MCP and agent packages
The packages that advisories about the Model Context Protocol and AI agents name, with what the Exposure Registry knows about each one: the LLM components it declares and the authority its dependencies grant (shell, files, browser, network, code execution).
Advisories are grouped by topic. The Model Context Protocol view counts the records that match that topic, and the AI agents view counts those that match the AI agents or the agent-to-agent protocols topic. Package names are those the advisory source lists. How authority is measured
- Advisories
- 198
- Critical or high
- 148
- Packages named
- 77
- Advisories listed as exploited (CISA KEV)
- 2
99 advisories were published in the last 90 days and 50 in the 90 days before. 64 of the 198 name no package, because their source lists none.
Advisories by month of publication
| Month | Items |
|---|---|
| May 2025 | 1 |
| Jun 2025 | 2 |
| Jul 2025 | 4 |
| Aug 2025 | 1 |
| Sep 2025 | 2 |
| Oct 2025 | 3 |
| Nov 2025 | 0 |
| Dec 2025 | 4 |
| Jan 2026 | 4 |
| Feb 2026 | 5 |
| Mar 2026 | 18 |
| Apr 2026 | 16 |
| May 2026 | 19 |
| Jun 2026 | 13 |
| Jul 2026 | 28 |
| Aug 2026 | 36 |
| Sep 2026 | 31 |
| Oct 2026 | 11 |
Latest advisories
- HighGHSA-hc5v-gxvj-58wh: PraisonAI: MCP HTTP-stream transport is unauthenticated by default, exposing tool enumeration and an unvalidated tool-call surface2026-10-08
- HighGHSA-6qxp-vccf-f47h: MCP TypeScript SDK: OAuth client could send credentials to an authorization server chosen by the MCP server2026-10-06
- HighCVE-2026-105741: Langflow IP spoofing bypasses local-only restriction on MCP install endpoint2026-10-05
- CriticalCVE-2026-105740: Langflow remote code execution through MCP server stdio command field2026-10-05
- HighCVE-2026-105699: Langflow MCP resource read exposes other users' flow files2026-10-05
- CriticalCVE-2026-105697: Langflow arbitrary command execution through MCP stdio server configuration2026-10-05
- MediumGHSA-p23f-cm6q-2qp8: SiYuan MCP asset.upload Reads Arbitrary Absolute File Paths (Workspace Boundary Bypass)2026-10-02
- MediumGHSA-c9xm-49cp-xcr9: rmcp OAuth client fetches server-controlled resource_metadata URLs2026-10-02
Authority in the registry
81 registry packages declare the MCP SDK or FastMCP. Their dependencies grant:
- MCP tools74Exposes or calls Model Context Protocol tools, which pass authority between agents and servers.
- Outbound HTTP38Makes outbound requests, the precondition for server-side request forgery and exfiltration.
- File system9Reads or writes files, so path traversal and data exposure are in reach.
- Browser control7Drives a browser, so it can act on websites with the user's sessions.
- Code execution7Runs code it is given, so injected instructions can become arbitrary code.
- Shell commands3Starts processes on the host, the most direct path from a prompt to the operating system.
Advisories that name langflow
ClosePyPI. Every record that names the package, on any topic, newest first. RSS feed for this package
- MediumGHSA-j8f7-x8jm-wmm4: Langflow: SSRF in URL-taking components (protection disabled by default / warn-only, not applied to RSS, SearXNG, Web Search, Home Assistant, Glean, Docling)2026-10-06
- CriticalGHSA-8qpj-27x8-pwpq: Langflow: PythonREPLComponent executes unsandboxed Python code, enabling authenticated RCE and privilege escalation2026-10-06
- HighCVE-2026-105741: Langflow IP spoofing bypasses local-only restriction on MCP install endpoint2026-10-05
- HighCVE-2026-105699: Langflow MCP resource read exposes other users' flow files2026-10-05
- MediumCVE-2026-105698: Langflow flow ownership bypass in deprecated build vertices endpoints2026-10-05
- CriticalCVE-2026-105697: Langflow arbitrary command execution through MCP stdio server configuration2026-10-05
- CriticalCVE-2026-51886: Langflow code injection in /api/v1/validate/code endpoint2026-10-01
- HighCVE-2026-9205: IBM Langflow OSS weak key derivation in ensure_fernet_key()2026-08-05
- CriticalCVE-2026-8505: IBM Langflow OSS unauthenticated flow execution through webhook authentication2026-07-17
- CriticalGHSA-ccv6-r384-xp75: Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit2026-06-19
- HighGHSA-qwqc-p3q8-wcg9: Langflow: Unauthenticated DoS through multipart form boundary file upload2026-06-19
- MediumGHSA-7hw8-6q6r-4276: Langflow: Logout button does not clear session2026-06-19
- CriticalGHSA-qrpv-q767-xqq2: Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow2026-06-19 · listed as exploited by CISA
- CriticalGHSA-x223-p2gf-v735: Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak2026-06-17
- MediumGHSA-rcjh-r59h-gq37: Langflow: Unauthenticated Shareable Playground arbitrary local or S3 file read2026-06-16
- CriticalGHSA-v5ff-9q35-q26f: Langflow: Unauthenticated RCE in Shareable Playgrounds2026-06-16
- MediumGHSA-79ph-745m-6wxq: Langflow: Path Traversal in Knowledge Bases API via Creation Endpoint2026-06-16
- HighGHSA-9c59-2mvc-vfr8: Langflow: IDOR/BOLA in Monitor API — Missing Ownership Enforcement on 7 Endpoints 2026-06-16
- CriticalCVE-2026-42048: Langflow path traversal in Knowledge Bases API DELETE endpoint2026-05-12
- MediumCVE-2026-7700: Langflow code injection in eval of lambda_filter component2026-05-03
- MediumCVE-2026-6599: Langflow injection through X-Forwarded-For in MCP project configuration API2026-04-20
- MediumCVE-2026-6598: Langflow cleartext storage of auth settings in project creation2026-04-20
- LowCVE-2026-6597: Langflow stores API credentials unprotected in Flow Using API component2026-04-20
- CriticalCVE-2026-33873: Langflow arbitrary Python execution through Agentic Assistant validation2026-03-27
- HighGHSA-8c4j-f57c-35cf: Langflow: Authenticated Users Can Read, Modify, and Delete Any Flow via Missing Ownership Check2026-03-27
- HighGHSA-ph9w-r52h-28p7: langflow: /profile_pictures/{folder_name}/{file_name} endpoint file reading2026-03-20
- HighGHSA-7grx-3xcx-2xv5: langflow has Unauthenticated IDOR on Image Downloads2026-03-20
- CriticalGHSA-g2j9-7rj2-gm6c: Langflow has an Arbitrary File Write (RCE) via v2 API2026-03-19
- HighGHSA-rf6x-r45m-xv3w: Langflow is Missing Ownership Verification in API Key Deletion (IDOR)2026-03-18
- CriticalGHSA-vwmf-pq79-vjvx: Unauthenticated Remote Code Execution in Langflow via Public Flow Build Endpoint2026-03-17 · listed as exploited by CISA
- CriticalCVE-2026-27966: Langflow CSV Agent code execution through prompt injection2026-02-26
- CriticalCVE-2026-0770: Langflow remote code execution through exec_globals in the validate endpoint2026-01-23 · listed as exploited by CISA
- CriticalCVE-2026-21445: Langflow missing authentication on API endpoints exposes user data2026-01-03
- HighCVE-2025-68478: Langflow arbitrary file write through the fs_path request field2025-12-19
- HighCVE-2025-68477: Langflow server-side request forgery through the API Request component2025-12-19
- HighCVE-2025-34291: Langflow account takeover and remote code execution via CORS and refresh token2025-12-06 · listed as exploited by CISA
- HighCVE-2025-57760: Langflow privilege escalation in containers via langflow superuser CLI command2025-08-25
- CriticalCVE-2025-3248: Langflow code injection in /api/v1/validate/code endpoint2025-04-07 · listed as exploited by CISA
- CriticalCVE-2024-48061: langflow remote code execution through components running outside a sandbox2024-11-05
- CriticalCVE-2024-42835: langflow remote code execution via the PythonCodeTool component2024-10-31
- LowCVE-2024-9277: Langflow regular expression complexity flaw in HTTP POST request handler2024-09-27
- CriticalCVE-2024-37014: Langflow remote code execution through custom component endpoint2024-06-11
Packages named in advisories
77 packages
| Package | Advisories | Highest severity | Latest advisory | Exploited | Authority |
|---|---|---|---|---|---|
| mcp-atlassianPyPI | 8 | Critical | Not in the registry | ||
| n8nnpm | 7 | High | Code execution, File system, MCP tools, Shell commands | ||
| n8n-mcpnpm | 7 | Critical | Not in the registry | ||
| mcpPyPI | 6 | High | None detected | ||
| fastmcpPyPI | 6 | Critical | None detected | ||
| litellmPyPI | 5 | Critical | 2 on CISA KEV | Code execution, Outbound HTTP, MCP tools | |
| mcp-searxngnpm | 4 | High | Not in the registry | ||
| flowisenpm | 4 | Critical | Outbound HTTP, MCP tools | ||
| flowise-componentsnpm | 4 | Critical | Browser control, Code execution, Outbound HTTP, MCP tools | ||
| mcp-server-kubernetesnpm | 4 | High | Not in the registry | ||
| github.com/modelcontextprotocol/go-sdkGo | 4 | High | None detected | ||
| praisonaiPyPI | 3 | High | Not in the registry | ||
| @modelcontextprotocol/sdknpm | 3 | High | Shell commands | ||
| langflowPyPI | 3 | Critical | None detected | ||
| rmcpcrates.io | 3 | High | Outbound HTTP | ||
| @aborruso/ckan-mcp-servernpm | 3 | Medium | Not in the registry | ||
| github.com/sonirico/mcp-shellGo | 3 | High | Not in the registry | ||
| network-ainpm | 3 | Critical | Not in the registry | ||
| @ooples/token-optimizer-mcpnpm | 2 | High | Not in the registry | ||
| @bitbonsai/mcpvaultnpm | 2 | Medium | Not in the registry | ||
| codewhale-tuicrates.io | 2 | High | Not in the registry | ||
| deepseek-tuicrates.io | 2 | High | Not in the registry | ||
| codewhalenpm | 2 | High | Not in the registry | ||
| deepseek-tuinpm | 2 | High | Not in the registry | ||
| chainlitPyPI | 2 | Critical | File system, Outbound HTTP, MCP tools | ||
| @apify/actors-mcp-servernpm | 2 | High | Not in the registry | ||
| awslabs-aws-api-mcp-serverPyPI | 2 | High | Not in the registry | ||
| @grackle-ai/mcpnpm | 2 | High | Not in the registry | ||
| agentsnpm | 2 | Medium | Not in the registry | ||
| @modelcontextprotocol/clientnpm | 1 | High | Shell commands | ||
| langflow-basePyPI | 1 | Critical | File system, Outbound HTTP, MCP tools | ||
| lfxPyPI | 1 | Critical | File system, Outbound HTTP, MCP tools | ||
| github.com/siyuan-note/siyuan/kernelGo | 1 | Medium | Not in the registry | ||
| clinenpm | 1 | High | Not in the registry | ||
| @bytebase/dbhubnpm | 1 | Critical | Not in the registry | ||
| @roomi-fields/notebooklm-mcpnpm | 1 | High | Not in the registry | ||
| github.com/stacklok/toolhiveGo | 1 | High | Not in the registry | ||
| @andrea9293/mcp-documentation-servernpm | 1 | High | Not in the registry | ||
| functype-mcp-servernpm | 1 | High | Not in the registry | ||
| browse-mcpnpm | 1 | High | Not in the registry | ||
| nextcloud-mcp-serverPyPI | 1 | Critical | Not in the registry | ||
| omnigentPyPI | 1 | Critical | Not in the registry | ||
| @contentful/mcp-servernpm | 1 | High | Not in the registry | ||
| @contentful/mcp-toolsnpm | 1 | High | Not in the registry | ||
| claude-faf-mcpnpm | 1 | High | Not in the registry | ||
| faf-mcpnpm | 1 | High | Not in the registry | ||
| grok-faf-mcpnpm | 1 | High | Not in the registry | ||
| atomic-agents-stackPyPI | 1 | High | Not in the registry | ||
| neuro-cortex-memoryPyPI | 1 | High | Not in the registry | ||
| @jshookmcp/jshooknpm | 1 | Medium | Not in the registry |
Topics are assigned by matching a record's title and summary against published patterns, so an advisory that never uses the words is missed and one that mentions them in passing is counted. An advisory that names several packages counts once for each. A package is listed with the ecosystem its advisory source states, and by name alone when the source states none.
Authority is read from the dependencies a package's latest release declares, and it is known only for packages the Exposure Registry tracks. It shows what a package's dependencies can do on the host. It does not show that a model is given that reach. Severity comes from the source advisory when it gives one, otherwise from the classifier. Dates are in UTC.