@pikhq@social.treehouse.systems
Post #1187835
2026-04-15 23:00 UTC
having seen what MCP _is_ i'm shocked it took this long
commentary limited because migraine but tldr: MCP is a generic API for machine use of all the things (okay...) oriented around LLMs (um...) that has a fundamental assumption that you're giving the LLM the precise set of perms you do (... excuse me?).
this is not a thing designed by someone who knows about the word "security" and so surprise there's huge CVEs in something using it!
https://www.bleepingcomputer.com/news/security/critical-nginx-ui-auth-bypass-flaw-now-actively-exploited-in-the-wild/
Replies (3)
-
@Mayabotics@tech.lgbt 2026-04-15 23:08
@pikhq Amazing. This sounds like a late 90s/early 2000s RPC/RMI flawed by design vulnerability.
-
@landley@mstdn.jp 2026-04-15 23:14
@pikhq https://mstdn.jp/@landley/116404300992947247
-
@tempest@social.treehouse.systems 2026-04-15 23:15
@pikhq honestly anything that claims to support MCP should be approached with caution — these are the same folks who think *telling* the model to behave is reasonable security, we're not surprised that having controls outside of it becomes an afterthought