that uses Large Language Models to correlate disparate security alerts and assess potential account compromise based on behavioral indicators.

Elastic Stack identity-compromise llm-security detection-engineering automated-triage
3t
high advisory

Server-Side Request Forgery in mcp-webresearch (CVE-2026-65056)

A server-side request forgery (SSRF) vulnerability in mcp-webresearch version 0.1.7 allows attackers to bypass URL protocol validation by supplying private IP addresses, enabling them to leverage prompt injection to steer an LLM-controlled URL, forcing the server's Playwright browser to access internal network services and cloud instance metadata, which leads to the exfiltration of sensitive internal content, including credentials, into the model's context.

mcp-webresearch 0.1.7 ssrf vulnerability cloud data-exfiltration cve-2026-65056 llm-security
4t 1c
high advisory

LiteLLM Vulnerability Allows Remote Code Execution with Service Privileges

A remote, authenticated attacker can exploit a vulnerability in LiteLLM to execute arbitrary program code with the privileges of the service.

LiteLLM remote-code-execution rce vulnerability llm-security bsi
2t