Skip to content

MCP and agent packages

The packages that advisories about the Model Context Protocol and AI agents name, with what the Exposure Registry knows about each one: the LLM components it declares and the authority its dependencies grant (shell, files, browser, network, code execution).

Advisories are grouped by topic. The Model Context Protocol view counts the records that match that topic, and the AI agents view counts those that match the AI agents or the agent-to-agent protocols topic. Package names are those the advisory source lists. How authority is measured

Advisories
198
Critical or high
148
Packages named
77
Advisories listed as exploited (CISA KEV)
2

99 advisories were published in the last 90 days and 50 in the 90 days before. 64 of the 198 name no package, because their source lists none.

Advisories by month of publication

May 2025: 11May 2025Jun 2025: 2Jul 2025: 4Aug 2025: 1Sep 2025: 2Oct 2025: 3Nov 2025: 0Dec 2025: 4Jan 2026: 4Jan 2026Feb 2026: 5Mar 2026: 18Apr 2026: 16May 2026: 19Jun 2026: 13Jul 2026: 28Aug 2026: 3636Sep 2026: 31Oct 2026: 1111Oct 2026
Advisories in this view, per month of publication
MonthItems
May 20251
Jun 20252
Jul 20254
Aug 20251
Sep 20252
Oct 20253
Nov 20250
Dec 20254
Jan 20264
Feb 20265
Mar 202618
Apr 202616
May 202619
Jun 202613
Jul 202628
Aug 202636
Sep 202631
Oct 202611

Authority in the registry

81 registry packages declare the MCP SDK or FastMCP. Their dependencies grant:

  • MCP tools74Exposes or calls Model Context Protocol tools, which pass authority between agents and servers.
  • Outbound HTTP38Makes outbound requests, the precondition for server-side request forgery and exfiltration.
  • File system9Reads or writes files, so path traversal and data exposure are in reach.
  • Browser control7Drives a browser, so it can act on websites with the user's sessions.
  • Code execution7Runs code it is given, so injected instructions can become arbitrary code.
  • Shell commands3Starts processes on the host, the most direct path from a prompt to the operating system.

Packages that declare the MCP SDK, in the Exposure Registry

Advisories that name langflow

Close

PyPI. Every record that names the package, on any topic, newest first. RSS feed for this package

Packages named in advisories

77 packages

Packages named in advisories of this view, with their advisory count and registry entry
PackageAdvisoriesHighest severityLatest advisoryExploitedAuthority
mcp-atlassianPyPI8CriticalNot in the registry
n8nnpm7HighCode execution, File system, MCP tools, Shell commands
n8n-mcpnpm7CriticalNot in the registry
mcpPyPI6HighNone detected
fastmcpPyPI6CriticalNone detected
litellmPyPI5Critical2 on CISA KEVCode execution, Outbound HTTP, MCP tools
mcp-searxngnpm4HighNot in the registry
flowisenpm4CriticalOutbound HTTP, MCP tools
flowise-componentsnpm4CriticalBrowser control, Code execution, Outbound HTTP, MCP tools
mcp-server-kubernetesnpm4HighNot in the registry
github.com/modelcontextprotocol/go-sdkGo4HighNone detected
praisonaiPyPI3HighNot in the registry
@modelcontextprotocol/sdknpm3HighShell commands
langflowPyPI3CriticalNone detected
rmcpcrates.io3HighOutbound HTTP
@aborruso/ckan-mcp-servernpm3MediumNot in the registry
github.com/sonirico/mcp-shellGo3HighNot in the registry
network-ainpm3CriticalNot in the registry
@ooples/token-optimizer-mcpnpm2HighNot in the registry
@bitbonsai/mcpvaultnpm2MediumNot in the registry
codewhale-tuicrates.io2HighNot in the registry
deepseek-tuicrates.io2HighNot in the registry
codewhalenpm2HighNot in the registry
deepseek-tuinpm2HighNot in the registry
chainlitPyPI2CriticalFile system, Outbound HTTP, MCP tools
@apify/actors-mcp-servernpm2HighNot in the registry
awslabs-aws-api-mcp-serverPyPI2HighNot in the registry
@grackle-ai/mcpnpm2HighNot in the registry
agentsnpm2MediumNot in the registry
@modelcontextprotocol/clientnpm1HighShell commands
langflow-basePyPI1CriticalFile system, Outbound HTTP, MCP tools
lfxPyPI1CriticalFile system, Outbound HTTP, MCP tools
github.com/siyuan-note/siyuan/kernelGo1MediumNot in the registry
clinenpm1HighNot in the registry
@bytebase/dbhubnpm1CriticalNot in the registry
@roomi-fields/notebooklm-mcpnpm1HighNot in the registry
github.com/stacklok/toolhiveGo1HighNot in the registry
@andrea9293/mcp-documentation-servernpm1HighNot in the registry
functype-mcp-servernpm1HighNot in the registry
browse-mcpnpm1HighNot in the registry
nextcloud-mcp-serverPyPI1CriticalNot in the registry
omnigentPyPI1CriticalNot in the registry
@contentful/mcp-servernpm1HighNot in the registry
@contentful/mcp-toolsnpm1HighNot in the registry
claude-faf-mcpnpm1HighNot in the registry
faf-mcpnpm1HighNot in the registry
grok-faf-mcpnpm1HighNot in the registry
atomic-agents-stackPyPI1HighNot in the registry
neuro-cortex-memoryPyPI1HighNot in the registry
@jshookmcp/jshooknpm1MediumNot in the registry

Topics are assigned by matching a record's title and summary against published patterns, so an advisory that never uses the words is missed and one that mentions them in passing is counted. An advisory that names several packages counts once for each. A package is listed with the ecosystem its advisory source states, and by name alone when the source states none.

Authority is read from the dependencies a package's latest release declares, and it is known only for packages the Exposure Registry tracks. It shows what a package's dependencies can do on the host. It does not show that a model is given that reach. Severity comes from the source advisory when it gives one, otherwise from the classifier. Dates are in UTC.