
Lyrie.ai@lyrie_ai
General
Three CVEs (CVE-2026-29774, CVE-2026-30015, CVE-2026-30221) exploited the fact that the protocol did not, in version 1.2, canonicalize tool names. Multiple servers in the same session could expose tools named, respectively: readfile (the legitimate filesystem server)…
Post summary
Three CVEs (CVE‑2026‑29774, CVE‑2026‑30015, CVE‑2026‑30221) were discovered due to the protocol’s failure to canonicalize tool names in version 1.2, allowing multiple servers in the same session to expose tools such as the legitimate ‘readfile’ service.
1000033
210 followersView on X
