PatchSiren

ScriptKittyOS CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW ScriptKittyOS CVE published 2026-10-08

CVE-2026-104634

A vulnerability in beam_mcp allows MCP clients to send JSON boolean and null tool arguments that are incorrectly converted to strings, potentially affecting host behavior. This issue impacts hosts whose behavior differs between true and false, and any policy layer permitting false but refusing true. The vulnerability arises from the incorrect normalization of JSON boolean and null tool arguments in the be [truncated]