JFrog AppTrust: A Technical Deep Dive into Building a Trusted Software Supply Chain
October 16, 2025 | 7 min read
October 21, 2025
10 min read
JFrog Security Research recently discovered and disclosed multiple CVEs in oatpp-mcp - the Oat++ framework’s implementation of Anthropic’s Model Context Protocol (MCP) standard. Among these, CVE-2025-6515 stood out due to its potential threat of hijacking MCP session IDs. Within the context of MCP we’ve dubbed this new attack technique "Prompt Hijacking". Your browser does not…
October 16, 2025 | 7 min read
October 15, 2025 | 5 min read
September 19, 2025 | 4 min read
September 16, 2025 | 7 min read
October 1, 2025 | 4 min read
September 16, 2025 | 11 min read
September 11, 2025 | 5 min read
September 10, 2025 | 4 min read
September 17, 2025 | 13 min read
September 9, 2025 | 7 min read