流行的 MCP 编码代理 Serena 存在关键远程代码执行漏洞
about.gitlab.com | 漏洞 | 严重 | #rce | #supply-chain | #gitlab | #mcp | #template-injection | #serena | #ai-coding-agent
摘要
GitLab 在 MCP 编码代理 Serena 中发现严重服务端模板注入(GHSA-pp25-4cg4-qcr9):恶意 .serena/project.yml 藏入仓库后,开发者用 MCP 服务器打开项目即触发任意代码执行,绕过其可信路径机制;1.7.0 已修复。
为什么值得关注
这篇漏洞报道帮助防守方确认受影响范围并确定修复优先级。
- 厂商
- GitLab
- 产品
- Serena MCP coding agent
- 发布时间
- 收录时间
Skip to content