CVE-2026-54504: MCP Documentation Server is a local-first document management and semantic search server for AI coding agents. From 1.13
Summary
MCP Documentation Server versions 1.13.0 through 1.13.1 expose an unauthenticated API (a set of functions that other programs can call) on all network interfaces instead of restricting it to localhost (the local computer only), allowing attackers on the same network to read, search, insert, or delete documents without a password. The vulnerability requires network access from a local area network, virtual machine network, or similar connected network, but does not allow remote code execution (running arbitrary commands on the server).
Solution / Mitigation
This issue is fixed in 1.13.1.
Vulnerability Details
8.8(high)
EPSS: 0.0%
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
adjacent
low
none
none
September 17, 2026
Classification
Affected Vendors
Related Issues
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-54504
First tracked: September 17, 2026 at 08:07 PM
Classified by LLM (prompt v3) · confidence: 92%