Blog · corpus.blog/blogs/oddguan.com/posts
oddguan.com
oddguan.com
2026
Your Session, My Policy: An MCP Gateway Authorization Bypass in Agentgateway, and the Move to Stateless MCPoriginal ↗
28 Jul 2026
Second Time, Same Sandbox: Another Anthropic Claude Code Network Sandbox Bypass Enables Data Exfiltrationoriginal ↗
20 May 2026
Comment and Control: Prompt Injection to Credential Theft in Claude Code, Gemini CLI, and GitHub Copilot Agentoriginal ↗
15 Apr 2026
Never Wait for Approval — Prompt Injection in Strix AI Pentesting Agent Steals Cloud Credentialsoriginal ↗
3 Apr 2026
Agent SkillSlip: Path Traversal in Google Gemini CLI, Anthropic Claude Code, and Vercel add-skilloriginal ↗
8 Mar 2026
Capability Laundering in MCP 3: CVE-2026-27735 Anthropic Git MCP Server git_add Path Traversal to Credential Exfiltrationoriginal ↗
28 Feb 2026
2025
Capability Laundering in MCP 2: CVE-2025-68143 Anthropic Git MCP Server Path Traversal to Credential Exfiltrationoriginal ↗
28 Dec 2025
25 Sept 2025