Open Source Security mailing list@oss_securityDisclosure
The post announces a privilege‑escalation vulnerability in KDE's plasma‑login‑manager caused by defense‑in‑depth weaknesses in the plasmaloginauthhelper component.
ナタリー 🌙@AbsolcassoDisclosure
The post reports an argument injection flaw in Anthropic's Git MCP server (CVE-2026-25710) that enables remote code execution, without providing a PoC, exploit, patch, or evidence of active exploitation.
FOSS Force@FOSSForceDisclosure
SUSE has reported new weaknesses in Plasma Login Manager, identified as CVE-2026-25710, and provided a link for further details.
ナタリー 🌙@AbsolcassoDisclosure
The note announces a remote code execution vulnerability due to argument injection in Anthropic's Git MCP server (CVE-2026-25710), warning that community servers may run vulnerable reference implementations and urging a security scan before trust.
ナタリー 🌙@AbsolcassoDisclosure
The post announces CVE-2026-25710, noting an argument injection flaw that causes RCE in Anthropic's Git MCP server, warning of broader risks in un-audited community servers.
ナタリー 🌙@AbsolcassoGeneral
The statement references two CVEs—an RCE flaw in nmap-mcp-server (CVE-2026-3484) and a Git server flaw in Anthropic (CVE-2026-25710)—but does not provide proof-of-concept, exploit code, patch, or active exploitation details, simply urging caution.
ナタリー 🌙@AbsolcassoGeneral
The post lists several new CVEs affecting MCP and AI-agent environments, highlighting unexpected runtime behavior but offering no technical specifics or remediation steps.
ナタリー 🌙@AbsolcassoDisclosure
The post reports CVE‑2026‑25710 as an argument injection vulnerability in Anthropic’s Git MCP server that enables remote code execution, underscoring risks in community‑maintained servers.