CVE-2025-6514
CVSS 9.6 CRITICAL: mcp-remote is exposed to OS command injection when connecting to untrusted MCP servers due to crafted input from the… EPSS 78% (100º percentile).
Sicurezza AI · Supply chain
Il rischio dell’AI agentica è passato dalla teoria alla pratica. Una singola dipendenza ostile può ora diventare un ampio punto d’appoggio all’interno del livello degli strumenti, perché molti agenti trattano testo esterno e aggiornamenti dei package come input fidati per l’azione, non solo come dati da visualizzare.
2 fonti · 11 giu
CVSS 9.6 CRITICAL: mcp-remote is exposed to OS command injection when connecting to untrusted MCP servers due to crafted input from the… EPSS 78% (100º percentile).
EPSS 0.9% (56º percentile).
CVSS 9.8 CRITICAL: cursor is a code editor built for programming with AI. EPSS 0.8% (54º percentile).
Help Net Security
Prompt injection still drives most agentic AI security failures in production - Help Net Security
OWASP's 2026 report puts prompt injection security at the center of agentic AI risk, citing CVEs, supply chain breaches, and tighter rules.
originaleInfosecurity Magazine
Prompt Injection Remains Unsolved, OWASP Researcher Warns
At Infosecurity Europe 2026, OWASP’s Ariel Fogel warned that prompt injection remains an “unresolved problem” within generative AI architecture
originaleRiepilogo fornitore: Microsoft
Part of the PlainSec briefing for 2026-06-12
Every edition of this story: Una singola dipendenza avvelenata può backdoorare i framework di agenti