WhisperX tag archive

#json-rpc

This page collects WhisperX intelligence signals tagged #json-rpc. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (2)

The Lab · 2026-03-30 20:27:28 · GitHub Issues

1. MCP-Hub Endpoint Exposed Without Auth or Rate Limiting, Relies on Network Isolation

A critical security oversight has been identified in the MCP-Hub server, where its primary JSON-RPC endpoint is exposed without standard authentication or rate-limiting controls. The hub's `POST /` endpoint, which handles sensitive operations like `execute_code`, is bound to `0.0.0.0` and accepts requests from any proc...

The Lab · 2026-04-01 16:27:19 · GitHub Issues

2. WAST Tool Expands to Scan MCP Servers for AI Agent Security Vulnerabilities

The WAST security tool is set to implement a new `wast mcpscan` command, explicitly targeting the emerging and largely unaudited attack surface of Model Context Protocol (MCP) servers. These servers, which expose tools to AI agents via JSON-RPC 2.0 over stdio, SSE, and HTTP, represent a critical new frontier for securi...