WhisperX tag archive

#Credential Exfiltration

This page collects WhisperX intelligence signals tagged #Credential Exfiltration. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (1)

The Lab · 2026-04-10 02:39:40 · GitHub Issues

1. GitHub MCP Proxy Exposes Critical SSRF Flaw, Enabling Internal Network & Credential Exfiltration

A critical Server-Side Request Forgery (SSRF) vulnerability has been exposed within GitHub's MCP (Model Context Protocol) proxy, allowing user-created MCP servers to force the platform's backend to fetch arbitrary external URLs without validation. This flaw transforms the proxy into a direct conduit for attackers to pr...