← 返回事件
降温中科技

Critical remote code execution in Serena, a popular MCP coding agent

发生了什么

Serena, one of the most widely used AI coding agents, ran attacker-supplied code the moment a developer opened a project. GitLab's Threat Research Group found a critical server-side template injection ( GHSA-pp25-4cg4-qcr9 , CVE pending) that executes arbitrary code in the Serena process. Anyone on serena-agent 1.6.1 or earlier should update to 1.7.0 now. A threat actor can exploit this by hiding a malicious .serena…

摘要按规则整理自下方来源原文

为什么在扩散

来源