serena-agent
A powerful MCP toolkit for coding, providing semantic retrieval and editing capabilities - the IDE for your agent
Activity
- Latest release
- 1mo ago
- Total releases
- 15
- Cadence
- ~7 days
- Last 12 months
- 13
Reach
- Stars
- 28.1k
Details
- License
- MIT
- First release
- Jul 21, 2025
| Version | Released | |
|---|---|---|
1.7.0
minor
| ||
1.6.1
patch
| ||
1.6.0
minor
| ||
1.5.3
patch
| ||
1.5.2
patch
| ||
1.5.1
patch
1 CVE
CVE-2026-49471
PYSEC-2026-3061
GHSA-37h2-6p4f-mp3q
Jul 13, 2026
Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCE
8.3
/ 10
High
Network
High
None
Required
Changed
High
High
High
SummarySerena's built-in web dashboard exposes an unauthenticated Flask API on a fixed, predictable port (TCP 24282, hardcoded as DetailsRoot cause 1 — Unauthenticated dashboard ( The Flask server starts automatically (
Flask does not validate the Root cause 2 —
This tool is enabled in every default context YAML: PoCStep 1 — Verify missing auth (no DNS rebinding needed):
Step 2 — Full chain (DNS rebinding → persistent memory poisoning → RCE):
Confirmed with standalone Python PoC (attached): all four endpoints ( ImpactAny user running Serena with the default configuration is affected. The dashboard is enabled by default ( An attacker who tricks the victim into visiting a malicious webpage can, with no credentials and no other preconditions:
A standalone Python PoC ( Affected versions
0.1.3
0.1.4
1.0.0
1.1.0
1.1.1
1.1.2
1.2.0
1.3.0
1.5.0
1.5.1
Fixed in
1.5.2
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.5.0
minor
1 CVE
CVE-2026-49471
PYSEC-2026-3061
GHSA-37h2-6p4f-mp3q
Jul 13, 2026
Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCE
8.3
/ 10
High
Network
High
None
Required
Changed
High
High
High
SummarySerena's built-in web dashboard exposes an unauthenticated Flask API on a fixed, predictable port (TCP 24282, hardcoded as DetailsRoot cause 1 — Unauthenticated dashboard ( The Flask server starts automatically (
Flask does not validate the Root cause 2 —
This tool is enabled in every default context YAML: PoCStep 1 — Verify missing auth (no DNS rebinding needed):
Step 2 — Full chain (DNS rebinding → persistent memory poisoning → RCE):
Confirmed with standalone Python PoC (attached): all four endpoints ( ImpactAny user running Serena with the default configuration is affected. The dashboard is enabled by default ( An attacker who tricks the victim into visiting a malicious webpage can, with no credentials and no other preconditions:
A standalone Python PoC ( Affected versions
0.1.3
0.1.4
1.0.0
1.1.0
1.1.1
1.1.2
1.2.0
1.3.0
1.5.0
1.5.1
Fixed in
1.5.2
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.3.0
minor
1 CVE
CVE-2026-49471
PYSEC-2026-3061
GHSA-37h2-6p4f-mp3q
Jul 13, 2026
Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCE
8.3
/ 10
High
Network
High
None
Required
Changed
High
High
High
SummarySerena's built-in web dashboard exposes an unauthenticated Flask API on a fixed, predictable port (TCP 24282, hardcoded as DetailsRoot cause 1 — Unauthenticated dashboard ( The Flask server starts automatically (
Flask does not validate the Root cause 2 —
This tool is enabled in every default context YAML: PoCStep 1 — Verify missing auth (no DNS rebinding needed):
Step 2 — Full chain (DNS rebinding → persistent memory poisoning → RCE):
Confirmed with standalone Python PoC (attached): all four endpoints ( ImpactAny user running Serena with the default configuration is affected. The dashboard is enabled by default ( An attacker who tricks the victim into visiting a malicious webpage can, with no credentials and no other preconditions:
A standalone Python PoC ( Affected versions
0.1.3
0.1.4
1.0.0
1.1.0
1.1.1
1.1.2
1.2.0
1.3.0
1.5.0
1.5.1
Fixed in
1.5.2
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.2.0
minor
1 CVE
CVE-2026-49471
PYSEC-2026-3061
GHSA-37h2-6p4f-mp3q
Jul 13, 2026
Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCE
8.3
/ 10
High
Network
High
None
Required
Changed
High
High
High
SummarySerena's built-in web dashboard exposes an unauthenticated Flask API on a fixed, predictable port (TCP 24282, hardcoded as DetailsRoot cause 1 — Unauthenticated dashboard ( The Flask server starts automatically (
Flask does not validate the Root cause 2 —
This tool is enabled in every default context YAML: PoCStep 1 — Verify missing auth (no DNS rebinding needed):
Step 2 — Full chain (DNS rebinding → persistent memory poisoning → RCE):
Confirmed with standalone Python PoC (attached): all four endpoints ( ImpactAny user running Serena with the default configuration is affected. The dashboard is enabled by default ( An attacker who tricks the victim into visiting a malicious webpage can, with no credentials and no other preconditions:
A standalone Python PoC ( Affected versions
0.1.3
0.1.4
1.0.0
1.1.0
1.1.1
1.1.2
1.2.0
1.3.0
1.5.0
1.5.1
Fixed in
1.5.2
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.1.2
patch
1 CVE
CVE-2026-49471
PYSEC-2026-3061
GHSA-37h2-6p4f-mp3q
Jul 13, 2026
Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCE
8.3
/ 10
High
Network
High
None
Required
Changed
High
High
High
SummarySerena's built-in web dashboard exposes an unauthenticated Flask API on a fixed, predictable port (TCP 24282, hardcoded as DetailsRoot cause 1 — Unauthenticated dashboard ( The Flask server starts automatically (
Flask does not validate the Root cause 2 —
This tool is enabled in every default context YAML: PoCStep 1 — Verify missing auth (no DNS rebinding needed):
Step 2 — Full chain (DNS rebinding → persistent memory poisoning → RCE):
Confirmed with standalone Python PoC (attached): all four endpoints ( ImpactAny user running Serena with the default configuration is affected. The dashboard is enabled by default ( An attacker who tricks the victim into visiting a malicious webpage can, with no credentials and no other preconditions:
A standalone Python PoC ( Affected versions
0.1.3
0.1.4
1.0.0
1.1.0
1.1.1
1.1.2
1.2.0
1.3.0
1.5.0
1.5.1
Fixed in
1.5.2
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.1.1
patch
1 CVE
CVE-2026-49471
PYSEC-2026-3061
GHSA-37h2-6p4f-mp3q
Jul 13, 2026
Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCE
8.3
/ 10
High
Network
High
None
Required
Changed
High
High
High
SummarySerena's built-in web dashboard exposes an unauthenticated Flask API on a fixed, predictable port (TCP 24282, hardcoded as DetailsRoot cause 1 — Unauthenticated dashboard ( The Flask server starts automatically (
Flask does not validate the Root cause 2 —
This tool is enabled in every default context YAML: PoCStep 1 — Verify missing auth (no DNS rebinding needed):
Step 2 — Full chain (DNS rebinding → persistent memory poisoning → RCE):
Confirmed with standalone Python PoC (attached): all four endpoints ( ImpactAny user running Serena with the default configuration is affected. The dashboard is enabled by default ( An attacker who tricks the victim into visiting a malicious webpage can, with no credentials and no other preconditions:
A standalone Python PoC ( Affected versions
0.1.3
0.1.4
1.0.0
1.1.0
1.1.1
1.1.2
1.2.0
1.3.0
1.5.0
1.5.1
Fixed in
1.5.2
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.1.0
minor
1 CVE
CVE-2026-49471
PYSEC-2026-3061
GHSA-37h2-6p4f-mp3q
Jul 13, 2026
Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCE
8.3
/ 10
High
Network
High
None
Required
Changed
High
High
High
SummarySerena's built-in web dashboard exposes an unauthenticated Flask API on a fixed, predictable port (TCP 24282, hardcoded as DetailsRoot cause 1 — Unauthenticated dashboard ( The Flask server starts automatically (
Flask does not validate the Root cause 2 —
This tool is enabled in every default context YAML: PoCStep 1 — Verify missing auth (no DNS rebinding needed):
Step 2 — Full chain (DNS rebinding → persistent memory poisoning → RCE):
Confirmed with standalone Python PoC (attached): all four endpoints ( ImpactAny user running Serena with the default configuration is affected. The dashboard is enabled by default ( An attacker who tricks the victim into visiting a malicious webpage can, with no credentials and no other preconditions:
A standalone Python PoC ( Affected versions
0.1.3
0.1.4
1.0.0
1.1.0
1.1.1
1.1.2
1.2.0
1.3.0
1.5.0
1.5.1
Fixed in
1.5.2
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.0.0
major
1 CVE
CVE-2026-49471
PYSEC-2026-3061
GHSA-37h2-6p4f-mp3q
Jul 13, 2026
Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCE
8.3
/ 10
High
Network
High
None
Required
Changed
High
High
High
SummarySerena's built-in web dashboard exposes an unauthenticated Flask API on a fixed, predictable port (TCP 24282, hardcoded as DetailsRoot cause 1 — Unauthenticated dashboard ( The Flask server starts automatically (
Flask does not validate the Root cause 2 —
This tool is enabled in every default context YAML: PoCStep 1 — Verify missing auth (no DNS rebinding needed):
Step 2 — Full chain (DNS rebinding → persistent memory poisoning → RCE):
Confirmed with standalone Python PoC (attached): all four endpoints ( ImpactAny user running Serena with the default configuration is affected. The dashboard is enabled by default ( An attacker who tricks the victim into visiting a malicious webpage can, with no credentials and no other preconditions:
A standalone Python PoC ( Affected versions
0.1.3
0.1.4
1.0.0
1.1.0
1.1.1
1.1.2
1.2.0
1.3.0
1.5.0
1.5.1
Fixed in
1.5.2
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.1.4
patch
1 CVE
CVE-2026-49471
PYSEC-2026-3061
GHSA-37h2-6p4f-mp3q
Jul 13, 2026
Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCE
8.3
/ 10
High
Network
High
None
Required
Changed
High
High
High
SummarySerena's built-in web dashboard exposes an unauthenticated Flask API on a fixed, predictable port (TCP 24282, hardcoded as DetailsRoot cause 1 — Unauthenticated dashboard ( The Flask server starts automatically (
Flask does not validate the Root cause 2 —
This tool is enabled in every default context YAML: PoCStep 1 — Verify missing auth (no DNS rebinding needed):
Step 2 — Full chain (DNS rebinding → persistent memory poisoning → RCE):
Confirmed with standalone Python PoC (attached): all four endpoints ( ImpactAny user running Serena with the default configuration is affected. The dashboard is enabled by default ( An attacker who tricks the victim into visiting a malicious webpage can, with no credentials and no other preconditions:
A standalone Python PoC ( Affected versions
0.1.3
0.1.4
1.0.0
1.1.0
1.1.1
1.1.2
1.2.0
1.3.0
1.5.0
1.5.1
Fixed in
1.5.2
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.1.3
initial
1 CVE
CVE-2026-49471
PYSEC-2026-3061
GHSA-37h2-6p4f-mp3q
Jul 13, 2026
Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCE
8.3
/ 10
High
Network
High
None
Required
Changed
High
High
High
SummarySerena's built-in web dashboard exposes an unauthenticated Flask API on a fixed, predictable port (TCP 24282, hardcoded as DetailsRoot cause 1 — Unauthenticated dashboard ( The Flask server starts automatically (
Flask does not validate the Root cause 2 —
This tool is enabled in every default context YAML: PoCStep 1 — Verify missing auth (no DNS rebinding needed):
Step 2 — Full chain (DNS rebinding → persistent memory poisoning → RCE):
Confirmed with standalone Python PoC (attached): all four endpoints ( ImpactAny user running Serena with the default configuration is affected. The dashboard is enabled by default ( An attacker who tricks the victim into visiting a malicious webpage can, with no credentials and no other preconditions:
A standalone Python PoC ( Affected versions
0.1.3
0.1.4
1.0.0
1.1.0
1.1.1
1.1.2
1.2.0
1.3.0
1.5.0
1.5.1
Fixed in
1.5.2
References
Updated Jul 13, 2026 · Source: OSV.dev |