
Three CVEs (CVE-2026-29774, CVE-2026-30015, CVE-2026-30221) exploited the fact that the protocol did not, in version 1.2, canonicalize tool names. Multiple servers in the same session could expose tools named, respectively: readfile (the legitimate filesystem server)…
Post summary
Three CVEs target a version‑1.2 protocol flaw that fails to canonicalize tool names, exposing servers such as readfile; technical details are given but no PoC, patch, or active exploitation is reported.



