Millions of AI agents imperiled by critical vulnerability in open source package
"BadHost" was found in Starlette, a package with 325 million weekly downloads.
Signal weather
Rising
Momentum is building quickly, so this card is a good early entry point into the topic.
Millions of AI agents and tools around the world have been imperiled by a critical vulnerability that can allow hackers to breach the servers running them and make off with sensitive data and credentials to third-party accounts, a security researcher is warning. The vulnerability is present in Starlette, an open source framework that its developer says receives 325 million downloads per week. Thousands of other open source projects are also vulnerable because they require Starlette to work. The framework is an implementation of the ASGI (asynchronous server gateway interface), which allows large numbers of requests to be efficiently processed simultaneously. Starlette is the base of FastAPI and other widely used frameworks for building services in Python apps, as well as many others. Trivial to exploit, millions of servers exposed ASGI, and by extension Starlette, have access to servers running the MCP (model context protocol), which allows AI agents from major providers to access external sources, including user data bases, email and calendar accounts, and all manner of other resources. To connect with these external systems, MCP servers store credentials for each one, making them especially valuable storehouses for attackers to breach. Read full article Comments
Stay on the signal
Follow Millions of AI agents imperiled by critical vulnerability in open source package
Follow this story beyond a single article: new follow-ups, adjacent sources, and the evolving storyline.
Story map
Understand this topic fast
A quick entry into the story: why it matters now, who is involved, and where to go next for context.
Why it matters now
Topic constellation
Open the live map for this story
See which entities, story threads, sources, and follow-up articles shape this story right now.
Click nodes to continue
Entity pages
Story threads
Story timeline
Continue with this story
A short sequence of events and follow-up stories to understand the arc quickly.
How reliable this looks
Signal and trust for Ars Technica
This source works at a rapid pace: 100% of recent stories land in the hot window, and 0% carry visible search signal.
Reliability
92
Freshness
100
Sources in storyline
1
Related articles
More stories that share tags, source, or category context.
Musk says US military suicide drones used Starlink in violation of SpaceX rules
Musk says drones used Starlink instead of Starshield, blames military contractor.
Signal weather
Momentum is building quickly, so this card is a good early entry point into the topic.
Why now
Fresh coverage with immediate momentum.
NASA takes steps toward building Moon Base, including discussing a "perimeter"
"We also obviously want to be very mindful of the Outer Space Treaty."
Signal weather
Momentum is building quickly, so this card is a good early entry point into the topic.
Why now
Fresh coverage with immediate momentum.
We're starting to see some PC makers respond to Apple's MacBook Neo
Sub-$600 laptops have existed for years, but consistently good ones remain rare.
Signal weather
Momentum is building quickly, so this card is a good early entry point into the topic.
Why now
Fresh coverage with immediate momentum.
Want an oxygen-rich atmosphere? Stuff oxygen’s friends in the mantle.
Getting carbon and sulfur into Earth’s interior may be part of oxygen’s story.
Signal weather
Momentum is building quickly, so this card is a good early entry point into the topic.
Why now
Fresh coverage with immediate momentum.
More from Ars Technica
Fresh reporting and follow-up coverage from the same newsroom.
Musk says US military suicide drones used Starlink in violation of SpaceX rules
Musk says drones used Starlink instead of Starshield, blames military contractor.
Signal weather
Momentum is building quickly, so this card is a good early entry point into the topic.
Why now
Fresh coverage with immediate momentum.
NASA takes steps toward building Moon Base, including discussing a "perimeter"
"We also obviously want to be very mindful of the Outer Space Treaty."
Signal weather
Momentum is building quickly, so this card is a good early entry point into the topic.
Why now
Fresh coverage with immediate momentum.
We're starting to see some PC makers respond to Apple's MacBook Neo
Sub-$600 laptops have existed for years, but consistently good ones remain rare.
Signal weather
Momentum is building quickly, so this card is a good early entry point into the topic.
Why now
Fresh coverage with immediate momentum.
Want an oxygen-rich atmosphere? Stuff oxygen’s friends in the mantle.
Getting carbon and sulfur into Earth’s interior may be part of oxygen’s story.
Signal weather
Momentum is building quickly, so this card is a good early entry point into the topic.
Why now
Fresh coverage with immediate momentum.