<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://mcp-news.com/news/apify-actors-mcp-token-leak-cve-reaches-nvd</loc>
    <news:news>
      <news:publication>
        <news:name>MCP News</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-18</news:publication_date>
      <news:title>CVE record published for an Apify MCP server flaw that could redirect a client&apos;s bearer token to a third-party host</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://mcp-news.com/news/context7-custom-instructions-prompt-injection-cve</loc>
    <news:news>
      <news:publication>
        <news:name>MCP News</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-18</news:publication_date>
      <news:title>CVE record published for the Context7 custom-rules prompt injection Upstash fixed in February</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://mcp-news.com/news/chrome-devtools-mcp-roots-symlink-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>MCP News</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-17</news:publication_date>
      <news:title>Advisory published for a roots boundary bypass in Google&apos;s Chrome DevTools MCP server, fixed three months earlier</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://mcp-news.com/news/onyx-cross-user-oauth-token-leak-mcp-endpoints</loc>
    <news:news>
      <news:publication>
        <news:name>MCP News</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-17</news:publication_date>
      <news:title>CVE record published for a critical cross-user OAuth token leak in Onyx&apos;s MCP server endpoints</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://mcp-news.com/news/pycharm-unauthenticated-jupyter-mcp-tools</loc>
    <news:news>
      <news:publication>
        <news:name>MCP News</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-17</news:publication_date>
      <news:title>JetBrains discloses code execution via unauthenticated Jupyter MCP tools in PyCharm before 2026.2.1</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://mcp-news.com/news/siyuan-mcp-database-clean-path-traversal</loc>
    <news:news>
      <news:publication>
        <news:name>MCP News</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-17</news:publication_date>
      <news:title>CVE record published for path traversal in SiYuan&apos;s database_clean MCP tool, a hardening gap the HTTP API had already closed</news:title>
    </news:news>
  </url>
</urlset>