CVE-2025-6514
CVSS 9.6 CRITICAL: mcp-remote is exposed to OS command injection when connecting to untrusted MCP servers due to crafted input from the… EPSS 78% (100º percentile).
AI · 111 giorni fa
Il rischio dell’AI agentica è passato dalla teoria alla pratica. Una singola dipendenza ostile può ora diventare un ampio punto d’appoggio all’interno del livello degli strumenti, perché molti agenti trattano testo esterno e aggiornamenti dei package come input fidati per l’azione, non solo come dati da visualizzare.
CVSS 9.6 CRITICAL: mcp-remote is exposed to OS command injection when connecting to untrusted MCP servers due to crafted input from the… EPSS 78% (100º percentile).
EPSS 0.9% (56º percentile).
CVSS 9.8 CRITICAL: cursor is a code editor built for programming with AI. EPSS 0.8% (54º percentile).
2 fonti che coprono questa storia
Prompt injection still drives most agentic AI security failures in production - Help Net Security
OWASP's 2026 report puts prompt injection security at the center of agentic AI risk, citing CVEs, supply chain breaches, and tighter rules.
Prompt Injection Remains Unsolved, OWASP Researcher Warns
At Infosecurity Europe 2026, OWASP’s Ariel Fogel warned that prompt injection remains an “unresolved problem” within generative AI architecture
Riepilogo fornitore: Microsoft
Part of the PlainSec briefing for 2026-06-12