Several advisories tracked in September and October 2026 affect tools used around AI-assisted development. They do not describe one shared exploit. They do share a useful lesson: a tool described as local, read-only, or development-only can still become a security boundary when it accepts browser connections, opens a network transport, processes model-controlled content, or trusts workspace configuration.
Patch affected tools first. Then check whether the vulnerable feature was reachable in your environment. A vulnerable version is evidence that a fix is required, but it is not proof that exploitation occurred.
What happened
The confirmed advisories cover twelve products and multiple distinct security boundaries:
- Cline Hub: CVE-2026-59723 / GHSA-3cj3-hqcr-g934 describes cross-origin WebSocket hijacking in Cline before 3.0.30. A malicious website visited from the same machine could reach the local Hub service and alter sensitive configuration, including MCP settings.
- DBHub: CVE-2026-61742 / GHSA-fm8p-53ww-hf6w affects the unauthenticated HTTP MCP transport through 0.22.4, while CVE-2026-61788 / GHSA-mwwr-p57h-56pf describes a bypass of read-only query enforcement before 0.22.6. Version 0.22.6 is the safe combined target.
- Decepticon: CVE-2026-61732 / GHSA-g5f9-3xfg-p9mf documents a vulnerable 1.1.4 deployment and describes the flaw as not release-specific. Untrusted crawl content can cross a ChatML role boundary with a compatible BYOK model backend. GitHub’s package database lists 1.1.17 as patched, but that version is not established by the upstream description; obtain vendor confirmation before treating a release as fixed.
- AWS Language Servers: CVE-2026-12957 / GHSA-xhcr-j4j9-3gh7 concerns command execution from malicious trusted-workspace configuration before 1.65.0. CVE-2026-12958 / GHSA-6v3r-4p5c-mrp5 concerns arbitrary file writes through symbolic links before 1.69.0. For the npm package
@aws/lsp-codewhisperer, the corresponding fixed versions are 0.0.113 and 0.0.117; use 0.0.117 or later to address both. - LangChain NVIDIA AI Endpoints: GHSA-g28h-2cmm-rj9x describes local file disclosure when attacker-controlled image references reach a vision-language-model call.
langchain-nvidia-ai-endpoints1.4.2 fixes releases through 1.4.1. - Rsdoctor: CVE-2026-61782 / GHSA-jmg2-rcxh-w8q3 describes an unauthenticated development-server API that could expose source and build metadata.
@rsdoctor/rspack-plugin1.5.16 fixes releases through 1.5.15. - SCBE-AETHERMOORE: CVE-2026-57443 / GHSA-q986-4x7x-gx39 describes an unauthenticated AetherBrowser operations endpoint that could run an email-reader subprocess and return operator email metadata. The upstream advisory lists 4.2.1 as affected and 4.3.0 or later as patched. GitHub’s package database instead lists 4.2.1 as the fix; use the upstream target of 4.3.0 or later and verify the operations endpoint is protected.
- Khoj: GHSA-62mm-xwmv-crhg describes an unauthenticated path traversal in the
/home/static-file route that could expose files readable by the server process. Khoj 2.0.0-beta.25 fixes versions 2.0.0-beta.23 and 2.0.0-beta.24. - Knowns: CVE-2026-86439 / GHSA-9gfj-28hw-jchp describes filesystem escapes in MCP Docs and Memory tools. Depending on granted capabilities, attacker-controlled paths could read, write, rename, or delete Markdown files outside the project sandbox. Knowns 0.30.0 fixes versions through 0.29.1.
- Kibana Agent Builder: CVE-2026-72668 is a confused-deputy flaw in Kibana 9.4.0 through 9.4.6. A non-administrator who can edit a shared agent can cause attached operations to run when a higher-privileged user later interacts with that agent. If the same user can also author workflows, the impact can extend to full administrative control. Kibana 9.4.7 and 9.5.0 contain the fix.
- vm2: CVE-2026-100721, CVE-2026-100722, and CVE-2026-100723 affect versions before 3.12.2. Their documented configurations can permit an external-module authorization bypass into host execution, terminate the host through a rejected Promise crossing a constructor bridge, or expose pooled host memory through an allowlisted
zlibmodule. - Penpot MCP: GHSA-ch2q-6x56-qg5r describes a plugin WebSocket bridge that binds to all interfaces despite the documented localhost default. In single-user mode, an unauthenticated network peer can intercept or forge plugin tasks or disrupt the integration. The upstream advisory lists Penpot through 2.17.2 as affected and 2.18.0 as patched. It does not establish a separate fixed version for the npm package
@penpot/mcp.
Use the current CISA Known Exploited Vulnerabilities catalog when prioritizing response. A catalog listing is evidence of known exploitation; absence does not establish safety.
Who was exposed
Exposure depends on more than the package version. Review whether the affected boundary was present:
- Did a browser-accessible local service accept connections without validating the requesting origin?
- Was an MCP HTTP endpoint reachable from untrusted networks or browser-driven DNS rebinding?
- Was DBHub's
execute_sqltool configured withreadonly = true, and did its database role still have privileges that could turn aSELECTinto a write, file access, or command execution? - Could model- or web-controlled text be serialized into privileged chat roles?
- Did developers open untrusted repositories as trusted workspaces?
- Could untrusted input select a local image path?
- Was a development inspection server bound beyond a trusted interface?
- Could a static-file route or MCP filesystem tool resolve paths outside its intended root?
- Could a lower-privileged user edit an agent or workflow that later executes with another user's authority?
- Was untrusted JavaScript isolated only by an in-process sandbox with host modules or constructors exposed?
- Did a documented localhost-only bridge actually listen on every network interface, and in single-user mode accept unauthenticated connections?
Global tools, editor extensions, and developer workstation installations may not appear in an application's lockfile. Inventory them separately.
Was VibeScan affected?
We found no references to the affected products or packages in VibeScan’s application source, package manifests, or lockfiles. That means there is no identified direct dependency exposure in the VibeScan application.
This check did not inventory every developer workstation, globally installed package, editor extension, or privately configured MCP server. Those environments remain a separate verification task. This repository review also cannot prove whether any separate deployment or workstation used the affected features, and it is not proof that exploitation never occurred.
How to check safely
Search application manifests and lockfiles first, without running proof-of-concept payloads:
npm ls @bytebase/dbhub @aws/lsp-codewhisperer @rsdoctor/rspack-plugin knowns vm2 @penpot/mcp
python -m pip show decepticon decepticon-core decepticon-sdk langchain-nvidia-ai-endpoints scbe-aethermoore khoj
Also check the version screens or package inventories for Cline and AWS language-server editor extensions. Review MCP client configuration for DBHub instances, determine whether HTTP transport was enabled or reachable, and check whether execute_sql relied on readonly = true with database credentials that were more privileged than intended. For development servers, verify the bind address and authentication controls.
Preserve relevant logs before changing an environment if there are signs of unexpected configuration edits, commands, file writes, or source retrieval. Do not test a production system with public exploit code.
Immediate response
- Upgrade Cline to 3.0.30 or later.
- Upgrade DBHub to 0.22.6 or later, restrict its listener to trusted interfaces, and require authentication where the deployment supports it.
- Confirm a fixed Decepticon release with the vendor before resuming affected crawl-to-agent workflows. Pause those workflows when the role-boundary fix cannot be verified.
- Upgrade AWS Language Servers to 1.69.0 or later and
@aws/lsp-codewhispererto 0.0.117 or later. Treat unfamiliar workspaces as untrusted. - Upgrade
langchain-nvidia-ai-endpointsto 1.4.2 or later and constrain any application-controlled file or image references. - Upgrade
@rsdoctor/rspack-pluginto 1.5.16 or later and keep inspection services private. - Upgrade
scbe-aethermooreto the upstream advisory target of 4.3.0 or later and keep operations endpoints authenticated and restricted to trusted interfaces. - Upgrade Khoj to 2.0.0-beta.25 or later and review access logs if an affected server was reachable.
- Upgrade Knowns to 0.30.0 or later; revoke affected MCP filesystem access until the upgrade is complete and review unexpected file changes.
- Upgrade Kibana to 9.4.7 or 9.5.0 or later. If an immediate upgrade is impossible, restrict or disable shared-agent editing, disable Workflows where possible, and review changes to shared agents and attached workflows.
- Upgrade vm2 to 3.12.2 or later. Use process, container, or virtual-machine isolation when hostile code must run; do not treat an in-process JavaScript sandbox as the only host boundary.
- Upgrade Penpot to 2.18.0 or later and verify that a separately packaged
@penpot/mcpincludes the bridge bind-address fix before using it. Verify each MCP listener binds only to a trusted interface. - Review developer workstations and MCP configuration in addition to application dependencies.
If investigation finds credible evidence of code execution or credential access, isolate the affected environment, preserve non-sensitive evidence, and rotate only the credentials that could have been exposed.
What VibeScan detects today
VibeScan can compare resolved dependencies in a supplied lockfile or SBOM with published vulnerability data. When the advisory source is represented in that data, this can flag an affected package version. It does not establish that a local service was reachable or that an exploit condition occurred.
VibeScan's URL-only scan does not inventory editor extensions, globally installed developer tools, private MCP servers, workstation configuration, model tokenization behavior, or local file permissions. Use a workstation and tool inventory for those checks. We have not tested or claimed a dedicated VibeScan detection for the attack paths described here.
Primary sources
- Cline advisory, GHSA-3cj3-hqcr-g934
- DBHub DNS-rebinding advisory, GHSA-fm8p-53ww-hf6w
- DBHub read-only bypass advisory, GHSA-mwwr-p57h-56pf
- Decepticon advisory, GHSA-g5f9-3xfg-p9mf
- AWS security bulletin AWS-2026-047
- LangChain NVIDIA advisory, GHSA-g28h-2cmm-rj9x
- Rsdoctor advisory, GHSA-jmg2-rcxh-w8q3
- SCBE-AETHERMOORE advisory, GHSA-q986-4x7x-gx39
- Khoj advisory, GHSA-62mm-xwmv-crhg
- Knowns advisory, GHSA-9gfj-28hw-jchp
- Elastic Kibana Agent Builder advisory, ESA-2026-85
- vm2 external-module boundary advisory, GHSA-5h3f-q97h-ccvc
- vm2 rejected-Promise advisory, GHSA-2v2p-6j97-cjg9
- vm2 pooled-memory advisory, GHSA-489w-w794-jq94
- Penpot MCP WebSocket bridge advisory, GHSA-ch2q-6x56-qg5r
- CISA Known Exploited Vulnerabilities catalog
Last reviewed: October 5, 2026.