MCP and agent packages
The packages that advisories about the Model Context Protocol and AI agents name, with what the Exposure Registry knows about each one: the LLM components it declares and the authority its dependencies grant (shell, files, browser, network, code execution).
Advisories are grouped by topic. The Model Context Protocol view counts the records that match that topic, and the AI agents view counts those that match the AI agents or the agent-to-agent protocols topic. Package names are those the advisory source lists. How authority is measured
- Advisories
- 339
- Critical or high
- 240
- Packages named
- 109
- Advisories listed as exploited (CISA KEV)
- 2
140 advisories were published in the last 90 days and 81 in the 90 days before. 129 of the 339 name no package, because their source lists none.
Advisories by month of publication
| Month | Items |
|---|---|
| May 2025 | 2 |
| Jun 2025 | 5 |
| Jul 2025 | 6 |
| Aug 2025 | 6 |
| Sep 2025 | 12 |
| Oct 2025 | 7 |
| Nov 2025 | 3 |
| Dec 2025 | 8 |
| Jan 2026 | 10 |
| Feb 2026 | 19 |
| Mar 2026 | 29 |
| Apr 2026 | 25 |
| May 2026 | 39 |
| Jun 2026 | 16 |
| Jul 2026 | 43 |
| Aug 2026 | 50 |
| Sep 2026 | 42 |
| Oct 2026 | 15 |
Latest advisories
- CriticalCVE-2026-108263: Astron Agent code-node execution as root through workflow run endpoints2026-10-09
- HighGHSA-hc5v-gxvj-58wh: PraisonAI: MCP HTTP-stream transport is unauthenticated by default, exposing tool enumeration and an unvalidated tool-call surface2026-10-08
- LowCVE-2026-107288: Pydantic AI web fetch bypasses blocked_domains via hostname variants2026-10-08
- HighCVE-2026-107286: Pydantic AI streamed requests leak concurrency slots, causing denial of service2026-10-08
- HighCVE-2026-82627: Uncanny Automator WordPress plugin PHP object injection via deserialization2026-10-08
- HighGHSA-6qxp-vccf-f47h: MCP TypeScript SDK: OAuth client could send credentials to an authorization server chosen by the MCP server2026-10-06
- HighCVE-2026-105741: Langflow IP spoofing bypasses local-only restriction on MCP install endpoint2026-10-05
- CriticalCVE-2026-105740: Langflow remote code execution through MCP server stdio command field2026-10-05
Authority in the registry
330 registry packages declare an MCP component or an agent framework. Their dependencies grant:
- Outbound HTTP120Makes outbound requests, the precondition for server-side request forgery and exfiltration.
- MCP tools90Exposes or calls Model Context Protocol tools, which pass authority between agents and servers.
- File system24Reads or writes files, so path traversal and data exposure are in reach.
- Browser control19Drives a browser, so it can act on websites with the user's sessions.
- Code execution17Runs code it is given, so injected instructions can become arbitrary code.
- Shell commands6Starts processes on the host, the most direct path from a prompt to the operating system.
Advisories that name openclaw
Closenpm. Every record that names the package, on any topic, newest first. RSS feed for this package
- MediumGHSA-gfg9-5357-hv4c: OpenClaw: Webchat audio embedding could read local files without local-root containment2026-04-29
- HighGHSA-66r7-m7xm-v49h: OpenClaw: QQBot media tags could read arbitrary local files through reply text2026-04-17
- HighGHSA-vfp4-8x56-j7c5: OpenClaw: Exec environment denylist missed high-risk interpreter startup variables2026-04-17
- MediumCVE-2026-35651: OpenClaw ANSI escape sequence injection in approval prompts2026-04-10
- LowGHSA-cm8v-2vh9-cxf3: OpenClaw: GIT_DIR and related git plumbing env vars missing from exec env denylist (GHSA-m866-6qv5-p2fg variant)2026-04-09
- MediumGHSA-3vvq-q2qc-7rmp: OpenClaw B-M3: ClawHub package downloads are not enforced with integrity verification2026-04-09
- MediumGHSA-67mf-f936-ppxf: OpenClaw `node.pair.approve` placed in `operator.write` scope instead of `operator.pairing` allows unprivileged pairing approval2026-04-09
- MediumGHSA-5h3f-885m-v22w: OpenClaw: Existing WS sessions survive shared gateway token rotation2026-04-09
- MediumGHSA-68x5-xx89-w9mm: OpenClaw: resolvedAuth closure becomes stale after config reload2026-04-09
- MediumGHSA-cmfr-9m2r-xwhq: OpenClaw `node.invoke(browser.proxy)` bypasses `browser.request` persistent profile-mutation guard2026-04-09
- MediumGHSA-whf9-3hcx-gq54: OpenClaw `device.token.rotate` mints tokens for unapproved roles, bypassing device role-upgrade pairing2026-04-09
- HighGHSA-7437-7hg8-frrw: OpenClaw: HGRCPATH, CARGO_BUILD_RUSTC_WRAPPER, RUSTC_WRAPPER, and MAKEFLAGS missing from exec env denylist — RCE via build tool env injection (GHSA-cm8v-2vh9-cxf3 class)2026-04-09
- MediumGHSA-jj6q-rrrf-h66h: OpenClaw: Shared-secret comparison call sites leaked length information through timing2026-04-07
- MediumGHSA-846p-hgpv-vphc: OpenClaw: QQ Bot structured payloads could read arbitrary local files2026-04-07
- MediumCVE-2026-34511: OpenClaw PKCE verifier exposure via OAuth state parameter in Gemini flow2026-04-03
- MediumGHSA-6p8r-6m93-557f: OpenClaw: Fake DeviceToken Bypasses Shared Auth Rate Limiting2026-04-03
- HighGHSA-v3qc-wrwx-j3pw: OpenClaw: Agentic Consent Bypass — LLM Agent Can Silently Disable Exec Approval via `config.patch`2026-04-03
- LowGHSA-g86v-f9qv-rh6m: OpenClaw SSRF guard misses four IPv6 special-use ranges2026-03-31
- MediumGHSA-m866-6qv5-p2fg: OpenClaw host-env blocklist missing `GIT_TEMPLATE_DIR` and `AWS_CONFIG_FILE` allows code execution via env override2026-03-31
- HighGHSA-jccr-rrw2-vc8h: OpenClaw safeBins jq `$ENV` filter bypass allows environment variable disclosure2026-03-31
- HighGHSA-m3mh-3mpg-37hw: OpenClaw has an Arbitrary Malicious Code Execution Vulnerability2026-03-30
- MediumGHSA-68f8-9mhj-h2mp: OpenClaw has a Gateway HTTP /v1/models Route Bypasses Operator Read Scope2026-03-30
- HighGHSA-hr5v-j9h9-xjhg: OpenClaw has Sandbox Media Root Bypass via Unnormalized `mediaUrl` / `fileUrl` Parameter Keys (CWE-22)2026-03-30
- HighGHSA-7xr2-q9vf-x4r5: OpenClaw: Symlink Traversal via IDENTITY.md appendFile in agents.create/update (Incomplete Fix for CVE-2026-32013)2026-03-26
- HighGHSA-cxmw-p77q-wchg: OpenClaw: Arbitrary code execution via unvalidated WebView JavascriptInterface2026-03-26
- MediumCVE-2026-28451: OpenClaw server-side request forgery in Feishu extension media fetching2026-03-05
- HighGHSA-vvjh-f6p9-5vcf: OpenClaw Canvas Authentication Bypass Vulnerability2026-03-04
- MediumGHSA-9mph-4f7v-fmvh: OpenClaw has agent avatar symlink traversal in gateway session metadata2026-03-04
- HighGHSA-x2ff-j5c2-ggpr: OpenClaw: Slack interactive callbacks could skip configured sender checks in some shared-workspace flows2026-03-04
- LowGHSA-v6x2-2qvm-6gv8: OpenClaw reuses the gateway auth token in the owner ID prompt hashing fallback2026-03-03
- HighGHSA-659f-22xc-98f2: OpenClaw hook transform path containment missed symlink-resolved escapes2026-03-03
- MediumGHSA-56pc-6hvp-4gv4: OpenClaw vulnerable to arbitrary file read via $include directive2026-03-03
- MediumGHSA-6g25-pc82-vfwp: OpenClaw: macOS beta onboarding exposed PKCE verifier via OAuth state2026-03-03
- MediumGHSA-5847-rm3g-23mw: OpenClaw has hook auth rate limiter bypass via IPv4-mapped IPv6 client key variants2026-03-03
- HighGHSA-943q-mwmv-hhvh: OpenClaw: Gateway /tools/invoke tool escalation + ACP permission auto-approval2026-03-02
- HighGHSA-jq4x-98m3-ggq6: OpenClaw Canvas Path Traversal Information Disclosure Vulnerability2026-03-02
- HighCVE-2026-27487: OpenClaw OS command injection in macOS Claude CLI keychain credential refresh2026-02-21
- MediumGHSA-cxpw-2g23-2vgw: OpenClaw: ACP prompt-size checks missing in local stdio bridge could reduce responsiveness with very large inputs2026-02-20
- MediumGHSA-r6h2-5gqq-v5v6: OpenClaw: Reject symlinks in local skill packaging script2026-02-20
- LowGHSA-wh94-p5m6-mr7j: OpenClaw Discord moderation authorization used untrusted sender identity in tool-driven flows2026-02-20
- HighCVE-2026-26320: OpenClaw macOS client confirmation dialog hides part of deep link message2026-02-19
- MediumGHSA-fh3f-q9qw-93j9: OpenClaw replaced a deprecated sandbox hash algorithm2026-02-19
- MediumGHSA-xxvh-5hwj-42pp: OpenClaw's sandbox config hash sorted primitive arrays and suppressed needed container recreation2026-02-18
- MediumGHSA-6hf3-mhgc-cm65: OpenClaw session tool visibility hardening and Telegram webhook secret fallback2026-02-18
- MediumGHSA-chf7-jq6g-qrwv: OpenClaw: Telegram bot token exposure via logs2026-02-18
- HighGHSA-w235-x559-36mg: OpenClaw: Docker container escape via unvalidated bind mount config injection2026-02-18
- HighGHSA-2qj5-gwg2-xwc4: OpenClaw: Unsanitized CWD path injection into LLM prompts2026-02-18
- HighGHSA-x22m-j5qq-j49m: OpenClaw has two SSRF via sendMediaFeishu and markdown image fetching in Feishu extension2026-02-18
- MediumGHSA-jfv4-h8mc-jcp8: OpenClaw: Process Safety - Unvalidated PID Kill via SIGKILL in Process Cleanup2026-02-18
- MediumGHSA-7rcp-mxpq-72pj: OpenClaw Chutes manual OAuth state validation bypass can cause credential substitution2026-02-18
Packages named in advisories
109 packages
| Package | Advisories | Highest severity | Latest advisory | Exploited | Authority |
|---|---|---|---|---|---|
| clinenpm | 1 | High | Not in the registry | ||
| @bytebase/dbhubnpm | 1 | Critical | Not in the registry | ||
| @roomi-fields/notebooklm-mcpnpm | 1 | High | Not in the registry | ||
| hatchetGo | 1 | High | Not in the registry | ||
| hatchet-dev/hatchetGo | 1 | Medium | Not in the registry | ||
| github.com/stacklok/toolhiveGo | 1 | High | Not in the registry | ||
| @andrea9293/mcp-documentation-servernpm | 1 | High | Not in the registry | ||
| functype-mcp-servernpm | 1 | High | Not in the registry | ||
| browse-mcpnpm | 1 | High | Not in the registry | ||
| nextcloud-mcp-serverPyPI | 1 | Critical | Not in the registry | ||
| @contentful/mcp-servernpm | 1 | High | Not in the registry | ||
| @contentful/mcp-toolsnpm | 1 | High | Not in the registry | ||
| claude-faf-mcpnpm | 1 | High | Not in the registry | ||
| faf-mcpnpm | 1 | High | Not in the registry | ||
| grok-faf-mcpnpm | 1 | High | Not in the registry | ||
| atomic-agents-stackPyPI | 1 | High | Not in the registry | ||
| neuro-cortex-memoryPyPI | 1 | High | Not in the registry | ||
| @trigger.dev/corenpm | 1 | High | Not in the registry | ||
| @jshookmcp/jshooknpm | 1 | Medium | Not in the registry | ||
| stata-mcpPyPI | 1 | High | Not in the registry | ||
| gemini-bridgePyPI | 1 | Medium | Not in the registry | ||
| n8nEcosystem not stated | 1 | High | Not in the registry | ||
| @agenticmail/claudecodenpm | 1 | High | Not in the registry | ||
| @agenticmail/codexnpm | 1 | High | Not in the registry | ||
| @agenticmail/openclawnpm | 1 | High | Not in the registry | ||
| mcp-memory-keepernpm | 1 | Medium | Not in the registry | ||
| langbotPyPI | 1 | High | Not in the registry | ||
| phantom-audioPyPI | 1 | High | Not in the registry | ||
| github.com/coder/coder/v2Go | 1 | Medium | Not in the registry | ||
| @grackle-ai/authnpm | 1 | High | Not in the registry | ||
| @grackle-ai/plugin-corenpm | 1 | High | Not in the registry | ||
| agentic-flownpm | 1 | High | Not in the registry | ||
| @agenticmail/mcpnpm | 1 | High | Not in the registry | ||
| anthropics/claude-code-actionactions | 1 | Medium | Not in the registry | ||
| github.com/safedep/gryphGo | 1 | Medium | Not in the registry | ||
| @yoda.digital/gitlab-mcp-servernpm | 1 | Critical | Not in the registry | ||
| @penpot/mcpnpm | 1 | High | Not in the registry | ||
| 9routernpm | 1 | Critical | Not in the registry | ||
| github.com/envoyproxy/ai-gatewayGo | 1 | Medium | Not in the registry | ||
| auth-fetch-mcpnpm | 1 | High | Not in the registry | ||
| apmPyPI | 1 | High | Not in the registry | ||
| paperclipainpm | 1 | Critical | Not in the registry | ||
| agixtPyPI | 1 | High | Not in the registry | ||
| io-modelcontextprotocol-sdk:mcp-coremaven | 1 | High | Not in the registry | ||
| @mobilenext/mobile-mcpnpm | 1 | High | Not in the registry | ||
| openclawnpm | 1 | High | Not in the registry | ||
| adx-mcp-serverPyPI | 1 | High | Not in the registry | ||
| github.com/tencent/weknoraGo | 1 | Medium | Not in the registry | ||
| github.com/agentgateway/agentgatewayGo | 1 | Medium | Not in the registry | ||
| @github/copilotnpm | 1 | High | Not in the registry |
Topics are assigned by matching a record's title and summary against published patterns, so an advisory that never uses the words is missed and one that mentions them in passing is counted. An advisory that names several packages counts once for each. A package is listed with the ecosystem its advisory source states, and by name alone when the source states none.
Authority is read from the dependencies a package's latest release declares, and it is known only for packages the Exposure Registry tracks. It shows what a package's dependencies can do on the host. It does not show that a model is given that reach. Severity comes from the source advisory when it gives one, otherwise from the classifier. Dates are in UTC.