One Researcher, Seven Agent CVEs in a Day: HaiND’s VulnCheck Batch Maps the Trust Boundaries Agents Keep Redrawing

On 10 October 2026, NVD published seven CVEs in the space of about four hours — CVE-2026-108115 at 15:16 UTC, CVE-2026-108583 at 16:16, CVE-2026-108585 and CVE-2026-108586 at 17:17, and CVE-2026-108592, CVE-2026-108595, and CVE-2026-108600 at 19:16 — and every one of them comes from the same researcher, HaiND (Nguyen Dinh Hai) of the Posts and Telecommunications Institute of Technology, disclosed through VulnCheck, each with a public HackMD writeup pinned to exact source lines. Every one of them is in AI agent or MCP software: Kortix Suna, zotero-mcp, the official Argo CD MCP server, 1MCP Agent, mini-swe-agent, Phi, and open-multi-agent. As of our checks the same day, six of the seven have no published fix. Only Suna shipped a patch.

This is not seven unrelated bugs that happened to land together. Read as a batch, the disclosures are a catalogue of the same failure wearing seven costumes: a trust boundary the agent framework drew, and a second path around it that nobody enforced. A scope check that validates what the expression mentions instead of what it selects. A guard applied to one URL sink but not its sibling. A sandbox rooted at a model-chosen directory. A path check that never looked at the final symlink. Individually the severities are moderate — CVSS 4.0 scores from 2.3 to 6.0. Collectively they say the agent supply chain keeps rebuilding the same missing check in new code.

The batch at a glance

  • CVE-2026-108115 — Kortix Suna SSRF guard bypass (CWE-918). Suna 0.10.7 through before 0.13.52. The shared egress guard isPrivateIp unwrapped two IPv4-in-IPv6 encodings (::ffff:a.b.c.d and IPv4-compatible) but not IPv6 6to4 (2002::/16), so http://[2002:0a00:0005::]/ — private 10.0.0.5 — passed as public. CVSS 4.9 (3.1) / 2.3 (4.0). Fixed in v0.13.52 (commit 9c949e4).
  • CVE-2026-108583 — zotero-mcp SSRF via zotero_add_by_url (CWE-918). Versions 0.10.0 through 0.14.1. The generic webpage-metadata fetch uses a bare requests.get with no destination check and default redirect-following, while the sibling PDF-download path in the same project is guarded by _url_resolves_to_public_host with per-hop re-validation. Blind, metadata-only readback. CVSS 4.2 / 2.3. No fix published.
  • CVE-2026-108585 — Argo CD MCP route smuggling (CWE-22). argocd-mcp through 0.9.0, in the official argoproj-labs/mcp-for-argocd repository. delete_application splices applicationName into the request path unencoded; new URL(path, base) then normalizes ../, so ../repositories/<repo> turns “delete an application” into an authenticated DELETE against the repositories, clusters, or projects endpoints with the server token. CVSS 5.4 / 5.3. No fix published.
  • CVE-2026-108586 — 1MCP Agent OAuth tag-scope bypass (CWE-863). @1mcp/agent 0.20.0 through 0.39.0. The scope middleware authorizes the tag names an advanced filter mentions; a token granted only tag:internal passes the check for not internal, and the downstream filter then evaluates the complement — selecting exactly the backends the token was never granted — with no second check at invocation time. CVSS 5.4 / 5.3. No fix published.
  • CVE-2026-108592 — mini-swe-agent sandbox environment leak (CWE-526/200). Versions 1.10.0 through 2.4.6. The opt-in BubblewrapEnvironment never passes --clearenv, subprocess.run gets no env= mapping, and the runner loads a global .env into os.environ — so sandboxed agent commands inherit provider keys like OPENROUTER_API_KEY, with host network still reachable (no --unshare-net). CVSS 5.3 / 6.0. No fix published.
  • CVE-2026-108595 — Phi sub-agent workspace escape (CWE-863). Versions 0.3.0 through 0.28.4. Three facts combine: agent_spawn copies a model-chosen workdir unchecked, the permission gate maps it to ActionAgent which is always allowed (readonly folding never touches it), and the child runner builds a fresh gate rooted at that directory — so a worker “in-workspace” write lands outside the parent workspace. CVSS 5.3 / 6.0. No fix published.
  • CVE-2026-108600 — open-multi-agent symlink sandbox escape (CWE-59/22). @open-multi-agent/core 1.5.0 through 1.21.2. The realpathTolerant helper resolves the longest existing prefix and re-attaches a dangling final symlink name with a plain join() — never calling lstat — so the containment check sees an in-root path while writeFile with O_CREAT and no O_NOFOLLOW follows the link and creates the file outside the workspace. CVSS 4.7 / 5.7. No fix published.

An eighth disclosure in the same NVD cluster, CVE-2026-108593 against the 9router dashboard (config injection into a managed agent config file, CVSS 6.4/7.3, requires a privileged dashboard user), sits outside the agent-runtime theme and we note it here only for completeness.

Why these seven belong in one story

Three threads run through the batch. First, four of the seven are prompt-injection-reachable by design: the zotero-mcp, argocd-mcp, Phi, and mini-swe-agent writeups each describe the trigger as untrusted content steering the model into a legitimate tool call — no exploit primitives, no authentication bypass, just the agent doing its job with attacker-influenced arguments. That is the same shape as the SSRF cluster across five MCP servers we covered earlier this month: the tool is the vulnerability’s delivery mechanism.

Second, three are authorization checks that verify the wrong thing. 1MCP checks which tags the filter names rather than which backends it selects. Argo CD MCP checks nothing about where the final normalized path lands. Phi checks the spawn action’s category rather than the workspace it creates. In each case the check exists, runs, and passes — on a question adjacent to the one that mattered.

Third, the guards the projects needed already existed nearby. zotero-mcp’s PDF path has the exact SSRF guard the webpage path lacks. Suna’s guard handled two of three IPv4-in-IPv6 encodings. mini-swe-agent’s --setenv PATH shows the intended model was an environment allowlist — minus the --clearenv that would make it one. open-multi-agent’s two-sided containment check (lexical pre-check plus post-resolution check) is genuinely careful engineering with one hole in the middle. These are not projects that never thought about the threat; they are projects where the defense stopped one sink short.

The Suna fix is the model response

Credit where it is due: Suna is the one project in the batch with a shipped remediation. The advisory names v0.13.52 (released 7 October, with v0.13.53 following on 9 October) and points at fix commit 9c949e4. The affected range is precisely bounded below the fixed version (0.10.7 to before 0.13.52), which is how coordinated disclosure is supposed to read. Everyone else in the batch is still in the “coordinated disclosure in progress” state their writeups declare — the HackMD badges said “no CVE assigned yet” when written, and the CVEs have now been assigned with NVD status still at Received (or Deferred for the Argo CD entry) and no independent NVD analysis. We checked the newest published releases of all six remaining projects on 10 October — zotero-mcp v0.14.1, 1MCP v0.39.0, argocd-mcp v0.9.0, Phi v0.28.4, mini-swe-agent v2.4.6, open-multi-agent v1.21.2 — and each still falls inside its advisory’s affected range, with recent commits showing dependency and UI work rather than security fixes.

What to do

  • Update Suna to 0.13.52 or later if you self-host it. It is the only item in the batch with an installable fix.
  • Treat the other six as tool-contract risks, not patch queues. Restrict which tools reach the model: run Argo CD MCP with MCP_READ_ONLY=true unless writes are genuinely needed, gate 1MCP behind a single-trust-domain deployment until tag scoping is fixed, and do not expose zotero_add_by_url to agents processing untrusted content.
  • Assume model-chosen paths are attacker-influenced. The Phi and open-multi-agent flaws share one lesson: any directory, filename, or filter expression the model supplies must be validated against the parent’s grant, not just syntactically. Constrain sub-agent workdirs to the parent workspace and resolve-then-recheck symlinks with lstat, not tolerant fallbacks.
  • Audit sandbox flag lists, not just sandbox presence. mini-swe-agent’s Bubblewrap backend is a sandbox — one missing flag (--clearenv) away from containing secrets. If you run agents under bwrap, Docker, or namespaces, verify environment inheritance and network sharing explicitly; “runs in a sandbox” is a claim about flags, not a property of the tool name.
  • Finish denylists in threes, not twos. Suna blocked ::ffff: and IPv4-compatible embeddings but missed 6to4 (and flags Teredo in the advisory title). Any IPv6 private-range check must handle mapped, compatible, 6to4 (2002::/16), and Teredo (2001::/32) forms — or, better, resolve-then-check the embedded IPv4 uniformly.

Verification note: all seven CVE descriptions, affected ranges, CWE assignments, CVSS vectors, and reference lists were read first-hand from NVD API records fetched 10 October 2026 (status Received for six, Deferred for CVE-2026-108585; VulnCheck as assigning source throughout, no independent NVD analysis yet). Advisory details, severity labels, researcher credit, and coordinated-disclosure status were read first-hand from the seven VulnCheck advisory pages. Root-cause mechanics, file and line references, and code excerpts were read first-hand from the seven HaiND HackMD writeups linked below. Release and commit data (latest tags, dates, and recent commit subjects) were read first-hand from the GitHub API for each of the seven repositories on 10 October 2026; the no-fix assessment reflects the newest published non-draft releases at that time. The 9router note is from its NVD record only. We tested nothing and exploited nothing.

Sources: