Critical remote code execution in Serena, a popular MCP coding agent
Blog post from GitLab
GitLab’s Threat Research Group disclosed a critical server-side template injection vulnerability in Serena AI coding agent versions 1.6.1 and earlier that could execute attacker-controlled code when a developer opens a malicious repository. The flaw uses an untrusted repository’s `.serena/project.yml` file to load a custom mode whose prompt is rendered through an unsandboxed Jinja2 environment, enabling arbitrary code execution despite Serena’s trusted-project protections. Because Serena MCP servers run locally with the developer’s user permissions, a successful exploit could expose credentials, environment files, browser sessions, and internal network resources. The issue was privately reported on August 1, 2026, accepted by maintainers on August 5, and fixed in version 1.7.0 on August 9 by switching to Jinja2’s sandboxed environment. The report argues that MCP servers create a significant new local attack surface because they process potentially hostile repositories with broad system access, and recommends treating project configuration as untrusted input, applying trust controls consistently across all execution paths, and testing tools against malicious project files.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| MCP | 21 | 8,729 | 854 | 211 | -20% |
| LLM | 7 | 5,068 | 1,020 | 229 | -34% |
| AI Coding Assistant | 4 | 1,513 | 470 | 139 | -19% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.