Critical MCP Server Vulnerability Exposes 3,000+ Servers and Sensitive API Keys
A critical path traversal vulnerability in Smithery.ai has exposed over 3,000 hosted AI servers and compromised thousands of API keys. The flaw, stemming from a configuration bug, allows attackers to access sensitive files and execute arbitrary code on the servers.