A high-severity vulnerability tracked as CVE-2026-49471 allows unauthenticated remote code execution in the Serena Model Context Protocol toolkit before version 1.5.2. Serena exposed a local Flask dashboard API on predictable port 24282 without authentication, CSRF protections, or Host header validation, letting an attacker use DNS rebinding from a malicious website to reach the victim’s local service through the browser. The attacker could then poison Serena’s persistent memory store with arbitrary content that the autonomous agent later reads and acts on.
The attack chain can lead to shell command execution on a developer workstation because Serena used execute_shell_command with shell=True, turning memory poisoning into code execution. Public reporting said a proof of concept is available and assigned the flaw a CVSS 8.3 severity rating. The issue is fixed in Serena 1.5.2, which adds Flask before_request Host header validation to restrict requests to localhost addresses, although researchers noted possible residual concerns involving IPv6 loopback handling and abuse from other local applications.

Track how attackers are adapting to this technology.
4 events from the most recent confirmed update back to the earliest known activity.
A public proof of concept for CVE-2026-49471 was reported in the later write-up, demonstrating exploitability of the Serena DNS rebinding and memory poisoning chain. The same write-up also noted residual concerns around IPv6 loopback handling and localhost-origin abuse.
On 2026-07-07, CVE-2026-59706 was published as a critical mem0 vulnerability involving unauthenticated configuration endpoints. The flaw allows plaintext retrieval of stored API keys and SSRF via modification of the ollama_base_url parameter.
On 2026-07-07, CVE-2026-49471 was published as a high-severity Serena vulnerability that can lead to remote code execution via DNS rebinding, memory poisoning, and shell command execution. Affected versions are prior to 1.5.2.
Serena addressed CVE-2026-49471 in version 1.5.2. The fix adds Flask Host header validation to restrict dashboard requests to localhost or 127.0.0.1 on the active port.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
3 references tracked. Mallory keeps watching after this page renders.
cvereports.com
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.