
sentrymcp
A static + runtime security scanner for MCP (Model Context Protocol) servers

A static + runtime security scanner for MCP (Model Context Protocol) servers
CVE-2026-67598 — Emlog Pro: disabled TLS certificate validation in AI assistant (MITM → API-key theft). CWE-295, CVSS 9.1. Reported by @IlhomjonR.

Application Security Verification Standard

CVE-2026-60137Temporary Emergency Mitigation for CVE-2026-60137 & CVE-2026-63030 (wp2shell)


批量检测Spring Cloud Gateway 远程代码执行漏洞 Spring_Cloud_Gateway_RCE_POC-CVE-2022-22947

CVE-2022-22947

CVE-2025-55182 and CVE-2025-66478




Takes third-party HTML and produces HTML that is safe to embed in your web application. Fast and easy to configure.

OWASP Secure Agent Playbook Project

DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of…

Defense-in-depth bundle for MCP stdio servers: drop-in guardExec/guardSpawn wrappers, AST audit CLI, reference MCP server. Closes the Ox-Security…

bluemonday: a fast golang HTML sanitizer (inspired by the OWASP Java HTML Sanitizer) to scrub user generated content of XSS

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.
