Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Critical remote code execution in Serena, a popular MCP coding agent

Summary

GitLab found a critical template injection in Serena, an MCP coding agent: a malicious project.yml executes attacker code when a developer opens the repo, bypassing its trust controls; fixed in 1.7.0.

Why it matters

This vulnerability coverage helps defenders validate exposure and prioritize remediation.
Vendor
GitLab
Product
Serena MCP coding agent
Published
Collected

original ↗

Related coverage

back