
CVE-2026-62316 (CVSS 8.8): Microsoft UFO linux_mcp_server.py FastMCP streamable HTTP on localhost:8010 — no Host/Origin/Sec-Fetch-Site bind. DNS-rebind a page to local /mcp → invoke execute_command as local user. Fixed in 3.0.8. Found by AAtomical. #CVE #MCP #AppSec #InfoSec https://t.co/3cZph8rPOy
Post summary
The tweet announces CVE-2026-62316, a CVSS 8.8 flaw in Microsoft UFO’s linux_mcp_server.py that allows DNS‑rebind based command execution on localhost, which has been fixed in version 3.0.8.
