Source · DiggingBeagle record

HTTP transports expose unauthenticated PowerShell control with wildcard CORS

Maintainer advisory for the Windows-MCP HTTP transport vulnerability later assigned CVE-2026-48989.

Published
May 14, 2026
Accessed
Sep 14, 2026
Publisher
CursorTouch / GitHub Security Advisory
Source type
primary
Version
2026-05-14
Rights
Public web source; citation and short excerpt only.

Each support, contradiction or context label applies to a cited Claim, not to a whole Case.

Cite this record

DiggingBeagle. “HTTP transports expose unauthenticated PowerShell control with wildcard CORS.” Published May 14, 2026 · Accessed Sep 14, 2026. https://diggingbeagle.com/sources/http-transports-expose-unauthenticated-powershell-control-with-wildcard-cors/

Citation guidance

Why this archive exists

The source matters after the headline fades.

DiggingBeagle is a non profit research project documenting AI security incidents, agent failures, vulnerabilities and AI-assisted operations. A case keeps its claims beside the sources that support, contest or limit them. Later updates stay visible, so a reader can see when the account changed.

We publish case reconstructions, dated reporting and analysis across records. Each has a different evidentiary role. About the project and our methodology explain how the work is reviewed.