Critical remote code execution in Serena, a popular MCP coding agent
about.gitlab.com | vulnerability | Critical | #rce | #supply-chain | #gitlab | #mcp | #template-injection | #serena | #ai-coding-agent
Summary
GitLab found a critical template injection in Serena, an MCP coding agent: a malicious project.yml executes attacker code when a developer opens the repo, bypassing its trust controls; fixed in 1.7.0.
Why it matters
This vulnerability coverage helps defenders validate exposure and prioritize remediation.
- Vendor
- GitLab
- Product
- Serena MCP coding agent
- Published
- Collected
Skip to content