Impact
A server component of Oraios AI Serena exposed by default through a configuration that causes the MCP server in HTTP mode to listen on all network interfaces, 0.0.0.0. This setting widens the potential attack surface, allowing any node on a network that can reach the host to connect to the MCP server without encountering a local‑interface restriction. The vulnerability does not describe an additional privilege or code‑execution flaw; it simply increases the reachability of the underlying HTTP interface.
Affected Systems
Oraios AI Serena versions prior to 1.0.0 employ the default 0.0.0.0 listen address for the MCP server, making the service accessible from every network interface on the host.
Risk and Exploitability
The base CVSS score of 2.9 flags the issue as low severity. The EPSS score of less than 1% signals a very low likelihood of exploitation, and the vulnerability is not included in the CISA KEV catalog. The additional exposure may allow an attacker to discover service functionality or attempt non‑authenticated interactions, but no evidence of privileged actions or direct code execution is present in the publicly available information.
OpenCVE Enrichment