CVE-2026-29872: A cross-session information disclosure vulnerability exists in the awesome-llm-apps project in commit e46690f99c3f08be80a9877fab52acacf7ab8251 (2026-01-19). The affected Streamlit-based GitHub MCP ...

Added to the CISA Known Exploited Vulnerabilities catalog on 30 Mar 2026. Vendor: AI/ML. Product: LLM. CVSS score: 8.2.

A cross-session information disclosure vulnerability exists in the awesome-llm-apps project in commit e46690f99c3f08be80a9877fab52acacf7ab8251 (2026-01-19). The affected Streamlit-based GitHub MCP Agent stores user-supplied API tokens in process-wide environment variables using os.environ without...

Required action: Review and patch if applicable to your AI infrastructure.