MCP and agent packages
The packages that advisories about the Model Context Protocol and AI agents name, with what the Exposure Registry knows about each one: the LLM components it declares and the authority its dependencies grant (shell, files, browser, network, code execution).
Advisories are grouped by topic. The Model Context Protocol view counts the records that match that topic, and the AI agents view counts those that match the AI agents or the agent-to-agent protocols topic. Package names are those the advisory source lists. How authority is measured
- Advisories
- 198
- Critical or high
- 148
- Packages named
- 77
- Advisories listed as exploited (CISA KEV)
- 2
99 advisories were published in the last 90 days and 50 in the 90 days before. 64 of the 198 name no package, because their source lists none.
Advisories by month of publication
| Month | Items |
|---|---|
| May 2025 | 1 |
| Jun 2025 | 2 |
| Jul 2025 | 4 |
| Aug 2025 | 1 |
| Sep 2025 | 2 |
| Oct 2025 | 3 |
| Nov 2025 | 0 |
| Dec 2025 | 4 |
| Jan 2026 | 4 |
| Feb 2026 | 5 |
| Mar 2026 | 18 |
| Apr 2026 | 16 |
| May 2026 | 19 |
| Jun 2026 | 13 |
| Jul 2026 | 28 |
| Aug 2026 | 36 |
| Sep 2026 | 31 |
| Oct 2026 | 11 |
Latest advisories
- HighGHSA-hc5v-gxvj-58wh: PraisonAI: MCP HTTP-stream transport is unauthenticated by default, exposing tool enumeration and an unvalidated tool-call surface2026-10-08
- HighGHSA-6qxp-vccf-f47h: MCP TypeScript SDK: OAuth client could send credentials to an authorization server chosen by the MCP server2026-10-06
- HighCVE-2026-105741: Langflow IP spoofing bypasses local-only restriction on MCP install endpoint2026-10-05
- CriticalCVE-2026-105740: Langflow remote code execution through MCP server stdio command field2026-10-05
- HighCVE-2026-105699: Langflow MCP resource read exposes other users' flow files2026-10-05
- CriticalCVE-2026-105697: Langflow arbitrary command execution through MCP stdio server configuration2026-10-05
- MediumGHSA-p23f-cm6q-2qp8: SiYuan MCP asset.upload Reads Arbitrary Absolute File Paths (Workspace Boundary Bypass)2026-10-02
- MediumGHSA-c9xm-49cp-xcr9: rmcp OAuth client fetches server-controlled resource_metadata URLs2026-10-02
Authority in the registry
81 registry packages declare the MCP SDK or FastMCP. Their dependencies grant:
- MCP tools74Exposes or calls Model Context Protocol tools, which pass authority between agents and servers.
- Outbound HTTP38Makes outbound requests, the precondition for server-side request forgery and exfiltration.
- File system9Reads or writes files, so path traversal and data exposure are in reach.
- Browser control7Drives a browser, so it can act on websites with the user's sessions.
- Code execution7Runs code it is given, so injected instructions can become arbitrary code.
- Shell commands3Starts processes on the host, the most direct path from a prompt to the operating system.
Advisories that name litellm
ClosePyPI. Every record that names the package, on any topic, newest first. RSS feed for this package
- HighCVE-2026-59823: LiteLLM Proxy server-side request forgery through user_config api_base2026-09-16
- MediumCVE-2026-84377: LiteLLM proxy credential exposure through unchecked api_base redirection2026-09-02
- CriticalCVE-2026-37004: LiteLLM unauthenticated command execution via template injection2026-08-27
- HighCVE-2026-59822: LiteLLM authentication bypass through MCP Streamable HTTP endpoint2026-07-08 · listed as exploited by CISA
- LowCVE-2026-59821: LiteLLM code injection through Custom Code Guardrails create and update2026-07-08
- HighCVE-2026-59820: LiteLLM path traversal in Skills archive extraction via uploaded ZIP2026-07-08
- LowCVE-2026-59819: LiteLLM file read through /health/test_connection endpoint2026-07-08
- LowGHSA-p897-vf7j-f5h8: BerriAI litellm has Security Feature Bypass in BannedKeywords and AzureContentSafety Guardrails via call_type Mismatch on Async Endpoints2026-06-21
- LowGHSA-m2v5-74w2-qhcj: BerriAI litellm: UI User Enumeration leads to System-Wide Information Disclosure2026-06-21
- LowGHSA-c693-x898-5g4h: BerriAI litellm has SSRF via Unvalidated spec_path URL in MCP OpenAPI Spec Loader2026-06-21
- LowGHSA-w2mh-qq9q-453x: BerriAI litellm: SSO Login Does Not Invalidate Previous UI Session Tokens2026-06-21
- MediumGHSA-j37q-q7p9-vpwm: LiteLLM: SSO Debug Flow Has Improper Authentication2026-06-21
- MediumGHSA-4jcj-7x88-m979: LiteLLM: MCP Proxy Has Improper Authentication2026-06-21
- LowGHSA-mf52-j94g-746m: LiteLLM: PROXY_ADMIN database API Key Generator Has Insufficient Session Expiration2026-06-21
- LowGHSA-qmf3-4767-5fg3: LiteLLM: M2M JWT Handler Has Improper Authorization2026-06-21
- LowGHSA-6qr3-3g89-m4jj: LiteLLM: Admin Key Handler Has Improper Authorization2026-06-21
- CriticalGHSA-4xpc-pv4p-pm3w: LiteLLM: Authentication Bypass via Host Header Injection2026-06-16
- HighCVE-2026-47102: LiteLLM self-service user update allows changing own user_role via /user/update2026-05-21
- HighCVE-2026-47101: LiteLLM API key creation bypasses role-based route restrictions2026-05-21
- CriticalCVE-2026-42271: LiteLLM command execution through MCP test endpoints2026-05-08 · listed as exploited by CISA
- CriticalCVE-2026-42208: LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before…2026-05-08 · listed as exploited by CISA
- CriticalCVE-2026-42203: LiteLLM code execution through prompt template rendering in /prompts/test2026-05-08
- HighGHSA-v4p8-mg3p-g94g: LiteLLM: Authenticated command execution via MCP stdio test endpoints2026-04-25
- CriticalGHSA-r75f-5x8p-qvmc: LiteLLM has SQL Injection in Proxy API key verification2026-04-24
- HighGHSA-xqmj-j6mv-4862: LiteLLM: Server-Side Template Injection in /prompts/test endpoint2026-04-24
- HighCVE-2026-40217: LiteLLM remote code execution at /guardrails/test_custom_code2026-04-10
- HighGHSA-69x8-hrgq-fjj8: LiteLLM: Password hash exposure and pass-the-hash authentication bypass2026-04-08
- CriticalGHSA-jjhc-v7c2-5hh6: LiteLLM: Authentication bypass via OIDC userinfo cache key collision2026-04-03
- HighGHSA-53mr-6c8q-9789: LiteLLM: Privilege escalation via unrestricted proxy configuration endpoint2026-04-03
- CriticalGHSA-5mg7-485q-xm76: Two LiteLLM versions published containing credential harvesting malware2026-03-25
- MediumCVE-2024-10188: LiteLLM denial of service through unsafe parsing of user input2025-03-20
- HighGHSA-879v-fggm-vxw2: LiteLLM Has a Leakage of Langfuse API Keys2025-03-20
- HighGHSA-fjcf-3j3r-78rp: LiteLLM Has an Improper Authorization Vulnerability2025-03-20
- HighGHSA-g5pg-73fc-hjwq: LiteLLM Reveals Portion of API Key via a Logging File2025-03-20
- HighGHSA-fh2c-86xm-pm2x: LiteLLM Vulnerable to Denial of Service (DoS) via Crafted HTTP Request2025-03-20
- HighGHSA-53gh-p8jc-7rg8: LiteLLM Vulnerable to Remote Code Execution (RCE)2025-03-20
- HighCVE-2024-6587: litellm server-side request forgery through api_base in chat completions2024-09-13
- MediumGHSA-qqcv-vg9f-5rr3: litellm vulnerable to improper access control in team management2024-06-27
- CriticalGHSA-gppg-gqw8-wh9g: litellm vulnerable to remote code execution based on using eval unsafely2024-06-27
- HighCVE-2024-4888: BerriAI litellm arbitrary file deletion through /audio/transcriptions endpoint2024-06-06
- MediumGHSA-8j42-pcfm-3467: SQL injection in litellm2024-06-06
- MediumGHSA-h6m6-jj8v-94jj: SQL injection in litellm2024-06-06
- HighGHSA-7ggm-4rjg-594w: litellm passes untrusted data to `eval` function without sanitization2024-05-18
- CriticalGHSA-46cm-pfwv-cgf8: LiteLLM has Server-Side Template Injection vulnerability in /completions endpoint2024-04-10
Packages named in advisories
77 packages
| Package | Advisories | Highest severity | Latest advisory | Exploited | Authority |
|---|---|---|---|---|---|
| mcp-atlassianPyPI | 8 | Critical | Not in the registry | ||
| n8nnpm | 7 | High | Code execution, File system, MCP tools, Shell commands | ||
| n8n-mcpnpm | 7 | Critical | Not in the registry | ||
| mcpPyPI | 6 | High | None detected | ||
| fastmcpPyPI | 6 | Critical | None detected | ||
| litellmPyPI | 5 | Critical | 2 on CISA KEV | Code execution, Outbound HTTP, MCP tools | |
| mcp-searxngnpm | 4 | High | Not in the registry | ||
| flowisenpm | 4 | Critical | Outbound HTTP, MCP tools | ||
| flowise-componentsnpm | 4 | Critical | Browser control, Code execution, Outbound HTTP, MCP tools | ||
| mcp-server-kubernetesnpm | 4 | High | Not in the registry | ||
| github.com/modelcontextprotocol/go-sdkGo | 4 | High | None detected | ||
| praisonaiPyPI | 3 | High | Not in the registry | ||
| @modelcontextprotocol/sdknpm | 3 | High | Shell commands | ||
| langflowPyPI | 3 | Critical | None detected | ||
| rmcpcrates.io | 3 | High | Outbound HTTP | ||
| @aborruso/ckan-mcp-servernpm | 3 | Medium | Not in the registry | ||
| github.com/sonirico/mcp-shellGo | 3 | High | Not in the registry | ||
| network-ainpm | 3 | Critical | Not in the registry | ||
| @ooples/token-optimizer-mcpnpm | 2 | High | Not in the registry | ||
| @bitbonsai/mcpvaultnpm | 2 | Medium | Not in the registry | ||
| codewhale-tuicrates.io | 2 | High | Not in the registry | ||
| deepseek-tuicrates.io | 2 | High | Not in the registry | ||
| codewhalenpm | 2 | High | Not in the registry | ||
| deepseek-tuinpm | 2 | High | Not in the registry | ||
| chainlitPyPI | 2 | Critical | File system, Outbound HTTP, MCP tools | ||
| @apify/actors-mcp-servernpm | 2 | High | Not in the registry | ||
| awslabs-aws-api-mcp-serverPyPI | 2 | High | Not in the registry | ||
| @grackle-ai/mcpnpm | 2 | High | Not in the registry | ||
| agentsnpm | 2 | Medium | Not in the registry | ||
| @modelcontextprotocol/clientnpm | 1 | High | Shell commands | ||
| langflow-basePyPI | 1 | Critical | File system, Outbound HTTP, MCP tools | ||
| lfxPyPI | 1 | Critical | File system, Outbound HTTP, MCP tools | ||
| github.com/siyuan-note/siyuan/kernelGo | 1 | Medium | Not in the registry | ||
| clinenpm | 1 | High | Not in the registry | ||
| @bytebase/dbhubnpm | 1 | Critical | Not in the registry | ||
| @roomi-fields/notebooklm-mcpnpm | 1 | High | Not in the registry | ||
| github.com/stacklok/toolhiveGo | 1 | High | Not in the registry | ||
| @andrea9293/mcp-documentation-servernpm | 1 | High | Not in the registry | ||
| functype-mcp-servernpm | 1 | High | Not in the registry | ||
| browse-mcpnpm | 1 | High | Not in the registry | ||
| nextcloud-mcp-serverPyPI | 1 | Critical | Not in the registry | ||
| omnigentPyPI | 1 | Critical | Not in the registry | ||
| @contentful/mcp-servernpm | 1 | High | Not in the registry | ||
| @contentful/mcp-toolsnpm | 1 | High | Not in the registry | ||
| claude-faf-mcpnpm | 1 | High | Not in the registry | ||
| faf-mcpnpm | 1 | High | Not in the registry | ||
| grok-faf-mcpnpm | 1 | High | Not in the registry | ||
| atomic-agents-stackPyPI | 1 | High | Not in the registry | ||
| neuro-cortex-memoryPyPI | 1 | High | Not in the registry | ||
| @jshookmcp/jshooknpm | 1 | Medium | Not in the registry |
Topics are assigned by matching a record's title and summary against published patterns, so an advisory that never uses the words is missed and one that mentions them in passing is counted. An advisory that names several packages counts once for each. A package is listed with the ecosystem its advisory source states, and by name alone when the source states none.
Authority is read from the dependencies a package's latest release declares, and it is known only for packages the Exposure Registry tracks. It shows what a package's dependencies can do on the host. It does not show that a model is given that reach. Severity comes from the source advisory when it gives one, otherwise from the classifier. Dates are in UTC.