Click any tag below to further narrow down your results
Links
Researchers at Tenet Security showed how anyone with a public Sentry DSN can inject a fake error report that coding agents like Claude Code, Cursor, and Codex will treat as a fix instruction. The agent fetches the malicious payload via the Model Context Protocol and runs arbitrary commands on the developer’s machine, exposing environment secrets and credentials. Sentry won’t close the write endpoint, leaving the fix to agent runtimes to filter untrusted data.
Ivanti released patches for two critical Sentry vulnerabilities: CVE-2026-10520, an OS command injection that lets attackers execute code as root, and CVE-2026-10523, an authentication bypass for creating rogue admin accounts. No active exploitation has been seen, but administrators should upgrade to Sentry R10.5.2, R10.6.2 or R10.7.1 immediately.