CVE-2026-25905Disclosure

LOWCVSS 5.8 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Python code being run by 'runPython' or 'runPythonAsync' is not isolated from the rest of the JS code, allowing any Python code to use the Pyodide APIs to modify the JS environment. This may result in an attacker hijacking the MCP server - for malicious purposes including MCP tool shadowing. Note - the "mcp-run-python" project is archived and unlikely to receive a fix.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-653

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-02-09); latest day: 1
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-02-09: 2Mentions · 2026-03-03: 1Mentions · 2026-04-25: 1Technical Details · 2026-02-09: 2Technical Details · 2026-04-25: 102-0903-0304-25
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-092
Disclosure1General1
2026-03-031
Disclosure1
2026-04-251
Disclosure1
Full discourse4 posts
  • シンギュラリティ研究所🐒@guava_asi
    Disclosure

    guard-scanner v5.0.5 released 🛡️ 147 patterns / 23 categories / 136 tests PASS 0.016ms/scan / zero deps New: CVE-2026-25905, CVE-2026-27825, VDB Injection (Cat 23) npm: http://npmjs.com/package/guard-scanner GitHub: http://github.com/koatora20/guard-scanner #AIAgentSecurity #OpenClaw

    Post summary

    Guard‑scanner v5.0.5 release announces detection of new CVE‑2026‑25905 and CVE‑2026‑27825, but provides no exploit, patch, or technical details.

    00101233
    15 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25905 The Python code being run by 'runPython' or 'runPythonAsync' is not isolated from the rest of the JS code, allowing any Python code to use the Pyodide APIs to modify … https://www.cve.org/CVERecord?id=CVE-2026-25905

    Post summary

    The entry highlights a flaw where Python code executed via 'runPython' or 'runPythonAsync' can interact with the surrounding JavaScript through Pyodide APIs, potentially compromising isolation.

    00010321
    56.5K followersView on X
  • AI Security Guard@ai_security_10x
    Disclosure

    📝 New article: CVE-2026-25905: Critical MCP Server Isolation Bypass Enables Tool Shadowing Attacks https://moltx.io/articles/04195627-b03d-4b8c-8f2f-d1488f90c03d

    Post summary

    An article announces the discovery of CVE‑2026‑25905, a critical MCP server isolation bypass that enables tool shadowing attacks.

    0000036
    5 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-25905 Pyodide API Hijacking Vulnerability in MCP Server Python Execution https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25905

    Post summary

    The text references CVE-2026-25905 as a Pyodide API hijacking vulnerability in MCP Server's Python execution, but provides no proof of concept, exploit, active exploitation, or patch information.

    0000060
    4.0K followersView on X

Explore more