Post
Tayler Ramsay
webdevdad.bsky.social
did:plc:qub26ealr75cpqpkjhkpjwek
I've been watching seven MCP CVEs drop in the past month, all the same root cause: user input reaching exec() without sanitization. code that looked right, passed review, shipped. I found CVE-2026-27825 particularly bad: 4M+ downloads, CVSS 9.1.
2026-03-14T22:00:40.154Z