MCP and agent packages
The packages that advisories about the Model Context Protocol and AI agents name, with what the Exposure Registry knows about each one: the LLM components it declares and the authority its dependencies grant (shell, files, browser, network, code execution).
Advisories are grouped by topic. The Model Context Protocol view counts the records that match that topic, and the AI agents view counts those that match the AI agents or the agent-to-agent protocols topic. Package names are those the advisory source lists. How authority is measured
- Advisories
- 339
- Critical or high
- 240
- Packages named
- 109
- Advisories listed as exploited (CISA KEV)
- 2
140 advisories were published in the last 90 days and 81 in the 90 days before. 129 of the 339 name no package, because their source lists none.
Advisories by month of publication
| Month | Items |
|---|---|
| May 2025 | 2 |
| Jun 2025 | 5 |
| Jul 2025 | 6 |
| Aug 2025 | 6 |
| Sep 2025 | 12 |
| Oct 2025 | 7 |
| Nov 2025 | 3 |
| Dec 2025 | 8 |
| Jan 2026 | 10 |
| Feb 2026 | 19 |
| Mar 2026 | 29 |
| Apr 2026 | 25 |
| May 2026 | 39 |
| Jun 2026 | 16 |
| Jul 2026 | 43 |
| Aug 2026 | 50 |
| Sep 2026 | 42 |
| Oct 2026 | 15 |
Latest advisories
- CriticalCVE-2026-108263: Astron Agent code-node execution as root through workflow run endpoints2026-10-09
- HighGHSA-hc5v-gxvj-58wh: PraisonAI: MCP HTTP-stream transport is unauthenticated by default, exposing tool enumeration and an unvalidated tool-call surface2026-10-08
- LowCVE-2026-107288: Pydantic AI web fetch bypasses blocked_domains via hostname variants2026-10-08
- HighCVE-2026-107286: Pydantic AI streamed requests leak concurrency slots, causing denial of service2026-10-08
- HighCVE-2026-82627: Uncanny Automator WordPress plugin PHP object injection via deserialization2026-10-08
- HighGHSA-6qxp-vccf-f47h: MCP TypeScript SDK: OAuth client could send credentials to an authorization server chosen by the MCP server2026-10-06
- HighCVE-2026-105741: Langflow IP spoofing bypasses local-only restriction on MCP install endpoint2026-10-05
- CriticalCVE-2026-105740: Langflow remote code execution through MCP server stdio command field2026-10-05
Authority in the registry
330 registry packages declare an MCP component or an agent framework. Their dependencies grant:
- Outbound HTTP120Makes outbound requests, the precondition for server-side request forgery and exfiltration.
- MCP tools90Exposes or calls Model Context Protocol tools, which pass authority between agents and servers.
- File system24Reads or writes files, so path traversal and data exposure are in reach.
- Browser control19Drives a browser, so it can act on websites with the user's sessions.
- Code execution17Runs code it is given, so injected instructions can become arbitrary code.
- Shell commands6Starts processes on the host, the most direct path from a prompt to the operating system.
Advisories that name n8n
CloseEcosystem not stated. Every record that names the package, on any topic, newest first. RSS feed for this package
- MediumGHSA-q5wm-mgqx-fv2f: n8n: Instance AI Credential Setup Accepts Unvalidated Probe URL from Fetched Content2026-09-10
- MediumGHSA-pf83-w3f9-8m37: n8n: Disabled OIDC SSO Endpoints Remain Active and Issue Valid Sessions2026-09-10
- MediumGHSA-5m98-cgcr-xx3q: n8n: GitHub Trigger 422 Reuse Path Skips Webhook Secret Storage, Causing Signature Verification to Fail-Open2026-09-10
- MediumGHSA-679f-58pq-4v2c: n8n: Prototype Pollution via Workflow Structure Summary Can Lead to Denial of Service2026-09-10
- MediumGHSA-65xw-2v52-jhxc: n8n: Cross-User Active Workflow ID and Lifecycle Event Disclosure via Missing userId Filter2026-09-10
- HighGHSA-6xcw-7xm6-48c6: n8n: Expression Sandbox Escape via Shared Builtin Tampering and Code-Printer Injection Leads to Code Execution2026-09-10
- MediumGHSA-35jj-42hp-8gmq: n8n: Anonymous Approval-Gate Bypass via Reused resumeToken over the Chat WebSocket2026-09-10
- HighGHSA-hh89-3r9w-qj3j: n8n: Unauthenticated Persistent Storage Exhaustion via OAuth Dynamic Client Registration Endpoint2026-09-10
- HighCVE-2026-86082: n8n OpenAI Chat Model node leaks credentials via model-search dropdown2026-09-08
- MediumGHSA-7hgx-277f-7vmg: n8n: Agent Workflow Tool Bypasses Sub-Workflow Caller Policy2026-09-08
- MediumGHSA-89gh-3pgc-v5h2: n8n: Custom Header Credential Values Leaked in Plaintext into LLM Node Execution Data2026-07-22
- MediumGHSA-33q9-f52j-gc75: n8n: Unauthenticated Endpoint Allows Cancellation of Any User's Active Test Webhook2026-07-22
- MediumGHSA-gq66-9cw5-j5jm: n8n: GraphQL Node Bypasses "Allowed HTTP Request Domains" Restriction2026-07-22
- MediumGHSA-q5xf-xhwf-cwqf: n8n: Member-Level Users Can Execute Other Users' MCP Server Trigger Workflows via Missing OAuth Authorization Check2026-07-22
- MediumGHSA-fpg6-x68q-5793: n8n: computer-use Shell Sandbox Not Enforced on Linux and Windows2026-07-22
- MediumGHSA-2xgm-wc4g-5jvg: n8n: Improper Authorization Allows Authenticated Users to Assign Workflows to Folders in Other Projects2026-07-22
- MediumGHSA-2434-3x6q-8r99: n8n: External Secrets Accessible via Workflow Expressions Outside Credentials2026-07-22
- MediumGHSA-pf2q-pxhf-hgmw: n8n: Path-Confinement Bypass in computer-use search_files Allows Reading Files Outside the Base Directory2026-07-22
- MediumGHSA-hx4h-vr3m-45vh: n8n: Prototype Pollution via VM Expression Engine Sandbox Escape Leads to Denial of Service2026-07-22
- HighGHSA-xwx6-jjhv-84p8: n8n: Prototype Pollution via Dot-Notation Field Names Leads To Instance-Wide Denial of Service2026-07-22
- HighGHSA-xmc9-4f2h-jf9c: n8n: Edit Image Node Format Injection Allows Arbitrary File Write2026-07-22
- HighGHSA-cj9h-qx8g-pq2g: n8n: Shared-Workflow Editor Can Exfiltrate Credentials via Inline Sub-Workflow JSON2026-07-22
- HighGHSA-gv7g-jm28-cr3m: n8n: Expression sandbox escape via arrow-function bodies enabling command execution2026-07-22
- MediumGHSA-vhf8-cg2h-cg3p: n8n: SSRF Protection Bypass via MCP Client Node2026-07-22
- HighGHSA-9wcp-9r3j-383q: n8n: Stored DOM XSS via Resource Locator `cachedResultUrl`2026-07-22
- HighGHSA-x5vx-c2c8-m3w9: n8n: AI Agents Project Viewer Privilege Escalation via run_node_tool2026-07-22
- HighGHSA-w46p-w7w2-fr9g: Duplicate Advisory: AI Agents Project Viewer Privilege Escalation via run_node_tool2026-07-22
- HighGHSA-h5xr-fqvj-253p: Duplicate Advisory: Stored DOM XSS via Resource Locator `cachedResultUrl`2026-07-22
- HighCVE-2026-59207: n8n AI Agents MCP tool ignores credential HTTP domain restriction2026-07-09
- MediumGHSA-664h-gpgq-h6xx: n8n: Wrong OAuth Scope on Evaluation Test Runs Endpoints2026-06-17
- HighGHSA-qrx8-25qr-5r7v: n8n: MCP Browser HTTP Transport Exposes Unauthenticated Browser-Control Sessions2026-06-16
- MediumGHSA-h3jj-5f3v-3685: n8n: Public API Execution Retry Authorization Bypass2026-06-16
- MediumGHSA-jwm3-qcfw-c5pp: n8n: Python Code Node AST Validator Bypass2026-06-16
- HighGHSA-42h7-m79w-wvg5: n8n: Stored XSS in Chat Trigger Node2026-06-16
- HighGHSA-9pq8-m8gp-4p53: n8n: Python sandbox escape2026-06-16
- MediumGHSA-3875-8gcx-7v46: n8n: Credential exfiltration via Allowed HTTP Request Domains Bypass2026-05-19
- MediumGHSA-2vx9-7wpg-88jq: n8n: Legacy ExecuteWorkflow Node Bypassed File Path Restrictions2026-05-19
- HighGHSA-6h4j-wcr9-2vg7: n8n Has a Cross-user Authorization Bypass in Dynamic Credential OAuth Endpoints2026-05-14
- CriticalGHSA-c8xv-5998-g76h: n8n: HTTP Request Node Pagination Prototype Pollution to RCE2026-05-14
- CriticalGHSA-q5f4-99jv-pgg5: n8n has Prototype Pollution in XML Webhook Body Parser that Leads to RCE2026-04-29
- HighGHSA-537j-gqpc-p7fq: n8n Vulnerable to XSS via MCP OAuth client2026-04-29
- HighGHSA-r4v6-9fqc-w5jr: n8n's Credential Authorization Bypass in dynamic-node-parameters Allows Foreign API Key Replay2026-04-29
- HighGHSA-49m9-pgww-9vq6: n8n Vulnerable to Unauthenticated Denial of Service via MCP Client Registration2026-04-29
- MediumGHSA-f77h-j2v7-g6mw: n8n Vulnerable to Hijacking of Unauthenticated Chat Execution 2026-04-29
- MediumGHSA-f6x8-65q6-j9m9: n8n has Open Redirect in MCP OAuth Consent Flow2026-04-29
- MediumGHSA-3c7f-5hgj-h279: n8n has XSS in Chat Trigger Node through Custom CSS2026-03-27
- HighGHSA-fxcw-h3qj-8m8p: n8n Has External Secrets Authorization Bypass in Credential Saving2026-03-25
- MediumGHSA-vpgc-2f6g-7w7x: n8n Has Authorization Bypass in OAuth Callback via N8N_SKIP_AUTH_ON_OAUTH_CALLBACK2026-03-25
- HighGHSA-m63j-689w-3j35: n8n is Vulnerable to Credential Theft via Name-Based Resolution and Permission Checker Bypass in Community Edition2026-03-25
- HighGHSA-xvh5-5qg4-x9qp: n8n has In-Process Memory Disclosure in its Task Runner2026-03-25
Packages named in advisories
109 packages
| Package | Advisories | Highest severity | Latest advisory | Exploited | Authority |
|---|---|---|---|---|---|
| clinenpm | 1 | High | Not in the registry | ||
| @bytebase/dbhubnpm | 1 | Critical | Not in the registry | ||
| @roomi-fields/notebooklm-mcpnpm | 1 | High | Not in the registry | ||
| hatchetGo | 1 | High | Not in the registry | ||
| hatchet-dev/hatchetGo | 1 | Medium | Not in the registry | ||
| github.com/stacklok/toolhiveGo | 1 | High | Not in the registry | ||
| @andrea9293/mcp-documentation-servernpm | 1 | High | Not in the registry | ||
| functype-mcp-servernpm | 1 | High | Not in the registry | ||
| browse-mcpnpm | 1 | High | Not in the registry | ||
| nextcloud-mcp-serverPyPI | 1 | Critical | Not in the registry | ||
| @contentful/mcp-servernpm | 1 | High | Not in the registry | ||
| @contentful/mcp-toolsnpm | 1 | High | Not in the registry | ||
| claude-faf-mcpnpm | 1 | High | Not in the registry | ||
| faf-mcpnpm | 1 | High | Not in the registry | ||
| grok-faf-mcpnpm | 1 | High | Not in the registry | ||
| atomic-agents-stackPyPI | 1 | High | Not in the registry | ||
| neuro-cortex-memoryPyPI | 1 | High | Not in the registry | ||
| @trigger.dev/corenpm | 1 | High | Not in the registry | ||
| @jshookmcp/jshooknpm | 1 | Medium | Not in the registry | ||
| stata-mcpPyPI | 1 | High | Not in the registry | ||
| gemini-bridgePyPI | 1 | Medium | Not in the registry | ||
| n8nEcosystem not stated | 1 | High | Not in the registry | ||
| @agenticmail/claudecodenpm | 1 | High | Not in the registry | ||
| @agenticmail/codexnpm | 1 | High | Not in the registry | ||
| @agenticmail/openclawnpm | 1 | High | Not in the registry | ||
| mcp-memory-keepernpm | 1 | Medium | Not in the registry | ||
| langbotPyPI | 1 | High | Not in the registry | ||
| phantom-audioPyPI | 1 | High | Not in the registry | ||
| github.com/coder/coder/v2Go | 1 | Medium | Not in the registry | ||
| @grackle-ai/authnpm | 1 | High | Not in the registry | ||
| @grackle-ai/plugin-corenpm | 1 | High | Not in the registry | ||
| agentic-flownpm | 1 | High | Not in the registry | ||
| @agenticmail/mcpnpm | 1 | High | Not in the registry | ||
| anthropics/claude-code-actionactions | 1 | Medium | Not in the registry | ||
| github.com/safedep/gryphGo | 1 | Medium | Not in the registry | ||
| @yoda.digital/gitlab-mcp-servernpm | 1 | Critical | Not in the registry | ||
| @penpot/mcpnpm | 1 | High | Not in the registry | ||
| 9routernpm | 1 | Critical | Not in the registry | ||
| github.com/envoyproxy/ai-gatewayGo | 1 | Medium | Not in the registry | ||
| auth-fetch-mcpnpm | 1 | High | Not in the registry | ||
| apmPyPI | 1 | High | Not in the registry | ||
| paperclipainpm | 1 | Critical | Not in the registry | ||
| agixtPyPI | 1 | High | Not in the registry | ||
| io-modelcontextprotocol-sdk:mcp-coremaven | 1 | High | Not in the registry | ||
| @mobilenext/mobile-mcpnpm | 1 | High | Not in the registry | ||
| openclawnpm | 1 | High | Not in the registry | ||
| adx-mcp-serverPyPI | 1 | High | Not in the registry | ||
| github.com/tencent/weknoraGo | 1 | Medium | Not in the registry | ||
| github.com/agentgateway/agentgatewayGo | 1 | Medium | Not in the registry | ||
| @github/copilotnpm | 1 | High | Not in the registry |
Topics are assigned by matching a record's title and summary against published patterns, so an advisory that never uses the words is missed and one that mentions them in passing is counted. An advisory that names several packages counts once for each. A package is listed with the ecosystem its advisory source states, and by name alone when the source states none.
Authority is read from the dependencies a package's latest release declares, and it is known only for packages the Exposure Registry tracks. It shows what a package's dependencies can do on the host. It does not show that a model is given that reach. Severity comes from the source advisory when it gives one, otherwise from the classifier. Dates are in UTC.