DeepInspect.AI reported that the settings tool in a separate CVE returns the HA cluster token in a cleartext response, converting MCP access into full server compromise.
Public source
Publisher name
Public post
Adversa's September 2026 MCP roundup lists three server CVEs where an authenticated caller pulled a cleartext cluster token or arbitrary file contents through tools far…
Company
DeepInspect.AI
Zero-trust gateway enforcing identity-aware, auditable controls on enterprise AI interactions.
- Industry
- Computer and Network Security
- Location
- New York, US
- Company size
- 2–10 employees
About DeepInspect.AI
DeepInspect is a zero-trust policy gateway that governs how enterprises use AI, not just where their data lives. We help security and platform teams apply identity-aware, auditable controls to AI interactions across models, tools, and workflows.
See moreLatest activity
Latest activity from DeepInspect.AI
3 signals
Products & Services
DeepInspect.AI reported that the confluence_upload_attachment tool in the MCP server has been fixed in version 0.22.0 to pass a client-supplied path straight to open(file_path, 'rb'), allowing authenticated callers to read arbitrary files.
Research & Knowledge
DeepInspect.AI published Zscaler's 2026 AI Threat Report, which recorded a 91% year-over-year surge in enterprise AI activity.
Discover more
Similar signals
Similar public activity from other companies.
Products & Services
Sweet Security
Sweet Security discovers MCP servers, AI agents, and shadow AI usage directly from live traffic using cloud context and runtime enforcement.
Products & Services
Hacktron AI
Hacktron AI tools prevent pre-authentication Remote Code Execution (RCE) issues before they reach production
Products & Services
RAPIDFORT
RAPIDFORT addresses the issue of idle code contributing to attack surface and CVE scans by providing validated vulnerability analysis, runtime-aware hardening, and near-zero CVE Curated Images.
Products & Services
Holm Security
Holm Security confirmed that every Langflow release up to 1.4.2 is vulnerable.
Products & Services
Transilience AI