Vulnerability intelligence
CVE-2026-47101
Auth bypass → admin privilege escalation → Python sandbox escape via unfiltered exec() → MCP callback injection. The open-source AI gateway used to route requests between Claude, GPT, and Gemini had a kill chain from viewer to root. Patched in v1.83.14.
2026
What WebPulse reported · 1 analysis
Related vulnerabilities