CVE-2026-108699 - hyper-mcp through 0.8.3 Improper Signature Verification of OCI WebAssembly Plugins
CVE ID :CVE-2026-108699 Published : Oct. 11, 2026, 2:17 p.m. | 1 hour, 13 minutes ago Description :hyper-mcp through 0.8.3 contains an improper signature verification vulnerability that allows attackers to load malicious WebAssembly plugins because cosign_verify_args() accepts any signer...