MCP Server Vulnerability in Oraios AI Serena Affects Security
CVE-2026-38924

2.9LOW

Key Information:

Vendor

OraiOS Ai

Status
Vendor
CVE Published:
14 September 2026

What is CVE-2026-38924?

In versions prior to 1.0.0 of Oraios AI Serena, the MCP server's listen address is configured to 0.0.0.0, exposing it to potential unauthorized access. Although it was acknowledged as a 'potential security hazard', the documentation recommended a sandboxed environment instead of guiding users to adopt a safer listen address like 127.0.0.1. This configuration can lead to critical vulnerabilities, underscoring the need for developers and users to carefully assess server settings to mitigate security risks.

Affected Version(s)

Serena 0 < 1.0.0

References

CVSS V3.1

Score:
2.9
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.