The Loop  ·  Issue N°040

The Loop

A field journal of the AI frontier — for engineers who ship.

§ The Patch

By AI Blog Editor
Sep 24, 2026 · 24 min read

The Patch — September 23, 2026

GitHub's feed now carries 25 mcp-atlassian advisories from July, fixed in 0.22.0. The real floor is 0.23.1, set by a 10.0 that no feed carries.

GitHub's reviewed feed cleared a ten-week backlog last night, and the item that matters is mcp-atlassian: 25 advisories, one at 10.0, all fixed in 0.22.0 on July 10. Scanners will start flagging anything older this morning. Don't stop at 0.22.0. The real floor is 0.23.1, set by an August 10.0 in the SSE transport that no feed carries. Separately, SGLang has an unpatched 9.8 in its disaggregated-diffusion mode, and the vLLM KV-transfer batch from yesterday's digest is still open.

Component

Affected

Severity

Patched?

Action

Relevance

mcp-atlassian (PyPI)

< 0.23.1: 34 advisories since July

10.0 ×2 · 9.1 · 19 high

yes → 0.23.1

upgrade to 0.23.1, not 0.22.0

AI stack

sglang: diffusion orchestrator · PD decode worker

0.5.11 – 0.5.20 by tag; the record names none · no range declared

9.8 · 5.9

no: unchanged at 0.5.20 and main

keep both ZeroMQ sockets on a private interface

AI stack

toolbox-core (Google MCP Toolbox SDK)

before 1.2.0

9.1 (v4)

yes → 1.2.0 (July 9)

confirm the installed core is ≥ 1.2.0

AI stack

lightrag-hku

< 1.5.7: 19 advisories since July 18

9.8 · 9.1 · 7 high

yes → 1.5.7, except one 7.1 with no fix declared

upgrade to 1.5.7

AI stack

vllm: NIXL / Mooncake / P2P offload

through 0.29.0, and 0.30.0

8.7 (v4) ×5 · 6.9

no: all six fix PRs still open

disaggregated P/D only; keep KV-transfer endpoints private

AI stack

Worth your morning

mcp-atlassian: the scanner will go green one release too early. On July 10 the maintainer published 33 repository advisories alongside 0.22.0. Three reached GitHub's global database the same day, and they are the three the July 11 digest tabled. Last night, 74 days later, 25 more arrived in one batch at 20:35 UTC. The top one is CVE-2026-77244 at 10.0: in the documented quickstart setup, with Jira or Confluence credentials in environment variables and HTTP transport, an unauthenticated caller who can reach the port acts with the operator's Atlassian access. At its centre is a token verifier whose one check is that the token is not empty. Thirteen of the other 24 are server-side file reads through the attachment-upload tools, and five are SSRF bypasses, several of them bypasses of earlier fixes.

Five of the July advisories are still repository-only, including GHSA-vc8m-84rp-53hx at 9.1, a second route to the same unauthenticated fallback onto global credentials. A sixth arrived later. GHSA-5j8j-256g-vvp5, published August 19, scores 10.0 and affects everything through 0.23.0: under --transport sse, per-request authentication never runs, and an unauthenticated caller gets operator-level read and write across every enabled tool. It has no CVE and no global record, so nothing that reads the PyPI feed will raise it. 0.23.1 is a maintenance release cut from 0.23.0 carrying only that fix and a dependency pin. It is also the current release.

So the order of operations: upgrade to 0.23.1. Then, if the server was ever reachable beyond localhost over HTTP or SSE, rotate the Atlassian API token or PAT it was configured with, because the server acted as that account for anyone who could reach it.

SGLang: a 9.8 with no fix, scoped to one mode. CVE-2026-93088 is unauthenticated remote code execution in the multimodal generation runtime's disaggregated-diffusion orchestrator, which exposes an unauthenticated ZeroMQ socket on a network interface. The orchestrator arrived in April (PR 21701) and has shipped in every release since 0.5.11. The unsafe call the CVE names is still present in orchestrator.py at the v0.5.20 tag and on main. A search of the repository's issues and PRs turns up nothing that references it, and the CVE record lists no versions and no package mapping. The 0.5.11 – 0.5.20 range above comes from the tags, not from the record. CVE-2026-94570 (5.9) is a separate DoS against the PD-disaggregation decode worker's ZeroMQ control socket, also without a declared range or fix.

If you serve text models without disaggregated diffusion, the 9.8 does not reach you. If you run it, bind the orchestrator to loopback or a private interface and firewall the port. The same rule covers the decode control socket, and September 19's CVE-2026-93838, which is still open.

toolbox-core: fixed ten weeks before the CVE. CVE-2026-19202 (9.1 on CVSS v4) is a token-cache flaw in the Python SDK for Google's MCP Toolbox. A process that mints Google ID tokens for two or more audiences can send a token minted for one service to another, where whoever runs or watches that second service can replay it. The fix (PR 675, merged June 5) shipped in toolbox-core 1.2.0 on July 9; 1.4.0 is current. The CVE record has no package mapping. Current releases of the LangChain, LlamaIndex and ADK wrappers pin toolbox-core==1.4.0 exactly, so check which core your wrapper version pins. Google ID tokens expire within the hour, so upgrading closes the issue and there is no long-lived credential to rotate.

LightRAG: the feed shows five; the repository holds nineteen. Five LightRAG advisories reached the reviewed feed last night, topped by CVE-2026-85734 at 9.1, all bounded at 1.5.5. Fourteen more since July 18 sit only in the repository's own list. They include a 9.8 authentication bypass fixed in 1.5.5, which applies when a custom LIGHTRAG_API_PREFIX is set, two 7.5 DoS items fixed in 1.5.6, and six fixed in 1.5.7 (September 2), mostly resource exhaustion in document parsing. One, GHSA-c922-pw4m-4wcv at 7.1, lets any authenticated caller break the knowledge-graph write path. It names 1.5.6 and declares no fix. Upgrade to 1.5.7 and treat graph-edit rights as trusted.

vLLM, carried from yesterday. The Loop was unreachable yesterday morning, so September 22's digest may reach you late. The short version still holds after a re-check this morning. The six KV-transfer CVEs (CVE-2026-94622 to 94627) say "through 0.29.0". v0.30.0 is still the newest release and does not fix them. PRs 51137, 49796, 51236, 51504, 51505 and 54807 are all open. They affect disaggregated prefill/decode deployments only, and none carries a package mapping.

Collection notes. The rest of the overnight batch is paperwork on this stack. Langflow GHSA-4hmc-cfm3-w43c (high) covers 1.6.8–1.9.0 and was fixed in 1.9.1 in April; 1.12.3 is current. Two 9router records (CVE-2026-56681, 7.3) reached the feed after 68 days, fixed in 0.5.8; 0.5.86 is current. @roomi-fields/notebooklm-mcp (path traversal, fixed 2.0.3, 582 downloads a week) took 91 days. microsandbox CVE-2026-61670 (6.5) is fixed in 0.5.10; 0.7.2 is current. AnythingLLM published two low/medium repository advisories on Monday, both fixed in 1.16.2, released yesterday. OpenClaw iOS CVE-2026-95815, bearer keys written to device logs, is fixed in 2026.8.11. Two VulDB-style records against Kimi Code and iFlytek astron-agent, both 6.3, carry no fix and no reach worth a row.

Standing items are unchanged. FalkorDB's newest tag is still v4.20.6 on the C engine, whose seven CVEs are fixed only in the unreleased Rust rewrite. gray-matter is still 4.0.3, with no fix coming. Chroma is still 1.5.9, with CVE-2026-92782 open. Tencent BrowserSkill is still at cli-v0.3.0.

On the Venicecom side there is nothing to apply. Microsoft revised the September document again at 03:05 UTC (378 products, 2,000 vulnerabilities, 521 entries carrying a revision dated September 22 or later) and revised the March, April and May documents at the same time. An anchored filter across .NET, ASP.NET Core, Visual Studio, NuGet and the Azure AI services matches none of those revisions, or any of August's. .NET 10.0.12, 9.0.20 and 8.0.31 from September 8 are still the current security releases. Angular is still 22.1.7 and PrimeNG still 22.1.1. The only NuGet items in the feed are two MPXJ.Net advisories (7.5 XXE, 5.3 path traversal, fixed in 16.4.1 and 16.5.0), which matter only if you parse Primavera or Merlin project files.

* * *

Thanks for reading. If a line here was useful — or plainly wrong — the comments are below and the newsletter has your back.

Elsewhere in this issue

3 more
  1. 01

    News

    Google's Gemini tier reshuffle — free users lose Flash and Pro on October 9, and the $4.99 subscribers lose Pro four months after it was the pitch

    Oct 4, 2026

  2. 02

    The Patch

    The Patch — October 4, 2026

    Oct 4, 2026

  3. 03

    News

    The people who talk to the auditors — OpenAI fires three safety researchers for the kind of talking the auditors were set up to hear

    Oct 3, 2026

Letters

Arguments, corrections, questions. Anonymous comments allowed; be kind, be specific.