๐Ÿ” CVE Alert

CVE-2026-38924

LOW 2.9
CVSS Score
2.9
EPSS Score
0.0%
EPSS Percentile
0th

In Oraios AI Serena before 1.0.0, the listen address of the MCP server in HTTP mode is 0.0.0.0. NOTE: the Supplier observed that 0.0.0.0 was a "potential security hazard" but the Serena documentation, at the time of the issue report proposing 127.0.0.1 instead of 0.0.0.0, recommended "use a sandboxed environment for running Serena."

CWE CWE-669
Vendor oraios ai
Product serena
Published Sep 14, 2026
Last Updated Sep 14, 2026
Stay Ahead of the Next One

Get instant alerts for oraios ai serena

Be the first to know when new low vulnerabilities affecting oraios ai serena are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Attack Vector
Local
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None

Affected Versions

Oraios AI / Serena
0 < 1.0.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/oraios/serena/commit/b00ae292ac2d49947506886f44eb1cad7b7d7cd1 github.com: https://github.com/oraios/serena/security/advisories/GHSA-m922-r24v-6wff dash.security: https://dash.security/blog/cve-2026-38924-unauthenticated-rce-in-the-serena-mcp-server github.com: https://github.com/oraios/serena/compare/v0.1.4...v1.0.0 github.com: https://github.com/oraios/serena/commit/a7af5c1f8a9ea27102eac9e72f64dd97dbfefff3