Read original ↗
newsGitLab BlogTrust 72 · OutletPublished yesterdayLive · 41m ago

Critical remote code execution in Serena, a popular MCP coding agent

Serena, one of the most widely used AI coding agents, ran attacker-supplied code the moment a developer opened a project. GitLab's Threat Research Group found a critical server-side template injection ( GHSA-pp25-4cg4-qcr9 , CVE pending) that executes arbitrary code in the Serena process. Anyone on serena-agent 1.6.1 or earlier should update to 1.7.0 now. A threat actor can exploit this by hiding

Why these links exist

Every edge carries a method, confidence, and the source snippet that justified it — so bad links are debuggable.

Covers

Related across the graph