One Researcher, Seven Agent CVEs in a Day: HaiND’s VulnCheck Batch Maps the Trust Boundaries Agents Keep Redrawing
On 10 October 2026, NVD published seven CVEs in the space of about four hours — CVE-2026-108115 at 15:16 UTC, CVE-2026-108583 at 16:16, CVE-2026-108585 and CVE-2026-108586 at 17:17, and CVE-2026-108592, CVE-2026-108595, and CVE-2026-108600 at 19:16 — and every one of them comes from the same researcher, HaiND (Nguyen Dinh Hai) of the Posts and Telecommunications Institute of Technology, disclosed through VulnCheck, each with a public HackMD writeup pinned to exact source lines. Every one of them is in AI agent or MCP software: Kortix Suna, zotero-mcp, the official Argo CD MCP server, 1MCP Agent, mini-swe-agent, Phi, and open-multi-agent. As of our checks the same day, six of the seven have no published fix. Only Suna shipped a patch.
This is not seven unrelated bugs that happened to land together. Read as a batch, the disclosures are a catalogue of the same failure wearing seven costumes: a trust boundary the agent framework drew, and a second path around it that nobody enforced. A scope check that validates what the expression mentions instead of what it selects. A guard applied to one URL sink but not its sibling. A sandbox rooted at a model-chosen directory. A path check that never looked at the final symlink. Individually the severities are moderate — CVSS 4.0 scores from 2.3 to 6.0. Collectively they say the agent supply chain keeps rebuilding the same missing check in new code.
The batch at a glance
- CVE-2026-108115 — Kortix Suna SSRF guard bypass (CWE-918). Suna 0.10.7 through before 0.13.52. The shared egress guard
isPrivateIpunwrapped two IPv4-in-IPv6 encodings (::ffff:a.b.c.dand IPv4-compatible) but not IPv6 6to4 (2002::/16), sohttp://[2002:0a00:0005::]/— private10.0.0.5— passed as public. CVSS 4.9 (3.1) / 2.3 (4.0). Fixed in v0.13.52 (commit9c949e4). - CVE-2026-108583 — zotero-mcp SSRF via
zotero_add_by_url(CWE-918). Versions 0.10.0 through 0.14.1. The generic webpage-metadata fetch uses a barerequests.getwith no destination check and default redirect-following, while the sibling PDF-download path in the same project is guarded by_url_resolves_to_public_hostwith per-hop re-validation. Blind, metadata-only readback. CVSS 4.2 / 2.3. No fix published. - CVE-2026-108585 — Argo CD MCP route smuggling (CWE-22).
argocd-mcpthrough 0.9.0, in the officialargoproj-labs/mcp-for-argocdrepository.delete_applicationsplicesapplicationNameinto the request path unencoded;new URL(path, base)then normalizes../, so../repositories/<repo>turns “delete an application” into an authenticatedDELETEagainst the repositories, clusters, or projects endpoints with the server token. CVSS 5.4 / 5.3. No fix published. - CVE-2026-108586 — 1MCP Agent OAuth tag-scope bypass (CWE-863).
@1mcp/agent0.20.0 through 0.39.0. The scope middleware authorizes the tag names an advanced filter mentions; a token granted onlytag:internalpasses the check fornot internal, and the downstream filter then evaluates the complement — selecting exactly the backends the token was never granted — with no second check at invocation time. CVSS 5.4 / 5.3. No fix published. - CVE-2026-108592 — mini-swe-agent sandbox environment leak (CWE-526/200). Versions 1.10.0 through 2.4.6. The opt-in
BubblewrapEnvironmentnever passes--clearenv,subprocess.rungets noenv=mapping, and the runner loads a global.envintoos.environ— so sandboxed agent commands inherit provider keys likeOPENROUTER_API_KEY, with host network still reachable (no--unshare-net). CVSS 5.3 / 6.0. No fix published. - CVE-2026-108595 — Phi sub-agent workspace escape (CWE-863). Versions 0.3.0 through 0.28.4. Three facts combine:
agent_spawncopies a model-chosenworkdirunchecked, the permission gate maps it toActionAgentwhich is always allowed (readonly folding never touches it), and the child runner builds a fresh gate rooted at that directory — so a worker “in-workspace” write lands outside the parent workspace. CVSS 5.3 / 6.0. No fix published. - CVE-2026-108600 — open-multi-agent symlink sandbox escape (CWE-59/22).
@open-multi-agent/core1.5.0 through 1.21.2. TherealpathToleranthelper resolves the longest existing prefix and re-attaches a dangling final symlink name with a plainjoin()— never callinglstat— so the containment check sees an in-root path whilewriteFilewithO_CREATand noO_NOFOLLOWfollows the link and creates the file outside the workspace. CVSS 4.7 / 5.7. No fix published.
An eighth disclosure in the same NVD cluster, CVE-2026-108593 against the 9router dashboard (config injection into a managed agent config file, CVSS 6.4/7.3, requires a privileged dashboard user), sits outside the agent-runtime theme and we note it here only for completeness.
Why these seven belong in one story
Three threads run through the batch. First, four of the seven are prompt-injection-reachable by design: the zotero-mcp, argocd-mcp, Phi, and mini-swe-agent writeups each describe the trigger as untrusted content steering the model into a legitimate tool call — no exploit primitives, no authentication bypass, just the agent doing its job with attacker-influenced arguments. That is the same shape as the SSRF cluster across five MCP servers we covered earlier this month: the tool is the vulnerability’s delivery mechanism.
Second, three are authorization checks that verify the wrong thing. 1MCP checks which tags the filter names rather than which backends it selects. Argo CD MCP checks nothing about where the final normalized path lands. Phi checks the spawn action’s category rather than the workspace it creates. In each case the check exists, runs, and passes — on a question adjacent to the one that mattered.
Third, the guards the projects needed already existed nearby. zotero-mcp’s PDF path has the exact SSRF guard the webpage path lacks. Suna’s guard handled two of three IPv4-in-IPv6 encodings. mini-swe-agent’s --setenv PATH shows the intended model was an environment allowlist — minus the --clearenv that would make it one. open-multi-agent’s two-sided containment check (lexical pre-check plus post-resolution check) is genuinely careful engineering with one hole in the middle. These are not projects that never thought about the threat; they are projects where the defense stopped one sink short.
The Suna fix is the model response
Credit where it is due: Suna is the one project in the batch with a shipped remediation. The advisory names v0.13.52 (released 7 October, with v0.13.53 following on 9 October) and points at fix commit 9c949e4. The affected range is precisely bounded below the fixed version (0.10.7 to before 0.13.52), which is how coordinated disclosure is supposed to read. Everyone else in the batch is still in the “coordinated disclosure in progress” state their writeups declare — the HackMD badges said “no CVE assigned yet” when written, and the CVEs have now been assigned with NVD status still at Received (or Deferred for the Argo CD entry) and no independent NVD analysis. We checked the newest published releases of all six remaining projects on 10 October — zotero-mcp v0.14.1, 1MCP v0.39.0, argocd-mcp v0.9.0, Phi v0.28.4, mini-swe-agent v2.4.6, open-multi-agent v1.21.2 — and each still falls inside its advisory’s affected range, with recent commits showing dependency and UI work rather than security fixes.
What to do
- Update Suna to 0.13.52 or later if you self-host it. It is the only item in the batch with an installable fix.
- Treat the other six as tool-contract risks, not patch queues. Restrict which tools reach the model: run Argo CD MCP with
MCP_READ_ONLY=trueunless writes are genuinely needed, gate 1MCP behind a single-trust-domain deployment until tag scoping is fixed, and do not exposezotero_add_by_urlto agents processing untrusted content. - Assume model-chosen paths are attacker-influenced. The Phi and open-multi-agent flaws share one lesson: any directory, filename, or filter expression the model supplies must be validated against the parent’s grant, not just syntactically. Constrain sub-agent workdirs to the parent workspace and resolve-then-recheck symlinks with
lstat, not tolerant fallbacks. - Audit sandbox flag lists, not just sandbox presence. mini-swe-agent’s Bubblewrap backend is a sandbox — one missing flag (
--clearenv) away from containing secrets. If you run agents under bwrap, Docker, or namespaces, verify environment inheritance and network sharing explicitly; “runs in a sandbox” is a claim about flags, not a property of the tool name. - Finish denylists in threes, not twos. Suna blocked
::ffff:and IPv4-compatible embeddings but missed 6to4 (and flags Teredo in the advisory title). Any IPv6 private-range check must handle mapped, compatible, 6to4 (2002::/16), and Teredo (2001::/32) forms — or, better, resolve-then-check the embedded IPv4 uniformly.
Verification note: all seven CVE descriptions, affected ranges, CWE assignments, CVSS vectors, and reference lists were read first-hand from NVD API records fetched 10 October 2026 (status Received for six, Deferred for CVE-2026-108585; VulnCheck as assigning source throughout, no independent NVD analysis yet). Advisory details, severity labels, researcher credit, and coordinated-disclosure status were read first-hand from the seven VulnCheck advisory pages. Root-cause mechanics, file and line references, and code excerpts were read first-hand from the seven HaiND HackMD writeups linked below. Release and commit data (latest tags, dates, and recent commit subjects) were read first-hand from the GitHub API for each of the seven repositories on 10 October 2026; the no-fix assessment reflects the newest published non-draft releases at that time. The 9router note is from its NVD record only. We tested nothing and exploited nothing.
Sources:
- VulnCheck — Kortix Suna SSRF Guard Bypass via IPv6 6to4 Addresses (10 October 2026; advisory, fixed-version reference)
- VulnCheck — zotero-mcp SSRF via zotero_add_by_url Tool (10 October 2026; advisory)
- VulnCheck — argocd-mcp Path Traversal via delete_application Tool (10 October 2026; advisory)
- VulnCheck — 1MCP Agent OAuth Tag-Scope Bypass via Negated Tag Filter (10 October 2026; advisory)
- VulnCheck — mini-swe-agent Environment Exposure via BubblewrapEnvironment (10 October 2026; advisory)
- VulnCheck — Phi Permission Bypass via agent_spawn Workdir (10 October 2026; advisory)
- VulnCheck — open-multi-agent Sandbox Escape via file_write Dangling Symlink (10 October 2026; advisory)
- HaiND — Suna SSRF guard accepts IPv6 6to4 addresses (researcher writeup with source analysis)
- HaiND — zotero-mcp generic webpage import fetches caller-supplied URLs with no SSRF guard (researcher writeup)
- HaiND — Argo CD MCP delete_application request smuggling via dot-segment (researcher writeup)
- HaiND — 1MCP Agent negated tag-filter scope bypass (researcher writeup)
- HaiND — mini-swe-agent Bubblewrap backend inherits the host environment (researcher writeup)
- HaiND — Phi sub-agent worker escapes the parent readonly workspace (researcher writeup)
- HaiND — Open Multi-Agent file_write escapes the sandbox through a dangling symlink (researcher writeup)