MCPA-2026-0045
highauth-missing
Serena unauthenticated dashboard DNS rebinding to memory poisoning and RCE (CVE-2026-49471)
Serena's built-in web dashboard exposes an unauthenticated Flask API on a fixed, predictable port (TCP 24282) with no authentication, CSRF protection, or Host header validation. A DNS rebinding attack lets any webpage the operator visits reach the API, write arbitrary content to the agent's persistent memory store (poisoning future agent sessions), and escalate to code execution. Affects the serena-agent PyPI package; fixed in 1.5.2.
Affected packages
| Ecosystem | Package | Affected versions |
|---|---|---|
| pypi | serena-agent | >= 0, < 1.5.2 |
Identifiers
CVE-2026-49471GHSA-37h2-6p4f-mp3qCWE-306CWE-352
References
- advisory https://github.com/advisories/GHSA-37h2-6p4f-mp3q
- advisory https://github.com/oraios/serena/security/advisories/GHSA-37h2-6p4f-mp3q
- web https://nvd.nist.gov/vuln/detail/CVE-2026-49471
Timeline
- Published: 2026-07-08