All vulnerabilities CVE-2026-61542 · GHSA-fmvx-487g-mrww Gearsystem: MCP HTTP transport binds every interface without authentication highCVSS 7.6CWE-306 Vendor drhelius Package io.github.drhelius/gearsystem Affected <= 3.8.6 Disclosed 2026-06-12 Credit Avishai Gonen auth-bypassmcp Published advisory