MCP and agent packages
The packages that advisories about the Model Context Protocol and AI agents name, with what the Exposure Registry knows about each one: the LLM components it declares and the authority its dependencies grant (shell, files, browser, network, code execution).
Advisories are grouped by topic. The Model Context Protocol view counts the records that match that topic, and the AI agents view counts those that match the AI agents or the agent-to-agent protocols topic. Package names are those the advisory source lists. How authority is measured
- Advisories
- 339
- Critical or high
- 240
- Packages named
- 109
- Advisories listed as exploited (CISA KEV)
- 2
140 advisories were published in the last 90 days and 81 in the 90 days before. 129 of the 339 name no package, because their source lists none.
Advisories by month of publication
| Month | Items |
|---|---|
| May 2025 | 2 |
| Jun 2025 | 5 |
| Jul 2025 | 6 |
| Aug 2025 | 6 |
| Sep 2025 | 12 |
| Oct 2025 | 7 |
| Nov 2025 | 3 |
| Dec 2025 | 8 |
| Jan 2026 | 10 |
| Feb 2026 | 19 |
| Mar 2026 | 29 |
| Apr 2026 | 25 |
| May 2026 | 39 |
| Jun 2026 | 16 |
| Jul 2026 | 43 |
| Aug 2026 | 50 |
| Sep 2026 | 42 |
| Oct 2026 | 15 |
Latest advisories
- CriticalCVE-2026-108263: Astron Agent code-node execution as root through workflow run endpoints2026-10-09
- HighGHSA-hc5v-gxvj-58wh: PraisonAI: MCP HTTP-stream transport is unauthenticated by default, exposing tool enumeration and an unvalidated tool-call surface2026-10-08
- LowCVE-2026-107288: Pydantic AI web fetch bypasses blocked_domains via hostname variants2026-10-08
- HighCVE-2026-107286: Pydantic AI streamed requests leak concurrency slots, causing denial of service2026-10-08
- HighCVE-2026-82627: Uncanny Automator WordPress plugin PHP object injection via deserialization2026-10-08
- HighGHSA-6qxp-vccf-f47h: MCP TypeScript SDK: OAuth client could send credentials to an authorization server chosen by the MCP server2026-10-06
- HighCVE-2026-105741: Langflow IP spoofing bypasses local-only restriction on MCP install endpoint2026-10-05
- CriticalCVE-2026-105740: Langflow remote code execution through MCP server stdio command field2026-10-05
Authority in the registry
330 registry packages declare an MCP component or an agent framework. Their dependencies grant:
- Outbound HTTP120Makes outbound requests, the precondition for server-side request forgery and exfiltration.
- MCP tools90Exposes or calls Model Context Protocol tools, which pass authority between agents and servers.
- File system24Reads or writes files, so path traversal and data exposure are in reach.
- Browser control19Drives a browser, so it can act on websites with the user's sessions.
- Code execution17Runs code it is given, so injected instructions can become arbitrary code.
- Shell commands6Starts processes on the host, the most direct path from a prompt to the operating system.
Advisories that name flowise-components
Closenpm. Every record that names the package, on any topic, newest first. RSS feed for this package
- CriticalGHSA-9gvv-qjj3-2p6g: Flowise NodeVM sandbox escape via puppeteer allowlist - authenticated RCE and arbitrary file read via Chromium2026-10-07
- CriticalCVE-2026-73487: Flowise Python code validator bypass in CSV and Airtable Agent nodes2026-08-13
- CriticalGHSA-5xvg-pmgg-3mxr: Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability2026-08-04
- CriticalGHSA-4j8x-x6v7-w9rq: Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python source without validation2026-08-04
- HighGHSA-88pr-878c-24wf: Flowise: Authenticated arbitrary file write in the `S3 Directory` document loader via unsanitized S3 object keys 2026-08-04
- CriticalGHSA-52fh-8v99-63c2: Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE2026-08-04
- HighGHSA-xc48-889x-5qmw: Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable blocklist (Unauthenticated RCE)2026-08-04
- CriticalGHSA-x3hf-7cj6-3r4m: Flowise RCE via SQLite Record Manager Node2026-08-04
- CriticalGHSA-x6vm-w76m-8j7g: Flowise: Remote Code Execution Vulnerability in CSVAgent2026-08-04
- CriticalGHSA-vmv7-4m6c-3cg5: Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified2026-08-04
- CriticalGHSA-3769-jgqc-cxm7: Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions Override2026-08-04
- CriticalGHSA-wg86-r78f-74mp: Flowise Sandbox Escape to RCE2026-08-04
- CriticalGHSA-g32j-mmxr-gfq5: Flowise RCE via TypeORM DataSource2026-08-04
- HighGHSA-m99r-2hxc-cp3q: Flowise has an MCP Security Bypass that Enables RCE2026-05-14
- MediumCVE-2026-43995: Flowise tools bypass secured wrapper and invoke raw HTTP clients2026-05-11
- CriticalCVE-2026-41274: Flowise GraphCypherQAChain node Cypher injection into Neo4j database2026-04-23
- HighCVE-2026-41272: Flowise SSRF protection bypass via DNS rebinding and default configuration2026-04-23
- HighCVE-2026-41271: Flowise server-side request forgery in POST/GET API Chain components2026-04-23
- HighCVE-2026-41270: Flowise SSRF protection bypass in Custom Function feature2026-04-23
- CriticalCVE-2026-41268: Flowise unauthenticated remote command execution via parameter override bypass2026-04-23
- CriticalCVE-2026-41265: Flowise command execution via prompt injection in Airtable Agent node2026-04-23
- CriticalCVE-2026-41138: Flowise remote code execution through AirtableAgent Pandas prompt input2026-04-23
- CriticalCVE-2026-41137: Flowise command injection through CSVAgent custom Pandas CSV read code2026-04-23
- CriticalCVE-2026-40933: Flowise command execution through Custom MCP stdio server configuration2026-04-21
- CriticalGHSA-3hjv-c53m-58jj: Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability2026-04-21
- CriticalGHSA-v38x-c887-992f: Flowise: Airtable_Agent Code Injection Remote Code Execution Vulnerability2026-04-18
- HighGHSA-28g4-38q8-3cwc: Flowise: Cypher Injection in GraphCypherQAChain2026-04-16
- HighGHSA-6r77-hqx7-7vw8: Flowise: APIChain Prompt Injection SSRF in GET/POST API Chains2026-04-16
- HighGHSA-2x8m-83vc-6wv4: Flowise: SSRF Protection Bypass (TOCTOU & Default Insecure)2026-04-16
- HighGHSA-xhmj-rg95-44hv: Flowise: SSRF Protection Bypass via Unprotected Built-in HTTP Modules in Custom Function Sandbox2026-04-16
- HighGHSA-cvrr-qhgw-2mm6: Flowise: Parameter Override Bypass Remote Command Execution2026-04-16
- CriticalGHSA-9wc7-mj3f-74xv: Flowise: Code Injection in CSVAgent leads to Authenticated RCE2026-04-16
- HighGHSA-f228-chmx-v6j6: Flowise: Remote code execution vulnerability in AirtableAgent.ts caused by lack of input verification when using `Pandas`.2026-04-16
- HighCVE-2026-31829: Flowise SSRF through HTTP Node in AgentFlow and Chatflow2026-03-10
- CriticalCVE-2025-61913: Flowise path traversal in WriteFileTool and ReadFileTool allows2025-10-08
Packages named in advisories
109 packages
| Package | Advisories | Highest severity | Latest advisory | Exploited | Authority |
|---|---|---|---|---|---|
| @anthropic-ai/claude-codenpm | 22 | Critical | Not in the registry | ||
| n8nnpm | 10 | High | Code execution, File system, MCP tools, Shell commands | ||
| mcp-atlassianPyPI | 8 | Critical | Not in the registry | ||
| n8n-mcpnpm | 7 | Critical | Not in the registry | ||
| mcpPyPI | 6 | High | None detected | ||
| fastmcpPyPI | 6 | Critical | None detected | ||
| github.com/pinchtab/pinchtabGo | 6 | High | Not in the registry | ||
| github.com/hatchet-dev/hatchetGo | 5 | Medium | Not in the registry | ||
| litellmPyPI | 5 | Critical | 2 on CISA KEV | Code execution, Outbound HTTP, MCP tools | |
| praisonaiPyPI | 4 | Critical | Not in the registry | ||
| pydantic-aiPyPI | 4 | High | None detected | ||
| pydantic-ai-slimPyPI | 4 | High | Outbound HTTP | ||
| langflowPyPI | 4 | Critical | None detected | ||
| omnigentPyPI | 4 | Critical | Not in the registry | ||
| mcp-searxngnpm | 4 | High | Not in the registry | ||
| flowisenpm | 4 | Critical | Outbound HTTP, MCP tools | ||
| flowise-componentsnpm | 4 | Critical | Browser control, Code execution, Outbound HTTP, MCP tools | ||
| mcp-server-kubernetesnpm | 4 | High | Not in the registry | ||
| github.com/modelcontextprotocol/go-sdkGo | 4 | High | None detected | ||
| @modelcontextprotocol/sdknpm | 3 | High | Shell commands | ||
| rmcpcrates.io | 3 | High | Outbound HTTP | ||
| @aborruso/ckan-mcp-servernpm | 3 | Medium | Not in the registry | ||
| github.com/sonirico/mcp-shellGo | 3 | High | Not in the registry | ||
| network-ainpm | 3 | Critical | Not in the registry | ||
| @evomap/evolvernpm | 3 | Critical | Not in the registry | ||
| github.com/pinchtab/pinchtab/cmd/pinchtabGo | 3 | High | Not in the registry | ||
| @ooples/token-optimizer-mcpnpm | 2 | High | Not in the registry | ||
| @bitbonsai/mcpvaultnpm | 2 | Medium | Not in the registry | ||
| codewhale-tuicrates.io | 2 | High | Not in the registry | ||
| deepseek-tuicrates.io | 2 | High | Not in the registry | ||
| codewhalenpm | 2 | High | Not in the registry | ||
| deepseek-tuinpm | 2 | High | Not in the registry | ||
| chainlitPyPI | 2 | Critical | File system, Outbound HTTP, MCP tools | ||
| @apify/actors-mcp-servernpm | 2 | High | Not in the registry | ||
| awslabs-aws-api-mcp-serverPyPI | 2 | High | Not in the registry | ||
| @agenticmail/corenpm | 2 | High | Not in the registry | ||
| @agenticmail/apinpm | 2 | High | Not in the registry | ||
| @grackle-ai/mcpnpm | 2 | High | Not in the registry | ||
| apm-cliPyPI | 2 | High | Not in the registry | ||
| @paperclipai/servernpm | 2 | Critical | Not in the registry | ||
| @openai/codexnpm | 2 | High | Not in the registry | ||
| @enclave-vm/corenpm | 2 | Critical | Not in the registry | ||
| agentsnpm | 2 | Medium | Not in the registry | ||
| enclave-vmnpm | 2 | Critical | Not in the registry | ||
| opencode-ainpm | 2 | High | Not in the registry | ||
| neuron-core/neuron-aicomposer | 2 | Critical | Not in the registry | ||
| @modelcontextprotocol/clientnpm | 1 | High | Shell commands | ||
| langflow-basePyPI | 1 | Critical | File system, Outbound HTTP, MCP tools | ||
| lfxPyPI | 1 | Critical | File system, Outbound HTTP, MCP tools | ||
| github.com/siyuan-note/siyuan/kernelGo | 1 | Medium | Not in the registry |
Topics are assigned by matching a record's title and summary against published patterns, so an advisory that never uses the words is missed and one that mentions them in passing is counted. An advisory that names several packages counts once for each. A package is listed with the ecosystem its advisory source states, and by name alone when the source states none.
Authority is read from the dependencies a package's latest release declares, and it is known only for packages the Exposure Registry tracks. It shows what a package's dependencies can do on the host. It does not show that a model is given that reach. Severity comes from the source advisory when it gives one, otherwise from the classifier. Dates are in UTC.