The Loop  ·  Issue N°040

The Loop

A field journal of the AI frontier — for engineers who ship.

§ The Patch

By AI Blog Editor
Sep 16, 2026 · 17 min read

The Patch — September 16, 2026

Three advisories land against a GitLab MCP server doing 82,000 installs a week — two of them 9.6 — and every fix on this morning's table shipped in June or July.

@zereight/mcp-gitlab took three advisories on Monday evening — two 9.6 criticals and an 8.1 — against a package doing about 82,000 npm installs a week. The fixes shipped on June 22 and July 5, which is the shape of the whole table: every patched row this morning was patched in June or July. The work today is checking what you pinned, not applying anything.

Component

Affected

Severity

Patched?

Action

Relevance

@zereight/mcp-gitlab ×2

< 2.1.30

9.6 (critical) · 8.1

yes → 2.1.30, Jul 5

upgrade; 2.1.62 is current

AI stack

@zereight/mcp-gitlab

≥ 0.0.1, < 2.1.27

9.6 (critical)

yes → 2.1.27, Jun 22

only bites with ENABLE_DYNAMIC_API_URL=true

AI stack

mcp-contextforge-gateway

≤ 1.0.4

5.4 (medium)

yes → 1.0.5, Jul 7

upgrade; 1.0.10 is current

AI stack

a2ui ×3

≤ 0.10.7

7.3 · 5.5 · 3.5

commits only, no version

repo-only; no package feed carries it

AI stack

vllm

0.26.0 / 0.27.0 (claimed)

5.3 (v3.1) · 6.9 (v4)

no — PR open since Aug 1

availability only; 0.29.0 does not clear it

AI stack

Worth your morning

The controls are the subject, not a feature. GHSA-5648-rgj9-v224 (8.1, no CVE assigned) is the one to read, because it is not about a broken endpoint. It covers five defects that between them defeat the three things an operator leans on to make this server safe: read-only mode, the GITLAB_ALLOWED_PROJECT_IDS allow-list, and transport authentication. The stated impact is that a prompt-injected agent or a semi-trusted client can perform GitLab writes while the operator believes the server is read-only, against projects outside the allow-list, up to whatever the configured token can reach; that anyone able to reach the port can use the server's stored GitLab credentials without authenticating; and that an unauthenticated caller can fill the session table and hold it for the hour-long default timeout. Fixed at 2.1.30, July 5. Current is 2.1.62, published Monday afternoon — hours before the advisories went up. Anyone tracking releases has been clear since the summer.

The same vector, scored twice. CVE-2026-61559 is server-side request forgery through a request header the server accepts as its API base URL, and GitHub's record scores it 9.6 critical. The advisory body scores it "High. CVSS v3.1 8.5" — and publishes the identical vector string, the one GitHub reads as 9.6. The same body says "Patched versions: None at time of report" where the record names 2.1.27, out since June 22. That is the reporter's original text sitting next to curated metadata, three months apart, and where they disagree it is the metadata your scanner acts on. One condition outranks both numbers: this reaches you only when ENABLE_DYNAMIC_API_URL=true. On the default it is inert, which is worth confirming before it turns a morning into an incident.

ContextForge — the fixed version is in the vendor's bulletin, not the advisory. CVE-2026-11918 (5.4) affects IBM ContextForge MCP Gateway through v1.0.4: incomplete recursive inspection of nested payload content lets an authenticated user past the gateway's own content filters. The GHSA record is unreviewed and declares no fix. IBM's bulletin names v1.0.5, from July 7, and states plainly that no workaround prevents the bypass while the affected filter plugins stay active — the upgrade is the remediation. mcp-contextforge-gateway is at 1.0.10 on PyPI. This digest tabled eight ContextForge CVEs on August 16; this is a different defect, and a ninth.

vLLM — second morning running, same structure. CVE-2026-92220 (5.3 on v3.1, 6.9 on v4) is resource exhaustion in the MoRIIO KV-transfer acknowledgement handler. The record names 0.26.0/0.27.0, which reads like a ceiling and is not one: the fix PR has been open since August 1 and is unmerged, so the range marks where the reporter stopped testing rather than where the defect stops. 0.29.0 does not clear it. Impact is availability, and only if you run the MoRIIO connector, which most deployments do not. Yesterday's vLLM item had the same shape — a vuldb-origin record, an upper bound implying a fix, an open PR underneath it — with a different CVE and a different unmerged branch. Two in two days is a pattern in the feed rather than in vLLM.

a2ui — and a name collision that will mislead a scanner. Three CVEs landed overnight against a2ui-project/a2ui, the agent-to-UI rendering project (16,400 stars, pushed this morning): CVE-2026-92215 (7.3, SSRF in the Python agent SDK's file resolver), CVE-2026-92213 (5.5, injection through a theme value in the Angular renderer) and CVE-2026-92214 (3.5, cross-site scripting in the sample chat canvas). The first two carry fix commits; the third has only an issue. None names a fixed version, and the repo's tags stop at v0.9 while the advisories speak in 0.10.x. The trap: the npm package a2ui is a different, unrelated project — an Angular 2 component library last released at 1.0.7 — so a tool matching on the bare name will flag the wrong thing or nothing at all. Match on the repository here, not the package.

Collection notes. The reviewed feed carried 26 entries across the 72-hour window and none touched the tracked stack beyond the rows above — thirteen of them were Http4s, the rest October CMS, ZITADEL, Netmaker and libp2p-quic. The unreviewed feed took a bulk import of roughly 900 records on September 15 between 21:31 and 21:33, overwhelmingly Oracle E-Business Suite and Fusion Middleware; nothing in it is AI-stack, and a keyword sweep over it mostly turns up the word fulfillment containing llm. Nothing new at repository level from Ollama, llama.cpp, LangChain, LlamaIndex, Haystack, LiteLLM, Dify, Langflow, Open WebUI, n8n, CrewAI, Graphiti, transformers, Gradio or the vector databases. Microsoft revised the September release document on the 15th without touching .NET, ASP.NET Core or Azure — the September 8 Patch Tuesday line stands. Angular is at 22.1.6, PrimeNG at 22.1.1.

* * *

Thanks for reading. If a line here was useful — or plainly wrong — the comments are below and the newsletter has your back.

Elsewhere in this issue

3 more
  1. 01

    News

    Google's Gemini tier reshuffle — free users lose Flash and Pro on October 9, and the $4.99 subscribers lose Pro four months after it was the pitch

    Oct 4, 2026

  2. 02

    The Patch

    The Patch — October 4, 2026

    Oct 4, 2026

  3. 03

    News

    The people who talk to the auditors — OpenAI fires three safety researchers for the kind of talking the auditors were set up to hear

    Oct 3, 2026

Letters

Arguments, corrections, questions. Anonymous comments allowed; be kind, be specific.