PatchSiren

Uptash CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Uptash CVE published 2026-08-18

CVE-2026-75130

CVE-2026-75130 is a prompt injection vulnerability in Context7 through version 2.1.2 that allows attackers to execute malicious instructions in connected AI coding agents. The vulnerability is triggered through the Custom AI Instructions feature served via the MCP server, enabling attackers to exfiltrate credentials from environment files and perform destructive file deletion.