
MCP's STDIO server model is a security hole by design. LangChain-ChatChat and Windsurf both hit by CVEs (CVSS 8.6, 8.0) via MCP STDIO. Attacker controls the command --> your agent runs it. If you run MCP servers: audit them. Now. CVE-2026-30617 + CVE-2026-30615
Post summary
The text reports that LangChain-ChatChat and Windsurf are being actively exploited through the MCP STDIO vulnerability, urging users to audit their servers.



