Day Two of the HaiND Batch: 22 Agent and MCP CVEs, a 9.4 Hardcoded Credential, and an Unauthenticated DoS in the Official MCP Kotlin SDK

On 11 October 2026, NVD published 68 CVEs from a single researcher — HaiND, disclosed through VulnCheck — with IDs running nearly contiguously from CVE-2026-108688 to CVE-2026-108760 and publication timestamps clustered around 13:17 UTC. It is the second day of a sustained disclosure run: yesterday we covered seven agent and MCP CVEs from the same researcher and channel, and today the agent-relevant subset alone is eighteen. Four more same-day NVD publications in core AI stack software — two LiteLLM flaws, an AG2 path traversal, and an MCP-handler SSRF, all via a different discloser with public exploits — bring this briefing to twenty-two. Four of the twenty-two score CVSS 7.0 or above, including a 9.4 hardcoded credential. Exactly one has a published fix.

The batch is not twenty-two variations on one bug. It is four distinct structural failures repeating across the agent supply chain: scoped credentials that do not actually scope, agent infrastructure (official SDKs included) that accepts unauthenticated input, sandboxes that validate the name instead of the file, and self-host defaults that ship the keys with the product. Each writeup again pins the flaw to exact source lines with a public HackMD analysis, so the catalogue is checkable claim by claim.

The 22 at a glance

  • CVE-2026-108753 — Agnai hard-coded credentials (CWE-798). CVSS 9.4. self-host.docker-compose.yml through 1.0.555 sets a fixed admin password and a public JWT secret. Unauthenticated attackers can log in as admin or sign their own admin: true JWT to impersonate users, reset passwords, and change server configuration. No fix named.
  • CVE-2026-108760 — LlamaFarm unrestricted bind + unauthenticated API (CWE-1327). CVSS 7.6. Through 0.0.34, the unauthenticated FastAPI server binds all interfaces on port 14345 while the lf CLI silently discards HOST overrides. Adjacent-network attackers can read stored provider API keys, modify projects, trigger ingestion, and irreversibly delete projects. No fix named.
  • CVE-2026-108714 — MCP Kotlin SDK memory exhaustion (CWE-770). CVSS 7.5. Through 0.15.0, Application.mcpWebSocket installs Ktor WebSockets with no maxFrameSize limit: small frame headers declaring payloads near 2 GiB force huge heap allocations over one or a few connections. Unauthenticated remote DoS against the official MCP SDK. No fix named; 0.15.0 is still the newest release.
  • CVE-2026-108739 — OpenAgents Workspace unauthenticated key disclosure (CWE-306). CVSS 7.5. Through launcher-v1.0.17, unauthenticated GET /v1/workspaces lists every workspace including the unmasked browserfabric_api_key, workspace ids, slugs, creator emails, and member lists. No fix named.
  • CVE-2026-108759 — mistral.rs code-exec sandbox escape (CWE-59). CVSS 6.8. mistralrs-code-exec 0.9.0 through 0.9.4 follows symlinks: outputs named as symlinks, or sessions reusing symlinked input paths, read and overwrite files outside the sandbox with server-process permissions. The record explicitly names prompt-injected agents as attackers. No fix named.
  • CVE-2026-108757 — pinclaw missing authentication (CWE-306). CVSS 6.5. The OpenClaw channel plugin through 0.3.0 skips the authToken check on POST /pinclaw/send, so unauthenticated callers reaching port 18790 — bound to all interfaces by default — can inject blind prompts into the user's main agent session as user instructions. No fix named.
  • CVE-2026-108542 — elvix-sdk MCP SSRF (CWE-918). CVSS 6.3. elvix-sdk through 0.10.1: the src/mcp/index.ts MCP request handler's path argument yields server-side request forgery. Public exploit; vendor contacted early, no response. (Different discloser; see LiteLLM/AG2 note below.)
  • CVE-2026-108543 — AG2 UserProxyAgent path traversal (CWE-22). CVSS 6.3. ag2ai AG2 through 0.13.4: legacy filename handling around os.path.join in the UserProxyAgent component allows remote path traversal. Public exploit; vendor contacted early, no response.
  • CVE-2026-108575 — LiteLLM secret-resolution improper authorization (CWE-266/285). CVSS 6.3. Through 1.94.0, get_secret in secret_managers/main.py: the api_key argument drives improper authorization. Public exploit; vendor contacted early, no response.
  • CVE-2026-108725 — Cheshire Cat AI stored XSS (CWE-79). CVSS 5.4. Core through 2.0.23: the uploads plugin accepts HTML via POST /uploads with no type restriction, served back at public GET /uploads/{path} in the application origin with the victim's access_token cookie — including administrators. No fix named.
  • CVE-2026-108756 — Abilityai Trinity missing authorization (CWE-862). CVSS 5.4. Through 0.9.5: agent-scoped MCP API keys can perform human-only Telegram binding operations — send messages through the owner's bot token, replace the binding with an attacker token, or delete it. The record names prompt injection as the typical route to controlling the agent. No fix named.
  • CVE-2026-108716 — mcp-remote cleartext OAuth transport (CWE-319). CVSS 5.3. 0.8.0 through 0.14.3: authorizeWithDeviceCode sends client secrets and receives tokens without enforcing HTTPS, so on-path attackers capture secrets plus issued access and refresh tokens when endpoints are non-loopback HTTP. No fix named; 0.14.3 is still the newest release.
  • CVE-2026-108721 — Open Computer Use denylist bypass (CWE-178). CVSS 5.3. iFurySt's macOS build through 1.0.0: case-variant bundle identifiers such as com.1Password.1Password bypass the password-manager denylist, exposing accessibility trees, screenshots, and control of unlocked password-manager UI to local MCP callers — explicitly including prompt-injected model turns. No fix named.
  • CVE-2026-108748 — Quarkus LangChain4j WebSocket memory leak (CWE-401). CVSS 5.3. 1.9.0 through 1.14.1: repeated CONNECT frames reusing one chatId against /_chat/routes orphan scopes in activeScopes until the JVM exits. Unauthenticated remote availability loss. No fix named.
  • CVE-2026-108719 — LLMGateway blind SSRF (CWE-918). CVSS 5.0. Through 1.20.0: the video-generation callback_url extension skips the assertSafeWebhookTarget check, so API key holders can make the worker POST to loopback, private, or cloud-metadata URLs. Scope changed. No fix named.
  • CVE-2026-108751 — MoAI-ADK symlink overwrite (CWE-59). CVSS 4.4. Through 3.1.2: the moai init template deployer follows a symlinked .moai-tmp staging path, so a malicious repository (e.g. a crafted .claude/settings.json.moai-tmp) gets atomicWriteFile to truncate and overwrite victim-writable files outside the project. No fix named.
  • CVE-2026-108574 — LiteLLM spend-tracking authorization bypass (CWE-285/639). CVSS 4.3. Through 1.95.0, ui_view_session_spend_logs: session_id manipulation reads other tenants' spend data. Fixed in 1.96.0 (commit 722d9ffa) — the only fixed item in this briefing.
  • CVE-2026-108711 — Honcho scoped-key over-read (CWE-863). CVSS 4.3. Plastic Labs Honcho through 3.3.0: get_or_create_workspace checks only the workspace claim, so peer- or session-scoped API keys submitted with a parent workspace name to POST /v3/workspaces retrieve metadata and configuration — including custom_instructions — reserved for workspace or admin keys. No fix named.
  • CVE-2026-108722 — e2b open-computer-use stored XSS (CWE-79). CVSS 4.2. Through commit 610bac8: Logger.write_log_file writes transcript text into log.html without escaping, so sandbox content — web pages or files surfacing in run_command output — injects script that runs when the operator opens the log and can exfiltrate transcript contents. No fix named.
  • CVE-2026-108749 — docling-serve missing authentication (CWE-306). CVSS 3.7. 1.14.0 through 1.36.0: /v1/memory/stats and /v1/memory/counts omit the require_auth dependency, bypassing DOCLING_SERVE_API_KEY for telemetry reads and forced gc.collect() heap enumeration. No fix named.
  • CVE-2026-108754 — GPT-Load cleartext key logging (CWE-532). CVSS 3.3. Through 1.4.11: the Gin Logger middleware records the raw query string before extractAuthKey strips the key parameter, so Gemini-style request proxy keys land in console logs and ./data/logs/app.log. No fix named.
  • CVE-2026-108741 — Shepherd citation-checker SSRF via DNS rebinding (CWE-367). CVSS 3.1. shepherd-ai through 0.3.1: the public_url guard validates a resolved address but fetch re-resolves at connect time, so an attacker who plants a crafted reference URL and controls its DNS steers GETs to internal HTTP(S) services and captures responses in evidence files. The guard itself has the TOCTOU. No fix named.

Scoped credentials that do not scope

The largest thread in the batch is authorization shaped like scoping. Honcho mints peer- and session-scoped keys and then checks only the workspace claim on the workspace endpoint — the caller supplies the parent workspace name and reads configuration, including custom_instructions, that the scoping model reserves for higher-privilege keys. Trinity draws a human/agent line around Telegram binding operations and then never enforces the key type, so an agent-scoped MCP key — obtainable in practice by steering the agent, which the record explicitly frames as prompt injection — sends messages as the owner's bot, rebinds the bot to an attacker token, or deletes the binding. mcp-remote moves OAuth device-code secrets and tokens over whatever transport the discovered endpoints advertise, with no HTTPS enforcement, converting any on-path position into a credential capture. Three different layers — API key scopes, key-type boundaries, transport — each with the check present in the design and absent at the decision point. Yesterday's 1MCP tag-scope bypass was the same failure in miniature; today it arrives in five costumes.

The infrastructure is the target now

The second thread is what makes this batch qualitatively different from yesterday's seven. Two findings sit in shared agent infrastructure rather than end-user projects. The MCP Kotlin SDK flaw is in the official Model Context Protocol SDK: we read the 0.15.0 source first-hand and Application.mcpWebSocket calls install(WebSockets) with no frame-size configuration, so any remote client can declare ~2 GiB payloads behind small headers and exhaust the server heap. The newest published release is still 0.15.0 (July 2026), so the current SDK is the vulnerable SDK. Quarkus LangChain4j's chat-scopes WebSocket leaks a scope object per reused chatId until the JVM exits — a slower version of the same unauthenticated availability story in Red Hat-adjacent plumbing. When the SDK and the framework both accept unbounded unauthenticated input, every downstream MCP server inherits the exposure no matter how careful its own code is.

pinclaw belongs in this thread too, and it is the briefing's most operationally urgent mid-severity item. We read the plugin source first-hand: every sibling route in http-router.ts compares a Bearer token against authToken, but the POST /pinclaw/send handler reads {message} and passes it straight to processMessage with no check — and the server's listen(this.port) call binds all interfaces. Anyone who can reach port 18790 can put words into the operator's agent session as user instructions. That is unauthenticated, adjacent-network, direct prompt injection into somebody else's agent, in a plugin distributed via npm.

Sandboxes that check the name, not the file

mistral.rs, MoAI-ADK, and AG2 form a tight triple. In mistral.rs we read output_path first-hand: it rejects absolute paths and parent-directory components lexically, then joins — with no symlink resolution anywhere in the path, so a model-named symlink output or a session reusing a symlinked input escapes the sandbox with server permissions. MoAI-ADK's template deployer stages through .moai-tmp without resolving it, so a cloned repository's symlink becomes an arbitrary victim-writable file overwrite at moai init time — pointedly including .claude/settings.json, i.e. the victim's own agent configuration. AG2's UserProxyAgent traversal completes the set in the most widely deployed framework of the three. The Open Computer Use macOS finding is the same family with a different primitive: a denylist keyed on exact bundle identifiers, bypassed by changing the case. In every case the containment logic inspects the attacker-influenced string rather than the filesystem object it resolves to — the exact lesson yesterday's Phi and open-multi-agent writeups taught, unlearned in four new codebases.

Self-hosting defaults that ship the keys

Agnai is the 9.4 and deserves the number. We read the pinned compose file first-hand: INITIAL_PASSWORD=password and JWT_SECRET=self-hosting, committed to the repository's own self-host instructions. Anyone deploying from the documented path gets a publicly known admin password and a publicly known signing secret, and the record notes self-signed admin: true JWTs plus impersonation, password resets, and configuration changes. LlamaFarm pairs the same self-host shape with a network one: an unauthenticated management API containing provider keys, bound to every interface, with the CLI quietly ignoring the operator's attempt to change that. OpenAgents leaks the same class of secret — a third-party browser-automation API key — to unauthenticated callers through a list endpoint. GPT-Load and docling-serve show the quieter variants: keys written into log files by middleware ordering, and telemetry endpoints that simply forgot the auth dependency the rest of the app uses. None of these require an exploit primitive beyond connecting.

Fix status: one of twenty-two

LiteLLM's spend-tracking bypass is the sole item with a shipped remediation: NVD names 1.96.0 and the fix commit, and current LiteLLM releases are far past it. Everything else in this briefing names no fixed version — the NVD ranges are open-ended (“through 0.15.0”, “through 1.0.555”), and our release checks on 11 October confirm the two most load-bearing cases are still exposed at HEAD: mcp-remote's newest npm release is 0.14.3 (September 2026, the top of the affected range) and the Kotlin SDK's newest release is 0.15.0 (July 2026, likewise the top of its range). The three vuldb-sourced records (elvix-sdk, AG2, LiteLLM get_secret) additionally state the vendor was contacted early and did not respond, with exploits already public. That closes the loop on a pattern this site has now documented three times in a week — fixes that exist but never ship — except here there is not even a branch to point at: for twenty-one of twenty-two, there is nothing to upgrade to.

What to do

  • Patch LiteLLM to 1.96.0 or later for CVE-2026-108574, and treat CVE-2026-108575 (get_secret, no fix, public exploit) as an open exposure: restrict who can reach the management API and rotate secrets visible to it.
  • Do not expose Agnai self-host deployments to any network until the compose defaults change: set a unique INITIAL_PASSWORD and JWT_SECRET immediately, rotate both if the instance was ever reachable, and invalidate existing sessions — any admin JWT signed with the public secret must be assumed compromised.
  • Bind LlamaFarm, OpenAgents backends, and pinclaw to loopback and front them with authenticated proxies. LlamaFarm's HOST override is silently discarded, so verify the listening socket with ss -ltnp rather than trusting configuration; treat any internet-adjacent LlamaFarm or OpenAgents instance as having disclosed its keys and rotate provider and browser-automation credentials.
  • Cap MCP WebSocket frame sizes yourself. Until the Kotlin SDK ships a limit, configure maxFrameSize on the underlying Ktor engine where your deployment allows it, and put memory limits plus connection-rate controls in front of any MCP WebSocket endpoint. Audit Quarkus chat-scope deployments for unexplained JVM heap growth.
  • Treat every model-supplied path as a symlink. Resolve with realpath/lstat and re-check containment after resolution in any agent file tooling you operate; do not clone-and-init untrusted MoAI templates, and pin agent workspaces so sub-agent workdirs cannot escape the parent grant.
  • Assume SSRF sinks in agent-adjacent services are reachable by key holders. Review webhook callback_url parameters (LLMGateway pattern), citation/reference fetchers (Shepherd pattern — validate once and fetch through the validated channel, never re-resolve), and MCP request-handler path arguments (elvix-sdk pattern) for server-side egress to internal or metadata endpoints.

Verification note: all 22 CVE descriptions, affected ranges, CWE assignments, CVSS 3.1 vectors, publication timestamps, and reference lists were read first-hand from NVD API 2.0 records fetched 11 October 2026 (all status Received, no independent NVD analysis; assigning source disclosure@vulncheck.com for eighteen, cna@vuldb.com for four). The 68-record same-day HaiND/VulnCheck count and the 108688–108760 ID span were computed first-hand from the full 11 October NVD publication set (155 records). Source excerpts were read first-hand from raw.githubusercontent.com at the exact pins named in the records: Agnai compose credentials, pinclaw's unauthenticated /pinclaw/send handler beside its authenticated siblings and hostless listen() call, the Kotlin SDK's bare install(WebSockets), mistral.rs's lexical-only output_path, Trinity's token-validating configure handler, and LlamaFarm's documented port. Release data (mcp-remote 0.14.3, Kotlin SDK 0.15.0, LiteLLM 1.10x line, AG2 v1.2.0) were read first-hand from the npm registry and the GitHub releases API on 11 October 2026. A Brave search the same day surfaced only automated CVE aggregators for these IDs — no analytical coverage and no vendor advisories. We tested nothing and exploited nothing.

Sources: