Two newly disclosed vulnerabilities affected software built around the Model Context Protocol (MCP), highlighting security weaknesses in AI-agent tooling. CVE-2026-63119 impacts the MCP Ruby SDK distributed as the mcp gem before version 0.23.0, where unbounded reads from stdio streams can let a connected peer or spawned subprocess send newline-free data until memory is exhausted, causing denial of service. Separately, CVE-2026-54785 affects the gemini-bridge MCP server's file-handling logic, where improper path validation in _resolve_path allows directory traversal and local file disclosure outside the configured workspace, potentially exposing sensitive files through Gemini query responses.
The disclosures come as MCP adoption expands and security guidance around AI-agent integrations matures. The MCP specification and introduction describe the protocol as a standard way to connect models with external tools and data sources, while recent security research has warned that tool-calling systems introduce risks including prompt injection, excessive privilege, SSRF, and data leakage. In parallel, the OpenID Foundation published draft COAZ and COAZ-MCP specifications to bring standardized authorization to MCP message flows before tool execution, and practitioner research on MCP deployments has emphasized authentication, input validation, logging, and least-privilege design as necessary safeguards for enterprise use.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
The CVE-2026-63119 report says the denial-of-service vulnerability in the MCP Ruby SDK was published in the NVD on 2026-07-29.
MCP Ruby SDK version 0.23.0 was officially released on 2026-07-07, adding a 4 MiB line-length limit, newline validation, and related transport hardening to address the stdio memory exhaustion issue.
The CVE-2026-63119 report states that the initial fix for stdio transport unbounded reads in the MCP Ruby SDK was completed on 2026-06-02.
On 2025-10-29, Flatt Security Research published an analysis of security risks and mitigations for LLM function-calling and MCP-style tool integrations, including SSRF, prompt injection, and excessive delegation.
The Model Context Protocol specification reference is explicitly versioned as 2025-03-26, indicating a specification release or publication point for that dated version.
A Tier Zero Security blog post states that Anthropic introduced the Model Context Protocol as an open standard for connecting AI models to external tools and data sources in November 2024.
A CVE report disclosed CVE-2026-54785, a directory traversal and local file read issue in gemini-bridge's consult_gemini_with_files workflow caused by improper path validation in _resolve_path.
An OpenID Foundation post announced the publication of two draft specifications, the COAZ Framework and the COAZ-MCP Binding, to standardize authorization for APIs and MCP-based AI agent workflows.
On 29 April 2025, Tier Zero Security published a write-up describing a locally built MCP server for Elasticsearch-based threat hunting with Claude Desktop, along with security considerations for MCP deployments.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
cvereports.com
Open sourceopenid.net
Open sourcecvereports.com
Open sourceflatt.tech
Open sourcetierzerosecurity.co.nz
Open sourcemodelcontextprotocol.io
Open sourcemodelcontextprotocol.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.