CuraDevOps

Act active

Critical RCE in Serena MCP coding agent — update to 1.7.0

2026-08-18 11:17 UTC · GitLab Blog · read the source ↗ #mcp-security#rce#ai-coding-agent
  • Platform/SRE — Skip
  • CI/CD — Act: Published GHSA-pp25-4cg4-qcr9 details a critical server-side template injection in serena-agent ≤1.6.1 that executes arbitrary code via a malicious .serena/project.yml smuggled in any cloned repo — a direct supply-chain threat to developer and CI environments; upgrade to serena-agent 1.7.0 now.
  • Leader — Plan: This is an early, documented example of a new risk class: MCP servers embedded in the SDL grant LLMs broad filesystem and shell access, making any compromise severe; evaluate whether your AI coding-agent adoption policies explicitly address this attack surface before broader org rollout.
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.