56,966 blogs · [ { "id": "01a087b5-7fa1-7017-9254-f0e605cad699", "title": "Your Session, My Policy: An MCP Gateway Authorization Bypass in Agentgateway, and the Move to Stateless MCP", "url": "https://oddguan.com/blog/mcp-2026-07-28-agentgateway-session-authorization-bypass/", "published_at": "2026-07-28T00:00:00+00:00" }, { "id": "01a087b5-7fa2-7226-bdb5-e6ab56f2bb84", "title": "Second Time, Same Sandbox: Another Anthropic Claude Code Network Sandbox Bypass Enables Data Exfiltration", "url": "https://oddguan.com/blog/second-time-same-sandbox-anthropic-claude-code-network-allowlist-bypass-data-exfiltration/", "published_at": "2026-05-20T00:00:00+00:00" }, { "id": "01a087b5-7fa2-7226-bdb5-e6ab571d8662", "title": "Comment and Control: Prompt Injection to Credential Theft in Claude Code, Gemini CLI, and GitHub Copilot Agent", "url": "https://oddguan.com/blog/comment-and-control-prompt-injection-credential-theft-claude-code-gemini-cli-github-copilot/", "published_at": "2026-04-15T00:00:00+00:00" }, { "id": "01a087b5-7fa2-7226-bdb5-e6ab579cc4c6", "title": "Never Wait for Approval — Prompt Injection in Strix AI Pentesting Agent Steals Cloud Credentials", "url": "https://oddguan.com/blog/strix-ai-agent-security-scanner-prompt-injection-credential-theft/", "published_at": "2026-04-03T00:00:00+00:00" }, { "id": "01a087b5-7fa2-7226-bdb5-e6ab582319c0", "title": "Agent SkillSlip: Path Traversal in Google Gemini CLI, Anthropic Claude Code, and Vercel add-skill", "url": "https://oddguan.com/blog/agent-skillslip-google-gemini-cli-anthropic-claude-code-vercel-add-skill-path-traversal/", "published_at": "2026-03-08T00:00:00+00:00" }, { "id": "01a087b5-7fa2-7226-bdb5-e6ab591466aa", "title": "Capability Laundering in MCP 3: CVE-2026-27735 Anthropic Git MCP Server git_add Path Traversal to Credential Exfiltration", "url": "https://oddguan.com/blog/anthropic-mcp-server-git-add-path-traversal-credential-exfiltration-capability-laundering-cve-2026-27735/", "published_at": "2026-02-28T00:00:00+00:00" }, { "id": "01a087b5-7fa2-7226-bdb5-e6ab59424f9c", "title": "MCP Bundle Security: Zip Slip and Silent Overwrite Risks for MCPB Developers", "url": "https://oddguan.com/blog/mcp-bundle-security-zip-slip-overwrite-for-mcp-client/", "published_at": "2026-01-17T00:00:00+00:00" }, { "id": "01a087b5-7fa2-7226-bdb5-e6ab597a925f", "title": "Capability Laundering in MCP 2: CVE-2025-68143 Anthropic Git MCP Server Path Traversal to Credential Exfiltration", "url": "https://oddguan.com/blog/anthropic-mcp-server-git-credential-exfiltration-capability-laundering-cve-2025-68143/", "published_at": "2025-12-28T00:00:00+00:00" }, { "id": "01a087b5-7fa2-7226-bdb5-e6ab59873866", "title": "Capability Laundering in MCP: Anthropic Memory Server to Terminal Hijacking", "url": "https://oddguan.com/blog/anthropic-memory-mcp-server-terminal-hijacking-capability-laundering/", "published_at": "2025-12-27T00:00:00+00:00" }, { "id": "01a087b5-7fa2-7226-bdb5-e6ab5a1f1615", "title": "CVE-2025-66479: Anthropic's Silent Fix and the CVE That Claude Code Never Got", "url": "https://oddguan.com/blog/anthropic-sandbox-cve-2025-66479/", "published_at": "2025-12-03T00:00:00+00:00" }, { "id": "01a087b5-7fa2-7226-bdb5-e6ab5a56fb76", "title": "Click, Parse, Execute - When a GUI Agent's Control Plane Becomes a Remote Control Surface", "url": "https://oddguan.com/blog/microsoft-omniparser-gui-agent-computer-use-rce-cve-2025-55322/", "published_at": "2025-09-25T00:00:00+00:00" }, { "id": "01a087b5-7fa2-7226-bdb5-e6ab5a874589", "title": "Three Dots to Root: How I Found a Path Traversal in Microsoft's Agentic Web (NLWeb)", "url": "https://oddguan.com/blog/nlweb-path-traversal/", "published_at": "2025-08-06T00:00:00+00:00" } ] posts Claim your blog
Back to oddguan.com
Blog · corpus.blog/blogs/oddguan.com/posts

oddguan.com

oddguan.com

2026

2025