PSA: Stop running local MCP servers. The folks at futuresearch were pwned when a local MCP server pulled in an impacted package. Always run your MCP servers remotely. The blast radius should be limited to the container that it runs in. If you're impacted by the LiteLLM
Stop Running Local MCP Servers: Security Vulnerability Alert
By
–
