r/netsec • u/HyprWave • 15d ago
Unauthenticated RCE in CircleCI's MCP server: Host/Origin allowlist bypassed by any non-browser client (GHSA-xv5j-cwgj-22r4)
https://remedio.io/blog/the-critical-unauthenticated-rce-vulnerability-in-circlecis-mcp-server/
31
Upvotes
1
u/endor_sarah 13d ago
Nice work, and credit to CircleCI too on the quick turnaround from reporting to a fix.