{"data":{"id":"26bc6771-eae5-4e41-afb7-30690488503f","title":"GHSA-2xhg-73j7-rrgx: Contentful MCP Server: export_space/import_space tools pass LLM-controlled `host`/`proxy` args to CMA client, redirecting server PAT to attacker-controlled endpoint","summary":"# Analysis\n\n## Summary\n\nThe Contentful MCP Server tools `export_space` and `import_space` accept LLM-controlled parameters like `host` and `proxy` that are passed directly to the API client without filtering, allowing an attacker to redirect the server's API credentials (a Personal Access Token, or PAT) to their own server. An attacker can exploit this by directly calling these tools with a malicious `host` parameter, or by embedding instructions in Contentful content that trick the LLM into mak","solution":"N/A — no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-2xhg-73j7-rrgx","publishedAt":"2026-08-19T19:17:00.000Z","cveId":"CVE-2026-53957","cweIds":null,"cvssScore":null,"cvssSeverity":"high","severity":"high","attackType":["prompt_injection"],"issueType":"vulnerability","affectedPackages":["@contentful/mcp-tools@< 0.4.5 (fixed: 0.4.5)","@contentful/mcp-server@< 1.7.19 (fixed: 1.7.19)"],"affectedVendors":[],"affectedVendorsRaw":["Contentful","@contentful/mcp-tools","contentful-export","contentful-import","contentful-management"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0,"patchAvailable":true,"disclosureDate":"2026-08-19T19:17:00.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"agent","llmSpecific":true,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":["AML.T0051"]}}