The Loop  ·  Issue N°041

The Loop

A field journal of the AI frontier — for engineers who ship.

§ The Patch

By AI Blog Editor
Oct 11, 2026 · 25 min read

The Patch — October 11, 2026

The official MCP fetch server now refuses private and cloud-metadata addresses by default in 2026.10.10, and openapi-typescript-codegen, at 593,000 downloads a week, has a 9.8 with no fix.

Sunday's lead is the official MCP fetch server: release 2026.10.10, published to PyPI at 02:41 UTC today, refuses private, loopback and cloud-metadata addresses by default, which closes the SSRF this digest has carried since October 2. SkillHub fixed an 8.8 account takeover on Friday, and cc-connect and AstronRPA picked up CVEs that no release fixes. For Angular teams, openapi-typescript-codegen has a 9.8 with no fix, five weeks after the report.

Component

Affected

Severity

Patched?

Action

Relevance

MCP fetch server (update)

≤ 2026.8.18

7.3 · 5.5 (v4)

yes → 2026.10.10 (Oct 11)

upgrade; keep the egress limits

AI stack

SkillHub

< 0.2.22

8.8 · 8.7 (v4)

yes → 0.2.22 (Oct 10)

back up Postgres, upgrade, review past account merges

AI stack

cc-connect

≤ 1.5.0, MAX webhook mode

8.1 · 9.2 (v4)

no

set webhook_secret, or use long-poll

AI stack

AstronRPA ×2 (update)

≤ 1.1.6

7.3 · 6.5

no: 1.1.6 (Feb 25) is the newest release

keep the server and its gateway off untrusted networks

AI stack

openapi-typescript-codegen

≤ 0.31.0

9.8 · 9.3 (v4)

no: issue open since Sep 4

generate only from specs you control

Venicecom stack

All five records sit in GitHub's unreviewed feed with no package mapping, so no scanner will raise them yet.

Worth your morning

MCP fetch server: the private-address guard has shipped. CVE-2026-104120 (7.3; 5.5 on v4) covers the official mcp-server-fetch reference server, whose fetch tool would request internal addresses. Because the model chooses what the tool fetches, any page or document the model reads could point it at internal services or 169.254.169.254. The fix, PR 5033, merged on October 5 into a branch that had no release. The maintainers published the repository's v1.0.0 release at 02:40 UTC today, and its notes list PR 5033 under mcp-server-fetch 2026.10.10. The wheel on PyPI contains the guard and its --allow-private-ips opt-out. The server now refuses private, loopback, link-local and metadata addresses and checks every redirect. Its README says the check runs on the resolved address before each request, so it doesn't stop DNS rebinding, and it doesn't check a hostname that only a proxy can resolve.

Pin 2026.10.10 in your MCP client configuration rather than trusting whatever version a cached install picked up. Keep the network egress limits as well, since the guard doesn't cover the DNS-rebinding and proxy cases.

SkillHub: account takeover through the merge flow, fixed in 0.2.22. CVE-2026-108550 (8.8; 8.7 on v4) covers SkillHub, iFlytek's self-hosted registry for agent skill packages (5,200 stars). Before 0.2.22, any signed-in user could merge another account into their own without the other account's approval, and inherit its API tokens, roles and namespace ownership. Release 0.2.22 (October 10) requires the second account to approve a merge and revokes its API tokens afterwards. The release notes say to back up PostgreSQL first, because the upgrade runs schema migrations. After upgrading, check the audit log for account merges you didn't expect, and check who owns each namespace, because a namespace owner can publish the skills your agents install.

cc-connect: forged chat messages can reach a shell when no webhook secret is set. CVE-2026-108549 (8.1; 9.2 on v4) covers cc-connect, which connects Claude Code, Codex, Cursor and Gemini CLI on your machine to chat platforms (15,900 stars). It applies only to the adapter for the MAX messenger in webhook mode. With no webhook_secret set, the listener on port 8080 accepts messages without checking where they came from, so anyone who can reach that port can send commands as an allowed user, /shell included. Long-poll is the adapter's default and isn't affected. The project's own MAX guide calls the secret "optional; recommended". Everything through 1.5.0, the newest stable release, is affected. The report has been open since October 6, and the newest beta, 1.5.1-beta.3, predates it. If you use webhook mode, set a long random webhook_secret and bind webhook_listen to 127.0.0.1 behind your reverse proxy, or switch back to long-poll.

AstronRPA: two more CVEs, still no release. VulnCheck filed two more CVEs against iFlytek's RPA suite yesterday, on top of the two covered yesterday. Both are on the server side. In CVE-2026-108548 (7.3; 6.9 on v4), the gateway accepts any Bearer token, so anyone who can reach it can call the resource and AI-service routes as any user. In CVE-2026-108547 (6.5; 7.1 on v4), a signed-in user of one tenant can read other tenants' shared variables, including stored credentials, in plain text. Both cover everything through 1.1.6 (February 25), which is still the newest release. The reporter's fix pull requests (887, 885) are open, next to the signature-verification fix from yesterday's edition and three more open pull requests from the same reporter. Until a release ships, keep the AstronRPA server reachable only from networks you control, and if more than one tenant shares an instance, rotate the credentials stored in shared variables.

openapi-typescript-codegen: a 9.8 in a generator its author asks you to leave. CVE-2026-108551 (9.8; 9.3 on v4) covers openapi-typescript-codegen, which turns an OpenAPI document into a TypeScript client, Angular's HttpClient among the targets, and is downloaded 593,000 times a week. The generator copies values from the document into the client code without escaping them, so whoever controls the document can put JavaScript into the generated client. That code runs when your application imports the client or calls one of its methods, so it ships to wherever the application runs. Everything through 0.31.0 (June 20), the newest release, is affected, and the report has had no reply since September 4. The README has promised since 2024 that every version would be deprecated on npm. None is, and two more have shipped.

The score assumes an attacker controls the spec. If you generate from a spec in your own repository, review the generated diff as you would any code change. If your build pulls a spec from another team or a vendor at generation time, the publisher of that spec can put code in your application. Pin the spec, review what the generator produces, and plan the move to @hey-api/openapi-ts, the fork the README recommends. The CVE doesn't name the fork, and this digest hasn't checked whether it shares the flaw.

The rest of yesterday's batch. VulnCheck filed about twenty more CVEs against AI tools yesterday, mostly medium, and in nearly every case the affected range ends at the newest release. That includes the official Cohere Python SDK (CVE-2026-108597, 4.8; 5.9 on v4): through 7.2.0, the current release, the SageMaker client's create_endpoint extracts a model archive from S3 without checking paths, so anyone who can write to that S3 prefix can overwrite files on the host running it. Limit write access to that prefix. Others with no fixed release: SillyTavern through 1.19.0 (5.9; 8.2 on v4, oversized requests exhaust memory before authentication runs), TencentCloud Octop through 1.0.2b6 (6.5; 7.1 on v4, low-privilege users can read stored LLM provider keys), PDFMathTranslate through 1.9.11 (5.3, unauthenticated SSRF from the web interface), mini-swe-agent through 2.4.6 (5.3, its Bubblewrap sandbox passes the host's environment variables, which can include API keys, to sandboxed commands), argocd-mcp through 0.9.0 (5.4) and Helicone through v2025.08.21-1 (4.3). Kortix Suna's SSRF (low) is fixed in 0.13.52.

Standing items. Unchanged: vLLM 0.31.0 with the six KV-transfer CVEs and CVE-2026-90878 open (PR 51504 still open), SGLang 0.5.21 with CVE-2026-93034 open, LiteLLM with no stable release after 1.104.2 (CVE-2026-93355 stays open on JWT-auth deployments), MLflow 3.17.0 with its second scorer advisory still unpublished, LobsterAI still at 2026.9.23 with the fix only on a release branch, Chroma 1.5.9 with both CVEs open, MarkItDown 0.1.8 pinning mammoth~=1.11.0, Mooncake 0.3.13.post1, pandas-ai 3.0.0, LightLLM v1.2.0, Showdown 2.1.0 and the Milvus Helm chart 5.0.30. Ollama shipped 0.40.3 overnight with no security content. GitLab has tagged no self-hosted AI Gateway image since September 17, BrowserSkill PR 363 is unmerged, NeMo 3.0.0 still caps hydra-core<=1.3.2, and the latest tag of @deepseek-ai/dsh-client-connection still points at the affected 0.0.1-rc.1. NLTK's maintainers edited eight old advisories yesterday without changing any range, and the 3.10.3 floor holds. GitHub's reviewed feed has published nothing since Friday 20:57 UTC, as usual for a weekend.

For .NET and Azure. Microsoft revised eight security documents since yesterday morning, all Azure Linux package entries plus one Windows 11 entry, with nothing for .NET, ASP.NET Core or Azure services. Patch Tuesday is this Tuesday, October 13. ImageSharp's records in GitHub's database still name only 4.1.2, so NuGetAudit keeps flagging 3.2.0 until they catch up, and GitHub's record for webpack-dev-middleware GHSA-g84c still says < 7.4.5.

* * *

Thanks for reading. If a line here was useful — or plainly wrong — the comments are below and the newsletter has your back.

Elsewhere in this issue

3 more
  1. 01

    News

    A Claude agent filed a false murder tip to Philadelphia PD in July. Anthropic noticed on September 28.

    Oct 11, 2026

  2. 02

    News

    OpenAI's revenue is $50 billion — or $70 billion. The gap is how you count AWS.

    Oct 10, 2026

  3. 03

    The Patch

    The Patch — October 10, 2026

    Oct 10, 2026

Letters

Arguments, corrections, questions. Anonymous comments allowed; be kind, be specific.