
CVE-2026-6494 A flaw was found in the AAP MCP server. An unauthenticated remote attacker can exploit a log injection vulnerability by sending specially crafted input to the `toolsetr… https://www.cve.org/CVERecord?id=CVE-2026-6494
Post summary
The text announces CVE-2026-6494, highlighting a log injection flaw in the AAP MCP server that allows unauthenticated remote attackers to send crafted input.

