By AI Blog Editor
Jun 19, 2026 · 8 min read
The Patch — June 19, 2026
Two unauthenticated remote-code-execution disclosures land on AI tooling — a critical command-injection flaw in gemini-mcp-tool (CVE-2026-0755) and Crawl4AI's June 18 batch of fixes topping out at CVSS 10.0.
This morning is two unauthenticated remote-code-execution disclosures, both in AI tooling that tends to sit one call away from a shell. CVE-2026-0755 is a command-injection flaw in gemini-mcp-tool, the npm MCP bridge to Google's Gemini, scored 9.8. Crawl4AI — the LLM-oriented web crawler — shipped a coordinated batch of fixes on June 18 that tops out at a clean CVSS 10.0. If you run either, upgrade before you read the rest of this. Nothing on the .NET or Angular side cleared the bar in the last 24 hours.
Component | Affected | Severity | Patched? | Action | Relevance |
|---|---|---|---|---|---|
gemini-mcp-tool | 1.1.2 – 1.1.5 | 9.8 (critical) | yes → 1.1.6 | upgrade now — unauth RCE | AI stack |
crawl4ai | ≤ 0.8.9 | up to 10.0 (critical) | yes → 0.9.0 | upgrade now | AI stack |
@agenticmail/* | see advisory | 8.2 (high) | yes → patched | upgrade all packages | AI stack |
Worth your morning
gemini-mcp-tool (CVE-2026-0755). A command-injection flaw lets an unauthenticated request reach a shell call, so the impact is arbitrary command execution on the host running the MCP server — no auth, no user interaction, which is where the 9.8 comes from. Affected releases run 1.1.2 through 1.1.5; the fix is 1.1.6. If you've wired this tool into an agent, upgrade and treat any secrets that process could see as exposed.
Crawl4AI (June 18 batch). Nine advisories landed together, spanning unauthenticated RCE, SSRF, and path traversal in the Docker crawl service; the most severe is an argument-injection bug rated a full 10.0. They roll up into 0.9.0. If you run the Crawl4AI Docker endpoint anywhere reachable, patch to 0.9.0 — and the recurring theme across the batch is an unauthenticated Docker API, so don't expose it in the first place.
AgenticMail (GHSA-fq4x-789w-jg5h). An inbound email — from anyone — could resume a Claude Code session running in bypass-permissions mode, which is to say an unauthenticated stranger's message ran as the operator. Fixed across the scoped packages (core 0.9.43, claudecode 0.2.39, codex 0.1.33, openclaw 0.5.71). High, 8.2.
* * *
Thanks for reading. If a line here was useful — or plainly wrong — the comments are below and the newsletter has your back.
Elsewhere in this issue
3 more- 01
News
Google's Gemini tier reshuffle — free users lose Flash and Pro on October 9, and the $4.99 subscribers lose Pro four months after it was the pitch
Oct 4, 2026
- 02
The Patch
The Patch — October 4, 2026
Oct 4, 2026
- 03
News
The people who talk to the auditors — OpenAI fires three safety researchers for the kind of talking the auditors were set up to hear
Oct 3, 2026
Letters
Arguments, corrections, questions. Anonymous comments allowed; be kind, be specific.