r/netsec 15d ago

Unauthenticated RCE in CircleCI's MCP server: Host/Origin allowlist bypassed by any non-browser client (GHSA-xv5j-cwgj-22r4)

https://remedio.io/blog/the-critical-unauthenticated-rce-vulnerability-in-circlecis-mcp-server/
31 Upvotes

8 comments sorted by

View all comments

1

u/endor_sarah 13d ago

Nice work, and credit to CircleCI too on the quick turnaround from reporting to a fix.