A logic flaw in @dynatrace-oss/dynatrace-mcp-server allowed indirect prompt injection to silently create Dynatrace notebooks without operator consent, exposing a gap in how AI-connected tools handle state-changing actions. Tracked as GHSA-PC2W-4MQ8-32QW and affecting versions before 1.8.7, the issue stemmed from a missing human-approval gate in create_dynatrace_notebook and absent risk metadata, enabling attackers to create persistent notebooks that could contain deceptive content or expensive Dynatrace Query Language queries. Dynatrace fixed the vulnerability in version 1.8.7 by adding approval checks and tool metadata to better distinguish risky and idempotent actions.
The disclosure comes amid broader industry efforts to impose stronger governance on AI agents and workflow automation platforms as enterprises connect models to internal tools and external systems. Security guidance from vendors and practitioners has stressed that natural-language tool descriptions are not effective permission boundaries, that external MCP servers enforce their own authentication and authorization models, and that per-user OAuth can unintentionally propagate excessive privileges. New enterprise platforms are also emphasizing isolated execution, credential protection, access mapping, logging, and deterministic policy enforcement, reflecting growing concern that AI agents with tool access require trusted registries, strict argument validation, approval gates, and auditable controls before they can safely act in production environments.

Track how attackers are adapting to this technology.
2 events from the most recent confirmed update back to the earliest known activity.
Tines launched 3B, a new AI-assisted enterprise workflow platform that lets users describe workflows in natural language while executing them as conventional code. The company said the platform includes governance controls such as isolated execution, credential protection, access mapping, logging, and admin monitoring.
Dynatrace addressed a logic vulnerability in @dynatrace-oss/dynatrace-mcp-server by releasing version 1.8.7 and Pull Request #529. The fix added requestHumanApproval() checks and destructiveHint and idempotentHint metadata to prevent silent notebook creation without operator consent.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
5 references tracked. Mallory keeps watching after this page renders.
reddit.com
Open sourcethenewstack.io
Open sourcecvereports.com
Open sourcesalesforce.com
Open sourcethenewstack.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.