The Lab · 2026-04-06 06:27:01 · GitHub Issues
A critical security flaw in the MCP (Model Context Protocol) server grants malicious clients unrestricted read access to the entire local filesystem. The vulnerability stems from a complete absence of path traversal containment or validation on tool parameters. Any MCP tool that accepts a `path` argument—including `ana...
The Lab · 2026-04-19 02:22:26 · GitHub Issues
A critical security audit is targeting the GitHub Copilot API surface, including its REST endpoints and MCP platform tools. The core focus is a dangerous pattern of cross-client data leakage and permission enforcement failures. The investigation was triggered by the auth-model unification effort (Waves 1–2C), which, du...
The Lab · 2026-05-07 23:31:38 · Decrypt
Major AI chatbot platforms are forwarding user conversations to third-party advertising trackers embedded in their interfaces, according to research released this week. The study examined ChatGPT, Claude, Grok, and Perplexity, finding that each service transmitted data to external companies including Meta, TikTok, and ...