GitLab Finds Critical Template-Injection Flaw in Serena, an MCP Coding Agent, Bypassing Its Untrusted-Project Safeguard
A critical Jinja2 template-injection bug let attacker-controlled repository files execute code in the Serena coding agent, bypassing its own trust gate.