Codex metadata collection trusted repository execution helpers
ZDI awarded Doyensec USD 10,000 for this distinct Pwn2Own Berlin entry.
AISecurity theme
Authority boundaries around model input, tools, and downstream actions. 7 disclosures · 12 related references · 1 diagrams.
Connected collection
ZDI awarded Doyensec USD 10,000 for this distinct Pwn2Own Berlin entry.
ZDI awarded Summoning Team USD 20,000 for this distinct Pwn2Own Berlin entry.
Sentry documents a USD 150,000 award to Drinor Selmanaj for CVE-2026-20685.
A researcher reports a $15,000 Google bounty for a Gemini Enterprise integration issue affecting persistent assistant memory.
Google awarded USD 20,000 for the Colab-export finding in a multi-finding research article.
One Workspace data-disclosure finding within a broader research article earned USD 20,000.
An authenticated media-editing operation exposed another user’s prompts and generated content because object ownership was not enforced. The researcher reports a USD 10,000 award.
Connected collection
Zafran’s tracing case, CVE-2026-41947, explains that console authentication did not bind configuration changes to the application’s tenant. Traces contain prompts and responses, so changing telemetry routing also…
The maintainer confirms that project-level MCP authentication did not authorize later file reads. Resource handlers reached storage without retaining user and project restrictions. A local two-user demonstration showed…
The advisory contrasts denied access to a private agent with accepted changes to its attached files. Upload handling omitted the agent permissions enforced elsewhere, allowing unauthorized context and search-file…
CVE-2026-31944 describes an MCP OAuth callback that trusted cached initiator identity without authenticating the returning browser or checking identity continuity. The advisory describes third-party credentials being…
The MCP registry prepared decrypted configuration for internal use, and response handlers returned that representation to viewers without removing secrets. Object visibility consequently became credential disclosure…
The maintainer advisory attributes cross-user knowledge-base file removal to an omitted ownership restriction in a database mutation. Its reported demonstration shows one deletion result. The boundary is between being…
Form elicitation excludes secrets. URL elicitation places sensitive interactions outside the MCP client and model context, with the requesting server and destination visible to the user. Agreeing to open the interaction…
Server permission challenges shape what a general-purpose MCP client requests. Broad discovery metadata and accumulated scopes can enlarge delegated authority. Token scopes still require application-side authorization.
CVE-2026-87015 concerns late-bound connection state: tool callables retained their own headers but read a shared cookie variable after connection processing finished. A maintainer-described controlled observation…
Explains why model-generated content remains untrusted when passed to browsers, databases or backend functions. The relevant boundary is the consuming component: plausible model text must not acquire executable meaning…
Defense-in-depth guidance for LLM applications that consume untrusted content or invoke tools. Covers data provenance, least privilege, action authorization, monitoring, and the limitations of guardrails.
Examines security assumptions around retrieval-augmented generation, including access to embeddings, cross-context disclosure and integrity of imported knowledge. Shared retrieval infrastructure must preserve the…
Connected collection
Editorial conceptual model derived from the linked cases and official guidance; not a vendor architecture diagram or an exploitation sequence.
Related learning follows the topic crosswalk or an explicit diagram relationship. It does not classify a resource as a finding. Topics overlap, so their counts should not be added together.
GitHub snapshot 2026-10-04
53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software
| / | Focus search on this page |
| Ctrl K | Search everything (command palette) |
| 1-9 | Library, Generator, Playbooks, Gadgets, Checklists, Payloads, Bypasses, Utilities, Reports |
| 0 | AI / MCP connector |
| j / k | Move selection down / up |
| Enter | Expand / open selected |
| c | Copy primary command of selected |
| f | Toggle favorite on selected tool |
| Esc | Clear search / close |