MCP and agent packages
The packages that advisories about the Model Context Protocol and AI agents name, with what the Exposure Registry knows about each one: the LLM components it declares and the authority its dependencies grant (shell, files, browser, network, code execution).
Advisories are grouped by topic. The Model Context Protocol view counts the records that match that topic, and the AI agents view counts those that match the AI agents or the agent-to-agent protocols topic. Package names are those the advisory source lists. How authority is measured
- Advisories
- 198
- Critical or high
- 148
- Packages named
- 77
- Advisories listed as exploited (CISA KEV)
- 2
99 advisories were published in the last 90 days and 50 in the 90 days before. 64 of the 198 name no package, because their source lists none.
Advisories by month of publication
| Month | Items |
|---|---|
| May 2025 | 1 |
| Jun 2025 | 2 |
| Jul 2025 | 4 |
| Aug 2025 | 1 |
| Sep 2025 | 2 |
| Oct 2025 | 3 |
| Nov 2025 | 0 |
| Dec 2025 | 4 |
| Jan 2026 | 4 |
| Feb 2026 | 5 |
| Mar 2026 | 18 |
| Apr 2026 | 16 |
| May 2026 | 19 |
| Jun 2026 | 13 |
| Jul 2026 | 28 |
| Aug 2026 | 36 |
| Sep 2026 | 31 |
| Oct 2026 | 11 |
Latest advisories
- HighGHSA-hc5v-gxvj-58wh: PraisonAI: MCP HTTP-stream transport is unauthenticated by default, exposing tool enumeration and an unvalidated tool-call surface2026-10-08
- HighGHSA-6qxp-vccf-f47h: MCP TypeScript SDK: OAuth client could send credentials to an authorization server chosen by the MCP server2026-10-06
- HighCVE-2026-105741: Langflow IP spoofing bypasses local-only restriction on MCP install endpoint2026-10-05
- CriticalCVE-2026-105740: Langflow remote code execution through MCP server stdio command field2026-10-05
- HighCVE-2026-105699: Langflow MCP resource read exposes other users' flow files2026-10-05
- CriticalCVE-2026-105697: Langflow arbitrary command execution through MCP stdio server configuration2026-10-05
- MediumGHSA-p23f-cm6q-2qp8: SiYuan MCP asset.upload Reads Arbitrary Absolute File Paths (Workspace Boundary Bypass)2026-10-02
- MediumGHSA-c9xm-49cp-xcr9: rmcp OAuth client fetches server-controlled resource_metadata URLs2026-10-02
Authority in the registry
81 registry packages declare the MCP SDK or FastMCP. Their dependencies grant:
- MCP tools74Exposes or calls Model Context Protocol tools, which pass authority between agents and servers.
- Outbound HTTP38Makes outbound requests, the precondition for server-side request forgery and exfiltration.
- File system9Reads or writes files, so path traversal and data exposure are in reach.
- Browser control7Drives a browser, so it can act on websites with the user's sessions.
- Code execution7Runs code it is given, so injected instructions can become arbitrary code.
- Shell commands3Starts processes on the host, the most direct path from a prompt to the operating system.
Advisories that name flowise
Closenpm. Every record that names the package, on any topic, newest first. RSS feed for this package
- CriticalGHSA-9gvv-qjj3-2p6g: Flowise NodeVM sandbox escape via puppeteer allowlist - authenticated RCE and arbitrary file read via Chromium2026-10-07
- CriticalCVE-2026-73487: Flowise Python code validator bypass in CSV and Airtable Agent nodes2026-08-13
- CriticalGHSA-qgvm-j2hm-6m38: Flowise: Unauthenticated OAuth2 token refresh endpoint returns access tokens — enables token theft for any connected service2026-08-04
- CriticalGHSA-5xvg-pmgg-3mxr: Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability2026-08-04
- HighGHSA-gmmw-qg98-6j6p: Flowise: Broken Access Control in Stripe Subscription Endpoints Allows Cross-Tenant Billing Manipulation2026-08-04
- MediumGHSA-8gj2-2cvc-6xx7: Flowise: Unauthenticated Credential Abuse via Text-to-Speech Endpoint Allows Unauthorized Use of Private Chatflow TTS Credentials2026-08-04
- HighGHSA-fm2f-4339-4p2f: Flowise: Missing Authorization on Execution Update Endpoint2026-08-04
- HighGHSA-wch5-xp77-fxg4: Flowise: Cross-Workspace OAuth2 Credential Metadata Leak2026-08-04
- MediumGHSA-rwrp-9823-p2xq: Flowise: Incomplete Credential Redaction Exposes Secrets via API2026-08-04
- HighGHSA-fr6g-7cq8-fg82: Flowise: Information Disclosure in GET /api/v1/upsert-history returns the entire server-wide upsert history2026-08-04
- HighGHSA-chm3-vqcf-52rx: Flowise: Cross-workspace credential IDOR in openai-assistants-vector-store2026-08-04
- CriticalGHSA-4j8x-x6v7-w9rq: Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python source without validation2026-08-04
- HighGHSA-88pr-878c-24wf: Flowise: Authenticated arbitrary file write in the `S3 Directory` document loader via unsanitized S3 object keys 2026-08-04
- HighGHSA-8r8h-6vcc-xhrv: Flowise: RBAC Bypass Leading to Unauthorized Workspace Variables Disclosure2026-08-04
- CriticalGHSA-52fh-8v99-63c2: Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE2026-08-04
- HighGHSA-xc48-889x-5qmw: Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable blocklist (Unauthenticated RCE)2026-08-04
- HighGHSA-p5w8-m249-4r4v: Flowise: `DELETE /api/v1/chatflows/:id` does not validate resource type, allowing `agentflows:delete` and `chatflows:delete` to delete each other’s flow type2026-08-04
- CriticalGHSA-x3hf-7cj6-3r4m: Flowise RCE via SQLite Record Manager Node2026-08-04
- HighGHSA-6vh2-wg4h-4vwj: Flowise: Unauthenticated Property Injection into Flow Execution Context via Ungated `overrideConfig` Spread in Prediction API2026-08-04
- HighGHSA-c6xh-wv4j-ppv5: Flowise: SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses2026-08-04
- CriticalGHSA-x6vm-w76m-8j7g: Flowise: Remote Code Execution Vulnerability in CSVAgent2026-08-04
- CriticalGHSA-vmv7-4m6c-3cg5: Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified2026-08-04
- CriticalGHSA-3769-jgqc-cxm7: Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions Override2026-08-04
- CriticalGHSA-wg86-r78f-74mp: Flowise Sandbox Escape to RCE2026-08-04
- HighGHSA-wp74-f5hh-5f3r: Flowise: Missing authorization on `/api/v1/files` allows low-privileged API keys to list and delete files across workspaces within the same organization2026-08-04
- CriticalGHSA-g32j-mmxr-gfq5: Flowise RCE via TypeORM DataSource2026-08-04
- HighGHSA-r745-8hwv-h473: Flowise: Unauthenticated OAuth2 Refresh Enables Non-Blind SSRF and Secret Exfiltration2026-08-04
- MediumGHSA-2364-jh4q-m9vm: Flowise: IDOR vulnerability exists at the GET /api/v1/organization/customer-default-source endpoint2026-08-04
- HighCVE-2026-46480: Flowise evaluator mass-assignment allows cross-workspace takeover2026-06-08
- HighCVE-2026-46479: Flowise mass-assignment flaw allows cross-workspace takeover2026-06-08
- HighCVE-2026-46478: Flowise mass-assignment flaw enables cross-workspace row takeover2026-06-08
- HighCVE-2026-46477: Flowise dataset mass-assignment allows cross-workspace takeover2026-06-08
- HighCVE-2026-46476: Flowise mass-assignment flaw enables cross-workspace template takeover2026-06-08
- HighCVE-2026-46475: Flowise assistant mass-assignment allows cross-workspace takeover2026-06-08
- HighCVE-2026-46444: Flowise OpenAI Assistants Vector Store endpoints lack authentication2026-06-08
- HighCVE-2026-46443: Flowise credential retrieval exposes encrypted data via credentialName filter2026-06-08
- CriticalCVE-2026-46442: Flowise remote code execution through /api/v1/node-custom-function endpoint2026-06-08
- MediumCVE-2026-46441: Flowise mass assignment in assistant update endpoint allows workspace2026-06-08
- HighCVE-2026-46440: Flowise checkBasicAuth validates plaintext creds without rate limiting2026-06-08
- MediumGHSA-c2c9-mfw7-p8hw: Flowise: Cross-Workspace Chatflow Disclosure via chatflows/apikey Endpoint Returns All Unprotected Chatflows2026-05-20
- MediumGHSA-59fh-9f3p-7m39: Flowise: Mass Assignment in PUT /api/v1/user Allows Authenticated Users to Override Password Hash and Bypass Password Change Verification2026-05-20
- MediumGHSA-m837-xvxr-vqwg: Flowise: Hardcoded CORS wildcard on TTS endpoint enables cross-origin credential abuse from any webpage2026-05-20
- HighGHSA-wxrr-jp8m-qq7f: FlowiseAI: Evaluator create+update mass-assignment allows cross-workspace evaluator takeover2026-05-14
- HighGHSA-mq53-pc65-wjc4: FlowiseAI: Evaluation create+update mass-assignment allows cross-workspace evaluation takeover2026-05-14
- HighGHSA-7j65-65cr-6644: FlowiseAI: DatasetRow create+update mass-assignment allows cross-workspace row takeover2026-05-14
- HighGHSA-5h9v-837x-m97r: FlowiseAI: Dataset create+update mass-assignment allows cross-workspace dataset takeover2026-05-14
- HighGHSA-728h-4mwj-f2p4: FlowiseAI: CustomTemplate create+update mass-assignment allows cross-workspace template takeover2026-05-14
- HighGHSA-78pr-c5x5-jggc: FlowiseAI: Assistant create+update mass-assignment allows cross-workspace assistant takeover2026-05-14
- HighGHSA-hmg2-jjjx-jcp2: FlowiseAI: Vector Store No Permission Checks2026-05-14
- HighGHSA-7g73-99r4-m4mj: FlowiseAI Vulnerable to Credential Data Leak2026-05-14
Packages named in advisories
77 packages
| Package | Advisories | Highest severity | Latest advisory | Exploited | Authority |
|---|---|---|---|---|---|
| mcp-atlassianPyPI | 8 | Critical | Not in the registry | ||
| n8nnpm | 7 | High | Code execution, File system, MCP tools, Shell commands | ||
| n8n-mcpnpm | 7 | Critical | Not in the registry | ||
| mcpPyPI | 6 | High | None detected | ||
| fastmcpPyPI | 6 | Critical | None detected | ||
| litellmPyPI | 5 | Critical | 2 on CISA KEV | Code execution, Outbound HTTP, MCP tools | |
| mcp-searxngnpm | 4 | High | Not in the registry | ||
| flowisenpm | 4 | Critical | Outbound HTTP, MCP tools | ||
| flowise-componentsnpm | 4 | Critical | Browser control, Code execution, Outbound HTTP, MCP tools | ||
| mcp-server-kubernetesnpm | 4 | High | Not in the registry | ||
| github.com/modelcontextprotocol/go-sdkGo | 4 | High | None detected | ||
| praisonaiPyPI | 3 | High | Not in the registry | ||
| @modelcontextprotocol/sdknpm | 3 | High | Shell commands | ||
| langflowPyPI | 3 | Critical | None detected | ||
| rmcpcrates.io | 3 | High | Outbound HTTP | ||
| @aborruso/ckan-mcp-servernpm | 3 | Medium | Not in the registry | ||
| github.com/sonirico/mcp-shellGo | 3 | High | Not in the registry | ||
| network-ainpm | 3 | Critical | Not in the registry | ||
| @ooples/token-optimizer-mcpnpm | 2 | High | Not in the registry | ||
| @bitbonsai/mcpvaultnpm | 2 | Medium | Not in the registry | ||
| codewhale-tuicrates.io | 2 | High | Not in the registry | ||
| deepseek-tuicrates.io | 2 | High | Not in the registry | ||
| codewhalenpm | 2 | High | Not in the registry | ||
| deepseek-tuinpm | 2 | High | Not in the registry | ||
| chainlitPyPI | 2 | Critical | File system, Outbound HTTP, MCP tools | ||
| @apify/actors-mcp-servernpm | 2 | High | Not in the registry | ||
| awslabs-aws-api-mcp-serverPyPI | 2 | High | Not in the registry | ||
| @grackle-ai/mcpnpm | 2 | High | Not in the registry | ||
| agentsnpm | 2 | Medium | Not in the registry | ||
| @modelcontextprotocol/clientnpm | 1 | High | Shell commands | ||
| langflow-basePyPI | 1 | Critical | File system, Outbound HTTP, MCP tools | ||
| lfxPyPI | 1 | Critical | File system, Outbound HTTP, MCP tools | ||
| github.com/siyuan-note/siyuan/kernelGo | 1 | Medium | Not in the registry | ||
| clinenpm | 1 | High | Not in the registry | ||
| @bytebase/dbhubnpm | 1 | Critical | Not in the registry | ||
| @roomi-fields/notebooklm-mcpnpm | 1 | High | Not in the registry | ||
| github.com/stacklok/toolhiveGo | 1 | High | Not in the registry | ||
| @andrea9293/mcp-documentation-servernpm | 1 | High | Not in the registry | ||
| functype-mcp-servernpm | 1 | High | Not in the registry | ||
| browse-mcpnpm | 1 | High | Not in the registry | ||
| nextcloud-mcp-serverPyPI | 1 | Critical | Not in the registry | ||
| omnigentPyPI | 1 | Critical | Not in the registry | ||
| @contentful/mcp-servernpm | 1 | High | Not in the registry | ||
| @contentful/mcp-toolsnpm | 1 | High | Not in the registry | ||
| claude-faf-mcpnpm | 1 | High | Not in the registry | ||
| faf-mcpnpm | 1 | High | Not in the registry | ||
| grok-faf-mcpnpm | 1 | High | Not in the registry | ||
| atomic-agents-stackPyPI | 1 | High | Not in the registry | ||
| neuro-cortex-memoryPyPI | 1 | High | Not in the registry | ||
| @jshookmcp/jshooknpm | 1 | Medium | Not in the registry |
Topics are assigned by matching a record's title and summary against published patterns, so an advisory that never uses the words is missed and one that mentions them in passing is counted. An advisory that names several packages counts once for each. A package is listed with the ecosystem its advisory source states, and by name alone when the source states none.
Authority is read from the dependencies a package's latest release declares, and it is known only for packages the Exposure Registry tracks. It shows what a package's dependencies can do on the host. It does not show that a model is given that reach. Severity comes from the source advisory when it gives one, otherwise from the classifier. Dates are in UTC.