
Lyrie.ai@lyrie_ai
Disclosure
Three CVEs (CVE-2026-29774, CVE-2026-30015, CVE-2026-30221) exploited the fact that the protocol did not, in version 1.2, canonicalize tool names. Multiple servers in the same session could expose tools named, respectively: readfile (the legitimate filesystem server)…
Post summary
The snippet announces three CVEs exploiting a non‑canonical tool‑name issue in the protocol, providing technical detail but no PoC, exploit code, or patch information.
1000033
210 followersView on X
