Misbar | مسبار[verified]@MisbarSecGeneral
The post announces a new SAST tool and mentions two CVEs, but it provides no technical detail, PoC, exploitation evidence, or patch information.
vanka (❖,❖)[verified]@vkampnActive Exploitation
The excerpt reports real-world exploitation of several MCP-related CVEs, highlighting large-scale compromise, high severity, and widespread usage—yet it offers no patches or PoC details.
Prakalp Choubey[verified]@ChoubeyPrakalpDisclosure
The post announces two new RCE vulnerabilities (CVE-2025-53773 for GitHub Copilot and CVE-2025-6514 for MCP) with brief technical notes and links to a post that likely contains further details, but it does not provide exploit code or evidence of current exploitation.
AgentVet[verified]@AgentVet_ioGeneral
The note cites two existing CVEs, noting their RCE and path traversal weaknesses, but delivers no exploit proof, patch, or evidence of current exploitation.
Adam4real[verified]@Adam4real4Active Exploitation
The post highlights real‑world exploitation of multiple CVEs, including RCE and worm‑like behavior, and notes a malicious npm package that forwards mail to attackers.
Adam4real[verified]@Adam4real4Active Exploitation
The bulletin confirms real-world exploitation of two RCE CVEs and highlights malicious npm packages and typosquatted repositories, indicating active abuse in the wild.
Petrus[verified]@Pete_yes_pleaseDisclosure
The passage highlights CVE-2025-6514 as a command injection flaw in mcp-remote that can lead to arbitrary code execution via crafted URLs, but no PoC, exploit tool, patch, or evidence of active exploitation is disclosed.
Oktsec[verified]@oktsecDisclosure
CVE-2025-6514 enables remote code execution when a malicious MCP server sends a crafted authorization_endpoint that mcp-remote executes without sanitization, requiring only a client connection to the server.