GitLab reports a critical template-injection flaw in the open-source Serena MCP coding agent that let a malicious repository execute code when opened, bypassing Serena’s trust gate until maintainers shipped version 1.7.0.
Critical remote code execution in Serena, a popular MCP coding agent
GitLab reports a critical template-injection flaw in the open-source Serena MCP coding agent that let a malicious repository execute code when opened, bypassing Serena's trust gate until maintainers shipped version 1.7.0.
Source: Gitlab