Tag
#MCP
blogHIGH 8.8
DNS Rebinding Vulnerability in GenieACS MCP
A DNS rebinding vulnerability exists in the genieacs-mcp package, allowing a malicious web page to interact with a victim's local GenieACS MCP server. This can lead to unauthorized access and control of the GenieACS system.
articleMEDIUM 6.0
Model Context Protocol Overhaul Introduces New Security Challenges
The Model Context Protocol (MCP) 2026-07-28 specification introduces significant security enhancements, including the removal of protocol-level security risks and mandatory OAuth 2.1 for authentication. However, this overhaul also presents new security challenges for developers. The protocol's earlier versions had security risks such as stateful initialization and server-initiated prompts, which have been addressed. The update aims to improve authentication security but requires developers to adapt to the changes.