Independent security research
Security research on AI, agents, and MCP servers
I find and responsibly disclose vulnerabilities in Model Context Protocol (MCP) implementations and AI-assisted developer tools, then work with maintainers and site operators to get them fixed.
For website operators
Received a security notice from me?
Verify it is genuine and find the guidance page for the component named in the email. I am not asking for money, passwords, or access to your site.
Check your notice →Already updated? One more step.
Updating closes the hole from now on. It cannot tell you whether anyone found it first. A practical 30-minute self-check, no security background needed.
I updated. Now what? →Found something in the self-check you are not sure about? Reply to the notice email. I read every reply.
Recent advisories
-
Data Exfiltration and Destruction in MLflow via Missing Origin Validation (DNS Rebinding)
-
Remote Code Execution via GenAI Scorer Deserialization in MLflow
-
Unauthorized MQ Broker Control via SSE Mode in AWS Labs' Amazon MQ Broker MCP Server
-
Kluster's Verify MCP Server Exposes Users to Credit Exhaustion
-
Neo4j MCP Cypher Server Vulnerable to Database Takeover Via DNS Rebinding
-
Vet MCP Server SSE Transport DNS Rebinding Vulnerability