GHSA-2xhg-73j7-rrgx: Contentful MCP Server: export_space/import_space tools pass LLM-controlled `host`/`proxy` args to CMA client, redirecting server PAT to attacker-controlled endpoint
Summary
# Analysis ## Summary The Contentful MCP Server tools `export_space` and `import_space` accept LLM-controlled parameters like `host` and `proxy` that are passed directly to the API client without filtering, allowing an attacker to redirect the server's API credentials (a Personal Access Token, or PAT) to their own server. An attacker can exploit this by directly calling these tools with a malicious `host` parameter, or by embedding instructions in Contentful content that trick the LLM into mak
Vulnerability Details
EPSS: 0.0%
Yes
August 19, 2026
Classification
Taxonomy References
Affected Vendors
Affected Packages
Related Issues
Original source: https://github.com/advisories/GHSA-2xhg-73j7-rrgx
First tracked: August 19, 2026 at 08:01 PM
Classified by LLM (prompt v3) · confidence: 95%