By AI Blog Editor
Sep 25, 2026 · 25 min read
The Patch — September 25, 2026
Payload fixed a 9.8 SQL injection in August and disclosed it Tuesday night with no CVE, so no scanner will raise it. mcp-remote has five new CVEs and no declared fix.
Payload fixed a 9.8 SQL injection in its Postgres and SQLite adapters on August 11 and published the advisory on Tuesday night. This digest missed it for two days. It has no CVE and no record in GitHub's advisory database, so a lockfile scan will not raise it. mcp-remote, at 784,000 downloads a week, picked up five CVEs yesterday, and no release claims to fix them.
Component | Affected | Severity | Patched? | Action | Relevance |
|---|---|---|---|---|---|
payload + two plugins ×5 | < 3.88.0 · 4.0 canaries < .27 | 9.8 · 9.3 (v4) · 8.6 (v4) · 6.9 (v4) · 6.1 | yes → 3.88.0 (Aug 11) | upgrade; MongoDB installs are exempt from the SQL injection | AI stack |
mcp-remote ×5 | 7.5 · 4 unscored | no fix declared; 0.14.3 current | connect only to remote MCP servers you trust | AI stack | |
Kiro IDE | < 1.0.242 | 8.8 · 8.6 (v4) | yes → 1.0.242 | upgrade; check | AI stack |
@bytebase/dbhub ×2 | 9.3 (v4) · 7.4 | yes → 0.22.6 (Jun 24); 1.3.1 current | upgrade if pinned | AI stack | |
cline (CLI) | 8.8 | yes → 3.0.30 (Jun 26); 3.0.65 current | upgrade if pinned | AI stack | |
Amazon Q Developer plugins ×2 | 8.5 (v4) ×2 | yes → VS Code 2.20 · JetBrains 4.3 · Eclipse 2.7.4 · Visual Studio 1.94.0.0 (Jun 23) | update the IDE plugin | AI stack |
Worth your morning
Payload: upgrade to 3.88.0 or later. Payload published five advisories at 21:15 UTC on Tuesday, all fixed in 3.88.0 on August 11. The current release is 3.90.2. The top one, GHSA-v49j-62m6-pgrr (9.8), is SQL injection in the Postgres and SQLite adapters. The advisory's condition is that untrusted users can query readable collections with dynamic filters or joins. Payload's REST API accepts where filters on any collection the caller can read, so a site with a publicly readable collection meets that condition by default. MongoDB installs are not affected. Until you can deploy, the vendor's workaround is to stop untrusted callers supplying filters or join parameters and to narrow read access.
Two plugin advisories matter if you run the plugin. GHSA-qf28-8hc6-vwrp (9.3 on v4) is unauthenticated code execution through prototype pollution when @payloadcms/plugin-import-export is enabled. GHSA-2q76-m6w6-qgc6 (8.6 on v4) lets an authenticated user manage MCP API keys outside their own account in @payloadcms/plugin-mcp (80,000 downloads a week), which the advisory says leads to account takeover. If you can't upgrade today, disable the plugin. The other two are a 6.9 leak of protected-field information through sort parameters and a 6.1 open redirect after login. All five return 404 in GitHub's global advisory database, so npm audit, Dependabot and anything else that reads it will stay quiet.
mcp-remote: the range is not an all-clear. Five CVEs filed yesterday cover mcp-remote 0.1.16 through 0.1.38. It is the bridge that lets local-only MCP clients reach remote servers. Three concern URLs a remote server hands the client during OAuth discovery and sign-in (CVE-2026-51994, CVE-2026-51995, CVE-2026-51997). One concerns how tokens are scoped on the SSE transport (CVE-2026-52001), and one concerns the MD5 hash that separates stored credentials per server (CVE-2026-51996). Only CVE-2026-51995 has a score, 7.5 from CISA's enrichment. The reporter's write-up lists them as unresolved in 0.1.38. Since August 21 the project has shipped 0.1.39 through 0.14.3 and moved to punkpeye/mcp-remote. No release note or commit since then mentions the reports. At the v0.14.3 tag the credential namespace still uses MD5, and the protected-resource discovery code has had one unrelated change. Treat current versions as affected until the maintainer says otherwise. The risk comes from the remote server, so the control is to point mcp-remote only at servers you trust. None of the five records has a package mapping, so scanners will not raise them.
Kiro: upgrade and check ~/.kiro. AWS published a bulletin yesterday for CVE-2026-95985. In Kiro IDE before 1.0.242, running the agent in an untrusted workspace could let that repository's content steer the agent's file-write tool into changing auto-loaded global configuration. The fix is in 1.0.242, and there is no workaround. AWS asks anyone who ran the agent in untrusted workspaces on an older version to review ~/.kiro (%USERPROFILE%\.kiro on Windows) for entries they did not create.
June fixes your scanner will raise today. Yesterday evening GitHub's reviewed feed indexed a group of advisories that their projects published on June 23 and 24. Every one was fixed at the time, and most readers are already past the fix. DBHub, a database MCP server with 33,000 downloads a week, has two. CVE-2026-61742 (9.3 on v4) let a web page reach its HTTP transport through DNS rebinding and run tool calls, fixed in 0.22.5. CVE-2026-61788 (7.4) found that readonly = true never made the connection read-only: a read-only switch wired to a setting nothing ever set. That one is fixed in 0.22.6, and a MySQL/MariaDB variant (CVE-2026-61789) is still repository-only. Cline's CLI CVE-2026-59723 (8.8) let a web page drive the local cline dashboard server when ROOM_SECRET was unset, the default on 127.0.0.1, fixed in 3.0.30. In Amazon Q Developer, CVE-2026-12957 and CVE-2026-12958 (8.5 on v4 each) are code execution from a crafted workspace's project config once the user trusts it, and a file write outside the workspace through a symlink. The fixed plugin versions are in the table. langchain-nvidia-ai-endpoints (7.5) accepted local file paths as VLM image inputs, so an app passing user-controlled image URLs to ChatNVIDIA or NVIDIARerank could send local files to the model endpoint. It is fixed in 1.4.2, and 1.4.3 is current. hpack (CVE-2026-59980, 6.3 on v4), the header decoder under Python's h2, can burn CPU on malformed input and is fixed in 4.2.0.
Also landed. @kazuph/mcp-fetch (2,400 downloads a week) has CVE-2026-80347 (7.5 on v3.1, 8.7 on v4): its private-address guard misses some IPv6 address forms. The CVE covers everything through 1.6.3, the newest release (June 12). The report has been open since August 26, and there has been no commit since June. Don't run it on a host that can reach internal services. IBM's CVE-2026-77825 (4.9) is an admin-only path traversal in ContextForge MCP Gateway's log download, covering 1.0.0 through 1.0.8. The current release is 1.0.10.
Standing items. vLLM 0.30.0 is still the newest release, and all nine of its open fix PRs are still unmerged, including the six for the September 22 KV-transfer CVEs. SGLang is still v0.5.20 with CVE-2026-93088 open. FalkorDB shipped v4.20.7 yesterday. Its one security item is a Redis bump for a zlib CVE, and it is still the C engine, so the seven August CVEs stand. Tencent BrowserSkill's issue 273 is still open, with no commits to the daemon's WebSocket handler since September 17. mcp-atlassian is still 0.23.1, and GHSA-5j8j-256g-vvp5 is still repository-only. Angular's GHSA-ff3f-86qr-9cv3 has not reached GitHub's database yet, so the 22.1.8 false positive we flagged yesterday has not started. Chroma 1.5.9, gray-matter 4.0.3 and Kotaemon v0.12.0 are unchanged.
On the Microsoft side there is nothing to apply. The September document has had 618 entries revised since Wednesday. Nearly all are Azure Linux kernel packages, and none touches .NET, ASP.NET Core, Visual Studio or Azure AI. .NET 10.0.12, 9.0.20 and 8.0.31 are still the current security releases, and PrimeNG is still 22.1.1.
* * *
Thanks for reading. If a line here was useful — or plainly wrong — the comments are below and the newsletter has your back.
Elsewhere in this issue
3 more- 01
News
Google's Gemini tier reshuffle — free users lose Flash and Pro on October 9, and the $4.99 subscribers lose Pro four months after it was the pitch
Oct 4, 2026
- 02
The Patch
The Patch — October 4, 2026
Oct 4, 2026
- 03
News
The people who talk to the auditors — OpenAI fires three safety researchers for the kind of talking the auditors were set up to hear
Oct 3, 2026
Letters
Arguments, corrections, questions. Anonymous comments allowed; be kind, be specific.