newsGitLab BlogTrust 72 · OutletPublished yesterdayLive · 41m ago
Critical remote code execution in Serena, a popular MCP coding agent
Serena, one of the most widely used AI coding agents, ran attacker-supplied code the moment a developer opened a project. GitLab's Threat Research Group found a critical server-side template injection ( GHSA-pp25-4cg4-qcr9 , CVE pending) that executes arbitrary code in the Serena process. Anyone on serena-agent 1.6.1 or earlier should update to 1.7.0 now. A threat actor can exploit this by hiding
Why these links exist
Every edge carries a method, confidence, and the source snippet that justified it — so bad links are debuggable.
- PossiblePossibly related (embedding) · 53%LuD1161/agentjail →
- PossiblePossibly related (embedding) · 53%Tako-Research/TakoVM →
- PossiblePossibly related (embedding) · 52%Distributed Attacks in Persistent-State AI Control →
- PossiblePossibly related (embedding) · 52%liaohch3/claude-tap →
- PossiblePossibly related (embedding) · 51%kahliburke/Kaimon.jl →
