{"id":"CVE-2026-38924","title":"In Oraios AI Serena before 1.0.0, the listen address of the MCP server in HTTP mode is 0.0.0.0","summary":"In Oraios AI Serena before 1.0.0, the listen address of the MCP server in HTTP mode is 0.0.0.0. NOTE: the Supplier observed that 0.0.0.0 was a \"potential security hazard\" but the Serena documentation, at the time of the issue report prop…","severity":"low","cvss":2.9,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","cwe":["CWE-669"],"vendor":"Oraios AI","product":"Serena","affected":["Serena < 1.0.0"],"published":"2026-09-14","updated":"2026-09-22","sourceUpdated":"2026-09-22T20:00:03.713","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-38924","references":[{"url":"https://dash.security/blog/cve-2026-38924-unauthenticated-rce-in-the-serena-mcp-server","label":"cve@mitre.org"},{"url":"https://github.com/oraios/serena/commit/a7af5c1f8a9ea27102eac9e72f64dd97dbfefff3","label":"cve@mitre.org"},{"url":"https://github.com/oraios/serena/commit/b00ae292ac2d49947506886f44eb1cad7b7d7cd1","label":"cve@mitre.org"},{"url":"https://github.com/oraios/serena/compare/v0.1.4...v1.0.0","label":"cve@mitre.org"},{"url":"https://github.com/oraios/serena/security/advisories/GHSA-m922-r24v-6wff","label":"cve@mitre.org"},{"url":"https://dash.security/blog/cve-2026-38924-unauthenticated-rce-in-the-serena-mcp-server","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","cve.org","exploit-available"],"epss":0.00157,"epssPercentile":0.04109,"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-14T16:32:11.855699Z"},"ingestedAt":"2026-09-14T15:23:07.467Z","slug":"CVE-2026-38924","body":"## Overview\n\nIn Oraios AI Serena before 1.0.0, the listen address of the MCP server in HTTP mode is 0.0.0.0. NOTE: the Supplier observed that 0.0.0.0 was a \"potential security hazard\" but the Serena documentation, at the time of the issue report proposing 127.0.0.1 instead of 0.0.0.0, recommended \"use a sandboxed environment for running Serena.\"\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":28,"depthScoreParts":{"impact":16,"likelihood":0,"exploitation":12,"ransomware":0},"changes":[{"seq":203077,"id":"CVE-2026-38924","ts":1789409572304,"field":"exploit_available","old":"false","new":"true"}]}