The article describes an unauthenticated remote code execution vulnerability in CircleCI's MCP server, where the host/origin allowlist can be bypassed by any non-browser client. The provided text is a Reddit network security block notice and contains no technical details on CVSS scores, affected versions, a fixed version, or workarounds.
You've been blocked by network security. To continue, log in to your Reddit account or use your developer token If you think you've been blocked by mistake, file a ticket below and we'll look into it. Log in File a ticket