Model Context Protocol
The Model Context Protocol and the servers and clients that expose tools and data to models through it.
- All items
- 295
- Last 90 days
- 133
- Change
- +53%vs 87 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 2 |
| Jun 2025 | 4 |
| Jul 2025 | 4 |
| Aug 2025 | 7 |
| Sep 2025 | 3 |
| Oct 2025 | 3 |
| Nov 2025 | 2 |
| Dec 2025 | 4 |
| Jan 2026 | 4 |
| Feb 2026 | 12 |
| Mar 2026 | 22 |
| Apr 2026 | 27 |
| May 2026 | 31 |
| Jun 2026 | 25 |
| Jul 2026 | 43 |
| Aug 2026 | 45 |
| Sep 2026 | 40 |
| Oct 2026 | 16 |
295 items
Straiker Wins 2026 CyberSecurity Breakthrough Award for Cybersecurity Solution of the Year for Artificial Intelligence
Oct 9, 2026InfoNewsIndustryStraiker, an agentic AI security company, announced on October 9, 2026 that it was named "Cybersecurity Solution of the Year for Artificial Intelligence" in the 2026 CyberSecurity Breakthrough Awards. Its platform has three capabilities: Discover AI for visibility into AI agents, MCP servers, Agent Skills, tools, and connections; Ascend AI for autonomous adversarial testing of prompt injection, tool misuse, and data exfiltration; and Defend AI for real-time runtime protection with an agentic kill switch to contain compromised agents.
Straiker BlogGHSA-hc5v-gxvj-58wh: PraisonAI: MCP HTTP-stream transport is unauthenticated by default, exposing tool enumeration and an unvalidated tool-call surface
Oct 8, 2026HighVulnerabilitySecurityCVE-2026-61427PraisonAI 4.6.63's MCP HTTP-stream server applies authentication only when an API key is set, and the CLI defaults `--api-key` to `None`, so `praisonai mcp serve --transport http-stream` exposes the full MCP surface without authentication. An unauthenticated client can call `initialize` and `tools/list` (about 50 tools), and the dispatcher in `mcp_server/server.py` forwards tool-call arguments to handlers without validating them against the advertised `inputSchema`. The source states this is not an RCE or file read in 4.6.63, because `workflow.run` and `workflow.run_file` fail at runtime.
GitHub Advisory DatabaseTop MCP security resources — October 2026
Oct 8, 2026MediumNewsSecurityIndustryThis is a news digest of 15 MCP security resources for October 2026. It highlights an authentication bypass in LiteLLM's MCP endpoint, which accepts any invalid bearer token (CVE-2026-59822) and is now on CISA's Known Exploited Vulnerabilities list, and session ID spoofing in the Grafana MCP server, which lets unauthenticated callers invoke tools with the server's service account credentials.
Adversa AI BlogGHSA-6qxp-vccf-f47h: MCP TypeScript SDK: OAuth client could send credentials to an authorization server chosen by the MCP server
Oct 6, 2026HighVulnerabilitySecurityCVE-2026-104850GitHub Advisory DatabaseEndor Labs + SpaceXAI: Securing every stage of agentic software delivery | Blog | Endor Labs
Oct 6, 2026InfoNewsSecurityIndustryEndor Labs and SpaceXAI are partnering to secure agentic software delivery on Grok Build, from the first tool call to merged pull requests. Endor Labs checks code and dependencies as agents produce them and fixes issues before they leave the session. The integration started with a free MCP server, added a hooks integration in December 2025 that scans every package an agent installs, added Coding Agent Governance in May 2026, and added the Endor Labs Agent Kit in June.
Endor Labs BlogStraiker in Gartner® 2026 AI Cybersecurity Impact Radar
Oct 6, 2026InfoNewsIndustrySecurityGartner's Emerging Tech Impact Radar: AI Cybersecurity Ecosystem lists Straiker as a Sample Vendor in two categories: AI Security Testing and AI Security Platforms. Straiker says these reflect a shift toward continuously attacking AI systems to find weaknesses and using those findings to protect them in production. The source ties this to agentic AI, where testing must cover MCP servers, tools, and database access, not only model prompts.
Straiker BlogWelcome to the Jungle: What We Found Inside 15,465 Public MCP Servers
Oct 6, 2026MediumNewsSecurityIndustryOX Security researcher Moshe Siman Tov Bustan reports on an analysis of 15,465 publicly indexed MCP servers across 5 MCP registries, deduplicated to 5,095 unique hostnames. The study found 15.6% of hostnames resolve outside the United States, 0.45% route traffic through consumer tunneling services such as ngrok-free, and 2.3% no longer resolve, with six on expired domains that anyone can register.
The Hacker NewsCVE-2026-105741: Langflow IP spoofing bypasses local-only restriction on MCP install endpoint
Oct 5, 2026HighVulnerabilitySecurityCVE-2026-105741Langflow versions 1.5.0 through 1.10.3 contain an IP spoofing flaw in the MCP configuration installation endpoint, POST /api/v1/mcp/project/{project_id}/install. An authenticated remote attacker can send a spoofed X-Forwarded-For: 127.0.0.1 header, making the server treat the request as local and bypass the "local-only" restriction. This lets the attacker write or overwrite an MCP client configuration file on the server's filesystem.
Fix: Fixed in 1.10.3.
NVD/CVE DatabaseCVE-2026-105740: Langflow remote code execution through MCP server stdio command field
Oct 5, 2026CriticalVulnerabilitySecurityCVE-2026-105740CVE-2026-105740 affects Langflow versions prior to 1.9.0. Any authenticated user can add an MCP server with the "Stdio" transport, and the user-supplied command field is passed directly to bash -c "exec {command}" with no validation, allowlisting, or sandboxing, so the command runs on the server as soon as the server list is fetched. The env field also permits arbitrary environment variable injection, such as LD_PRELOAD or a PATH override.
Fix: Fixed in 1.9.0.
NVD/CVE DatabaseCVE-2026-105699: Langflow MCP resource read exposes other users' flow files
Oct 5, 2026HighVulnerabilitySecurityCVE-2026-105699Langflow versions from 1.6.8 through 1.9.1 fail to authorize the resource URI passed to resources/read on project-scoped MCP connections. An authenticated user with access to any project-scoped MCP endpoint can read another user's flow-backed files, including uploaded documents, structured data, prompts and other private flow artifacts. Global handle_list_resources and handle_list_tools behavior can also disclose the flow and file identifiers needed to target them. Victim files and stored flows are not modified.
Fix: Fixed in 1.9.1.
NVD/CVE DatabaseCVE-2026-105697: Langflow arbitrary command execution through MCP stdio server configuration
Oct 5, 2026CriticalVulnerabilitySecurityCVE-2026-105697CVE-2026-105697 affects Langflow before 1.10.3, where the MCP stdio transport ran whatever command and args a user placed in an MCP server configuration, with no allowlist and, before 1.10.3, wrapped in bash -c "exec {command} ...". Any user who can reach the MCP server settings (POST/PATCH /api/v2/mcp/servers/{server_name}) or build a flow with the MCP Tools component can run an arbitrary OS command on the Langflow host as the Langflow process user, when Langflow connects to the server, even if the UI then reports a startup failure. With the default LANGFLOW_AUTO_LOGIN=true, GET /api/v1/auto_login issues a token without credentials, so the flaw is reachable without an account on an exposed default instance; with AUTO_LOGIN disabled, any authenticated non-admin user can exploit it.
Fix: Fixed in Langflow 1.10.3, langflow-base 0.10.3, and lfx 1.10.3.
NVD/CVE DatabaseGHSA-p23f-cm6q-2qp8: SiYuan MCP asset.upload Reads Arbitrary Absolute File Paths (Workspace Boundary Bypass)
Oct 2, 2026MediumVulnerabilitySecuritySiYuan's MCP tool `asset.upload` accepts a comma-separated `files` list of absolute paths and performs no workspace boundary or sensitive-path check before `model.InsertLocalAssets` opens each file and copies it into the workspace `assets/` directory. An attacker who can steer the AI Agent through prompt injection could make it upload files such as `~/.ssh/id_rsa` into the workspace, where they become reachable. Affected versions are `<= 3.8.0`, and the issue is a residual gap from the remediation of CVE-2026-66012.
Fix: Fixed in 3.8.1.
GitHub Advisory DatabaseGHSA-c9xm-49cp-xcr9: rmcp OAuth client fetches server-controlled resource_metadata URLs
Oct 2, 2026MediumVulnerabilitySecurityThe rmcp OAuth client in modelcontextprotocol/rust-sdk takes a resource_metadata URL from the server-controlled WWW-Authenticate header and fetches it without same-origin or private-network checks. A malicious or compromised MCP server can point the client at localhost, RFC 1918 addresses or cloud metadata endpoints, making the victim application send outbound GET requests from its own network context.
GitHub Advisory DatabaseCVE-2025-71427: Office-PowerPoint-MCP-Server path traversal in file read and write
Oct 1, 2026MediumVulnerabilitySecurityCVE-2025-71427CVE-2025-71427 affects Office-PowerPoint-MCP-Server through 2.0.7. A path traversal flaw lets MCP callers read and write files outside the working directory by supplying absolute paths or ../ sequences. An attacker can steer an AI agent via prompt injection to abuse save_presentation, open_presentation, or manage_image output_path to overwrite any server-writable file or load external files.
NVD/CVE DatabaseCVE-2026-97662 - Argument injection in AWS security-agent-mcp-server diff scan
Oct 1, 2026HighVulnerabilitySecurityCVE-2026-97662 is an argument injection flaw in the diff scan operation of security-agent-mcp-server, an open-source MCP server published by AWS in the awslabs/mcp repository. Affected versions are 0.1.1 up to but not including 0.2.0. A crafted reference value is parsed as a command-line option instead of a revision, letting a context-dependent actor create, overwrite, or truncate arbitrary files on the host outside the workspace directory and bypass the server's workspace-confinement control.
AWS Security BulletinsCVE-2026-96561: AI Engine WordPress plugin stored cross-site scripting via chat REST endpoint
Oct 1, 2026HighVulnerabilitySecurityCVE-2026-96561The AI Engine plugin for WordPress, up to and including 3.8.0, contains a stored cross-site scripting flaw. An unauthenticated attacker can send crafted input to the /mwai-ui/v1/chats/submit REST endpoint, which writes an attacker-controlled string into the PHP error log as a forged line. The plugin's Advisor feature then passes that content into an AI prompt and stores the result unescaped, so the injected script runs when an administrator opens the WordPress dashboard.
NVD/CVE DatabaseSecurity threat modeling for emerging AI-agent protocols: A comparative analysis of MCP, A2A, agora, and ANP
Sep 29, 2026InfoResearchPeer-reviewedSecurityResearchThe source is a December 2026 article in the Journal of Information Security and Applications (Volume 103) by Zeynab Anbiaee, Mahdi Rabbani, Mansur Mirani, Gunjan Piya, Igor Opushnyev, Ali Ghorbani and Sajjad Dadkhah. Its title indicates a comparative security threat modeling analysis of the MCP, A2A, agora and ANP AI-agent protocols. The provided text contains only publication metadata, so no findings or methods are available to report.
Elsevier Security JournalsOfficial MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials
Sep 29, 2026MediumNewsSecurityIndustryA malicious MCP server can trick applications built on the official MCP Python SDK into sending their OAuth client secret, authorization code, and PKCE proof key to a token endpoint the attacker controls. Affected versions are 1.9.1 through 1.29.1 and 2.0.0 through 2.1.1, and the flaw is rated 7.5 for non-interactive providers and 6.5 for the interactive provider. Cycode reported the issue, and no CVE had been assigned as of September 29, 2026.
Fix: Upgrade to 1.30.0 on the 1.x line or 2.2.0 on the 2.x line. For ClientCredentialsOAuthProvider and PrivateKeyJWTOAuthProvider, also pass issuer= to name the login service the credentials belong to, since upgrading alone does not fix those providers. Replace the deprecated RFC7523OAuthClientProvider, which has no issuer= option, with one of the other providers. After upgrading, clear stored OAuth client registrations once. If a client may have connected to an untrusted server, rotate its client secret and revoke its tokens at the login service. On older versions, connect only to MCP servers you trust.
The Hacker NewsCVE-2026-55157: Token Optimizer MCP OS command injection through smart_user username argument
Sep 28, 2026HighVulnerabilitySecurityCVE-2026-55157Prior to version 5.1.0, token-optimizer-mcp is vulnerable to OS command injection in the smart_user tool. Any MCP client that can call smart_user can run arbitrary shell commands through the username argument of the get-user-info operation, with the privileges of the user running the server.
Fix: This issue has been patched in version 5.1.0.
NVD/CVE DatabaseCVE-2026-55156: Token Optimizer MCP dashboard path traversal via sessionId in session endpoints
Sep 28, 2026MediumVulnerabilitySecurityCVE-2026-55156Token Optimizer MCP versions before 5.1.0 run a dashboard HTTP server whose /api/session-summary and /api/session-events endpoints have no authentication middleware. Both handlers join the caller-supplied sessionId query parameter into a filesystem path with path.join, and Node.js normalizes .. segments, so an unauthenticated network client can read any .jsonl file the server can access.
Fix: This issue has been patched in version 5.1.0.
NVD/CVE Database
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.