{
  "slug": "n4d-mesh",
  "name": "n4d mesh",
  "aliases": [
    "n4d mesh controller"
  ],
  "status": "dormant",
  "firstSeen": "2026-07-01",
  "lastSeen": "2026-07-01",
  "lastReviewed": "2026-09-20T00:00:00Z",
  "summary": "Shodan-driven MCP command loops harvested exposed AI infrastructure credentials.",
  "description": "The reported mesh chained ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio exposures through MCP execute_command loops.",
  "actor": "n4d mesh controller",
  "platforms": [
    "internet-exposed",
    "ollama",
    "github"
  ],
  "ttps": [
    {
      "framework": "safe_mcp",
      "id": "execute_command"
    }
  ],
  "timeline": [
    {
      "date": "2026-07-01",
      "branch": "exposure",
      "id": "mcp-execute_command-loop",
      "note": "XLab-linked reporting described the mesh.",
      "source": "https://cybersecuritynews.com/nadmesh-uses-shodan/",
      "approximate": true
    }
  ],
  "iocs": [
    {
      "type": "package",
      "value": "execute_command",
      "firstSeen": "2026-07-01",
      "source": "https://cybersecuritynews.com/nadmesh-uses-shodan/"
    }
  ],
  "exposedConfigurations": [
    {
      "label": "MCP exposes execute_command alongside a public AI service",
      "matcher": {
        "all": [
          {
            "some": "tools",
            "where": {
              "field": "name",
              "op": "eq",
              "value": "execute_command"
            }
          },
          {
            "field": "surface",
            "op": "in",
            "value": [
              "public",
              "internet"
            ]
          }
        ]
      }
    }
  ],
  "advisories": [
    "ACVE-2026-0420"
  ],
  "incidents": [],
  "sources": [
    {
      "url": "https://cybersecuritynews.com/nadmesh-uses-shodan/",
      "publisher": "Cybersecurity News",
      "date": "2026-07-01"
    }
  ],
  "dormantAfterDays": 30
}
