Model Context Protocol
The Model Context Protocol and the servers and clients that expose tools and data to models through it.
- All items
- 295
- Last 90 days
- 133
- Change
- +53%vs 87 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 2 |
| Jun 2025 | 4 |
| Jul 2025 | 4 |
| Aug 2025 | 7 |
| Sep 2025 | 3 |
| Oct 2025 | 3 |
| Nov 2025 | 2 |
| Dec 2025 | 4 |
| Jan 2026 | 4 |
| Feb 2026 | 12 |
| Mar 2026 | 22 |
| Apr 2026 | 27 |
| May 2026 | 31 |
| Jun 2026 | 25 |
| Jul 2026 | 43 |
| Aug 2026 | 45 |
| Sep 2026 | 40 |
| Oct 2026 | 16 |
295 items
GHSA-jwp7-wg77-3w9v: Apify Model Context Protocol (MCP) server: Domain Allowlist Bypass in fetch-apify-docs via String Prefix Matching
May 19, 2026MediumVulnerabilitySecurityCVE-2026-46341The fetch-apify-docs tool in the Apify Model Context Protocol (MCP) server checks URLs against a domain allowlist with String.startsWith() instead of comparing hostnames. An attacker can use a URL such as https://docs.apify.com.evil.com/ to pass the check and have the tool return attacker-controlled page content to the LLM. The advisory notes this enables prompt injection and can direct the LLM to use a victim's _meta.apifyToken in call-actor invocations.
GitHub Advisory DatabaseGHSA-4gph-2hhr-5mwg: Envoy AI Proxy - MCP Message Smuggling Vulnerability
May 19, 2026MediumVulnerabilitySecurityEnvoy AI Gateway's MCP proxy parses JSON-RPC 2.0 messages case-insensitively, contrary to the MCP-mandated case-sensitive matching, via `jsonrpc.DecodeMessage` in `github.com/modelcontextprotocol/go-sdk` and the `internal/json` wrapper around `github.com/bytedance/sonic`. An attacker can send a message with a case-variant `Name` field alongside `name`, and the gateway re-serializes it with the injected value, so the upstream backend receives a different tool call (e.g. `backend__secretTool` instead of `backend__greet`), potentially bypassing authorization checks applied earlier.
GitHub Advisory DatabaseGHSA-hv85-774v-26fg: auth-fetch-mcp: SSRF and disk exfiltration via unvalidated auth_fetch and download_media URLs
May 19, 2026HighVulnerabilitySecurityThe download_media and auth_fetch tools in ymw0407/auth-fetch-mcp accept arbitrary URLs and request them from the MCP server process without validating the destination. An MCP client can therefore reach loopback, link-local and private-range hosts, and download_media additionally writes the response body to a user-controlled output directory.
GitHub Advisory DatabaseGHSA-jxx9-px88-pj69: n8n-MCP: Multi-tenant MCP requests fall back to process-level n8n credentials when tenant headers are absent or incomplete
May 18, 2026HighVulnerabilitySecurityCVE-2026-45707When ENABLE_MULTI_TENANT=true, n8n-mcp's HTTP transport selects the target n8n instance from the x-n8n-url and x-n8n-key headers, but requests missing one or both headers silently fell back to the operator's process-level N8N_API_URL and N8N_API_KEY. An authenticated MCP tenant could therefore run n8n management calls against the operator's own instance, with possible escalation to remote code execution where Code-node execution reaches OS-level modules. Single-tenant deployments are not affected.
Fix: Fixed in n8n-mcp 2.51.2, which rejects header-less multi-tenant requests with HTTP 400 / JSON-RPC -32602 and refuses to construct an env-credential n8n API client when ENABLE_MULTI_TENANT=true. Upgrade with `npx n8n-mcp@latest` or `docker pull ghcr.io/czlonkowski/n8n-mcp:latest`. Workarounds: set ENABLE_MULTI_TENANT=false and run a separate instance per tenant with its own credentials; require both x-n8n-url and x-n8n-key at a proxy (partial mitigation only); or scope the operator's N8N_API_KEY to the minimum required permissions.
GitHub Advisory DatabaseGHSA-m99r-2hxc-cp3q: Flowise has an MCP Security Bypass that Enables RCE
May 14, 2026HighVulnerabilitySecurityFlowise's MCP feature contains a security bypass chain that lets an attacker run arbitrary commands on the host. The validateCommandFlags blocklist in packages/components/nodes/tools/MCP/core.ts omits docker build, so a Custom MCP Server configured as docker build <remote-URL> pulls and runs a remote Dockerfile. A second bypass uses the long alias --yes, which is not blocked for npx, letting npx install and execute an attacker-supplied npm package. The attacker needs a Flowise account of any role or an API key with view and update permissions for chatflows, and the server must have the docker or npx command available.
GitHub Advisory DatabaseSweet Security Launches Agentic AI Red Teaming to Counter ‘Mythos Moment’
May 13, 2026InfoNewsSecurityIndustrySweet Security has launched Sweet Attack, an agentic AI red teaming product that runs continuous automated attack testing. The agent reasons over a runtime index of each client's own infrastructure, including topology, identity paths and deployed source code, rather than generic models. It also discovers shadow IT and shadow AI components such as MCP servers, and reevaluates attack paths when new components appear.
SecurityWeekCVE-2026-43992: JunoClaw MCP write tools expose BIP-39 mnemonic in LLM tool-call parameters
May 12, 2026CriticalVulnerabilitySecurityPrivacyCVE-2026-43992CVE-2026-43992 affects JunoClaw, an agentic AI platform built on Juno Network, prior to 0.x.y-security-1. Every MCP write tool, including send_tokens, execute_contract, instantiate_contract, upload_wasm and ibc_transfer, accepted 'mnemonic: string' as an explicit tool-call parameter. As a result, the BIP-39 seed was embedded in the LLM tool-call JSON and exposed to any transport, log or telemetry surface between the LLM provider and the MCP process.
Fix: This vulnerability is fixed in 0.x.y-security-1.
NVD/CVE DatabaseCVE-2026-43989: JunoClaw upload_wasm MCP tool accepts unvalidated filesystem paths
May 12, 2026HighVulnerabilitySecurityCVE-2026-43989CVE-2026-43989 affects JunoClaw, an agentic AI platform built on Juno Network, prior to 0.x.y-security-1. The upload_wasm MCP tool accepted a filesystem path from the agent and uploaded whatever bytes that path resolved to, without validating location, symlink target, file size, or file format. The flaw is classified as CWE-20, CWE-22, CWE-59 and CWE-73.
Fix: Fixed in 0.x.y-security-1.
NVD/CVE DatabaseWhy Agentic AI Is Security's Next Blind Spot
May 12, 2026InfoNewsSecurityIndustryThe article argues that security teams lack fluency in agentic AI, which is already running in production across many organizations, and that this gap is widening. It describes three agent categories: general-purpose coding agents such as Claude Code and GitHub Copilot, vendor-built agents using the Model Context Protocol (MCP), and custom agents built by individual users. It illustrates MCP risk with a malicious calendar invite whose hidden instructions an agent reads and executes.
The Hacker News1,800+ MCP servers exposed without authentication: How zero trust can secure the AI agent revolution
May 11, 2026MediumNewsSecurityIndustryKnostic researchers found 1,862 MCP servers exposed to the public internet, and in a manual check of 119 instances every one allowed unauthenticated access to internal tool listings. Some exposed production systems had write access to financial databases, social media accounts and CRM platforms. The article also covers EchoLeak (CVE-2025-32711), a zero-click exploit disclosed by Aim Security in June 2025, and CVE-2025-6514 in the mcp-remote package, which JFrog disclosed in July 2025.
CSO OnlineCVE-2026-44284: FastGPT SSRF through stored internal MCP tool server URLs
May 8, 2026MediumVulnerabilitySecurityCVE-2026-44284FastGPT, an AI Agent building platform, prior to version 4.14.17, let authenticated users who can create or manage MCP toolsets save an internal MCP server URL, such as http://localhost:3000/mcp, through the MCP tool create and update endpoints. The direct MCP preview and run endpoints already rejected internal or private network URLs, so the protection was inconsistent. Later workflow execution used the stored URL without revalidating the destination, letting the FastGPT backend workflow runner connect to that internal destination.
Fix: Fixed in 4.14.17.
NVD/CVE DatabaseGHSA-8g7g-hmwm-6rv2: n8n-mcp affected by path traversal, redirect-following SSRF, and telemetry payload exposure
May 8, 2026HighVulnerabilitySecurityn8n-mcp versions before 2.50.1 contain three independently reported issues in deployments that use the n8n API integration. An authenticated MCP caller can supply crafted identifiers that the n8n API client uses as URL path segments, sending the configured n8n API key to other same-origin endpoints and bypassing handler-level controls including DISABLED_TOOLS. Validated webhook, form and chat trigger URLs also follow redirects, returning the response body to the caller, and default opt-in telemetry uploads unredacted operation payloads that can contain bearer tokens, API keys and webhook secrets. CVSS 8.3 (HIGH); exploitation requires an authenticated MCP caller and a configured n8n API key.
Fix: Upgrade to n8n-mcp >= 2.50.1. Workarounds: for the first two issues, restrict network access to the HTTP transport (firewall, reverse-proxy ACL or VPN) or switch to stdio mode; for the telemetry issue, set N8N_MCP_TELEMETRY_DISABLED=true before starting the server or run `npx n8n-mcp telemetry disable` once.
GitHub Advisory DatabaseGHSA-cmrh-wvq6-wm9r: n8n-mcp webhook and API client paths has an authenticated SSRF
May 8, 2026HighVulnerabilitySecurityIndustryCVE-2026-44694Authenticated server-side request forgery in n8n-mcp affects the webhook trigger tools, the n8n API client via N8N_API_URL, and per-request URLs supplied in the x-n8n-url header in multi-tenant HTTP mode. A caller with an MCP session can make the n8n-mcp host send requests to internal services and cloud metadata endpoints, and the response body is returned to the caller. Fixed in n8n-mcp@2.50.2.
Fix: Fixed in `n8n-mcp@2.50.2`. Operators whose N8N_API_URL points at localhost or a private address should set WEBHOOK_SECURITY_MODE to moderate (allows localhost, still blocks RFC1918 and cloud metadata) or permissive (also allows RFC1918, only safe on a trusted private network); the default strict applies where n8n is on a public hostname. Workarounds for deployments that cannot upgrade: restrict network egress from the host and deny cloud metadata IPs (169.254.169.254, 169.254.170.2, 100.100.100.200, 192.0.0.192, and the GCP metadata.google.internal resolved IP) and RFC1918 networks; run in stdio mode instead of HTTP; or set DISABLED_TOOLS=n8n_trigger_webhook_workflow,n8n_create_workflow,n8n_test_workflow.
GitHub Advisory DatabaseYour CTEM program is probably ignoring MCP. Here’s how to fix it
May 8, 2026LowNewsSecurityIndustryThe article argues that Model Context Protocol (MCP) servers and shadow AI are a blind spot for security programs, and that integrating MCP risks into a Continuous Threat Exposure Management (CTEM) program can help teams surface exposures. It cites a 2025 malicious npm package, postmark-mcp, which shipped a version that BCC'd outgoing emails to an external address and affected around 300 organizations.
CSO OnlineCVE-2026-42271: LiteLLM command execution through MCP test endpoints
May 8, 2026CriticalVulnerabilitySecurityCVE-2026-42271EPSS: 92.6%Actively ExploitedLiteLLM versions from 1.74.2 up to, but not including, 1.83.7 expose two endpoints, POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list, that accept a full MCP server configuration including the stdio transport's command, args and env fields. Any holder of a valid proxy API key, including low-privilege internal-user keys, can make these endpoints spawn an arbitrary command as a subprocess on the proxy host with the proxy process's privileges, because no role check gates them.
Fix: Fixed in 1.83.7.
NVD/CVE DatabaseClaude Code OAuth Tokens Can Be Stolen Through Stealthy MCP Hijacking
May 7, 2026MediumNewsSecurityIndustryMitiga Labs reported that a tailored npm package can redirect Claude Code MCP traffic through an attacker's proxy, exposing OAuth tokens stored in plain text in ~/.claude.json. The attack requires installing the package on a machine where Claude Code is configured with dynamic authorization MCP servers, and the post-install hook persists across token rotation. Mitiga reported the issue to Anthropic on April 10, 2026, and Anthropic replied on April 12, 2026 that it was out of scope.
SecurityWeekAutomatic Red Teaming LLM-Based Agents With Model Context Protocol Tools
May 7, 2026InfoResearchPeer-reviewedSecurityResearchResearchers present AutoMalTool, an automated red teaming framework that generates malicious MCP tools to test LLM-based agents. The authors argue that prior tool poisoning studies stayed at the proof-of-concept stage, leaving automatic red teaming open. Their evaluation reports that AutoMalTool produces malicious MCP tools that steer mainstream LLM-based agents toward unintended behavior while evading current detection mechanisms.
IEEE Xplore (Security & AI Journals)GHSA-89vp-x53w-74fx: rmcp Streamable HTTP server transport has a DNS rebinding vulnerability
May 6, 2026HighVulnerabilitySecurityCVE-2026-42559Prior to version 1.4.0, the rmcp crate's Streamable HTTP server transport did not validate the incoming Host header, so a malicious public website using a DNS rebinding attack could send authenticated requests to a local or private-network MCP server. An attacker could enumerate and invoke exposed tools and read resources, and because MCP servers often run with the user's privileges, the impact can extend to arbitrary code execution on the victim's machine.
Fix: Fixed in rmcp 1.4.0 (PR #764, commit 8e22aa2): StreamableHttpServerConfig::allowed_hosts now defaults to a loopback-only allowlist, and requests whose Host header is not on the allowlist receive HTTP 403. Upgrade to rmcp >= 1.4.0. If upgrade is not possible, place the MCP server behind a reverse proxy configured to reject requests whose Host header is not an expected hostname, and do not bind the server to 0.0.0.0 without such a proxy.
GitHub Advisory DatabaseMicrosoft named an overall leader in KuppingerCole Analyst’s 2026 Emerging AI Security Operations Center (SOC) report
May 6, 2026InfoNewsIndustrySecurityMicrosoft was named an Overall Leader and Market Leader in KuppingerCole Analysts' 2026 Emerging AI Security Operations Center (SOC) report. The report argues that SOC effectiveness now depends on intelligence-driven automation rather than alert volume. Microsoft cites Automatic attack disruption, a Phishing triage agent, AI powered incident prioritization, and a Playbook generator, along with the Microsoft Sentinel MCP (Model Context Protocol) Server.
Microsoft Security BlogGHSA-fj4g-2p96-q6m3: Network-AI missing authentication on MCP HTTP endpoint, which allows unauthenticated privileged tool calls
May 5, 2026HighVulnerabilitySecurityCVE-2026-42856Network-AI version 5.1.2 (commit c344f2053eb0d49395988f803bf92f2a86b2a0d0) accepts JSON-RPC tools/call requests on its MCP HTTP transport with no authentication, session, origin or token check, dispatching them straight to the orchestrator's tool registry. The default bind address is 0.0.0.0, so any party with network reachability can list and invoke privileged tools such as config_get and config_set, agent_spawn, token_create and budget_set_ceiling. The advisory is rated High (CWE-306) and was validated on 2026-04-21 with a proof of concept that changed a live configuration value without credentials.
GitHub Advisory Database
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.