{"data":{"id":"5eb7ddef-64f2-4613-8ebb-f2f0ebcd42e8","title":"CVE-2026-97228: Rapid7 Bulk Export MCP versions 0.2.5 through 0.6.1 suffer from a GraphQL query injection issue in the export-status com","summary":"Rapid7 Bulk Export MCP versions 0.2.5 through 0.6.1 have a GraphQL query injection vulnerability (a type of attack where an attacker manipulates database queries by inserting malicious code) in the export-status component. An attacker can craft a malicious `export_id` value that breaks out of the intended query and adds their own commands, but the attack is limited because it only runs with the operator's own API permissions and cannot access other accounts or organizations.","solution":"This is fixed in version 0.6.2, which passes `export_id` as a parameterized GraphQL variable (`$exportId: ID!`), meaning the value is treated as data rather than part of the query structure itself.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-97228","publishedAt":"2026-09-25T11:17:02.163Z","cveId":"CVE-2026-97228","cweIds":["CWE-943"],"cvssScore":"2.7","cvssSeverity":"low","severity":"low","attackType":["prompt_injection"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["Rapid7"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N","attackVector":"network","attackComplexity":"low","privilegesRequired":"high","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-09-25T11:17:02.163Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity"],"aiComponentTargeted":"agent","llmSpecific":false,"classifierConfidence":0.75,"researchCategory":null,"atlasIds":["AML.T0051"]}}