<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Open Source Security on Lynx Tech Blog</title><link>https://blog.lynxflow.co/en/tags/open-source-security/</link><description>Recent content in Open Source Security on Lynx Tech Blog</description><generator>Hugo -- gohugo.io</generator><language>en</language><lastBuildDate>Fri, 28 Aug 2026 00:00:00 +0800</lastBuildDate><atom:link href="https://blog.lynxflow.co/en/tags/open-source-security/index.xml" rel="self" type="application/rss+xml"/><item><title>From Rejected to Published: My First Security Advisory</title><link>https://blog.lynxflow.co/en/posts/first-accepted-security-advisory-qwed-mcp-rce/</link><pubDate>Fri, 28 Aug 2026 00:00:00 +0800</pubDate><guid>https://blog.lynxflow.co/en/posts/first-accepted-security-advisory-qwed-mcp-rce/</guid><description>On the afternoon of August 27, 2026, I refreshed a private advisory page and watched its status flip from triage to published.
That was a genuinely good moment.
An advisory in four and a half hours The advisory is GHSA-2p69-jpm6-jrxh, severity Critical, CVSS 9.8. Its title reads:
qwed-mcp: RCE bypass of CVE-2026-55546 fix via __getattribute__ and string concatenation
In plain terms: qwed-mcp had just patched a remote-code-execution CVE (CVE-2026-55546) in its 0.2.1 release by adding a denylist o</description></item></channel></rss>