Rails and Nuxt Hit by Critical RCEs; MCP 2.0 Drops SSE for Stateless HTTP
Two critical remote code execution vulnerabilities were disclosed this week affecting Rails and Nuxt applications running in production, requiring immediate patching. On the protocol side, mcp-handler version 2.0.0 implements the July 2026 MCP specification, replacing HTTP+SSE transport with a stateless Streamable HTTP model suited for serverless environments like AWS Lambda and Cloudflare Workers. The update removes the /sse and /message endpoints entirely, returning 410 Gone, and requires Node.js 20 or later along with a migration to the new MCP server SDK. Separately, AI Gateway is passing through provider-side cost and performance improvements, including an 80% price reduction for Luna tokens and a 2.5x speed boost for Sol's fast mode, with no code changes needed. ThinkingMachines also launched a smaller variant of its Inkling model via AI Gateway, featuring controllable reasoning effort, multimodal support, and an optional Zero Data Retention flag for compliance-sensitive deployments.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in