CVE-2026-108699 hyper-mcp through 0.8.3 Improper Signature Verification of OCI WebAssembly Plugins. The hyper-mcp package through version 0.8.3 contains an improper signature verification vulnerability. This allows attackers to load malicious WebAssembly plugins by default accepting any signer identity and OIDC issuer. Attackers controlling a plugin image reference can sign a malicious image with a free S [truncated]
A signature verification bypass vulnerability exists in hyper-mcp through 0.8.3. The load_wasm function in src/wasm/oci.rs verifies the Cosign signature of a separately resolved tag rather than the loaded manifest. This allows attackers controlling registry responses for the tag to serve an unsigned malicious manifest to the loader and a signed one to Cosign, potentially executing unsigned WebAssembly plu [truncated]