Model Context Protocol
The Model Context Protocol and the servers and clients that expose tools and data to models through it.
- All items
- 295
- Last 90 days
- 133
- Change
- +56%vs 85 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 2 |
| Jun 2025 | 4 |
| Jul 2025 | 4 |
| Aug 2025 | 7 |
| Sep 2025 | 3 |
| Oct 2025 | 3 |
| Nov 2025 | 2 |
| Dec 2025 | 4 |
| Jan 2026 | 4 |
| Feb 2026 | 12 |
| Mar 2026 | 22 |
| Apr 2026 | 27 |
| May 2026 | 31 |
| Jun 2026 | 25 |
| Jul 2026 | 43 |
| Aug 2026 | 45 |
| Sep 2026 | 40 |
| Oct 2026 | 16 |
198 items
CVE-2026-0621: Anthropic MCP TypeScript SDK ReDoS in UriTemplate array pattern matching
Jan 5, 2026HighVulnerabilitySecurityCVE-2026-0621Anthropic's MCP TypeScript SDK, versions up to and including 1.25.1, contains a regular expression denial of service (ReDoS) flaw (CVE-2026-0621) in the UriTemplate class when it processes RFC 6570 exploded array patterns. The dynamically generated regular expression contains nested quantifiers that can cause catastrophic backtracking on crafted input, driving CPU use up. An attacker who supplies a malicious URI can make the Node.js process unresponsive.
NVD/CVE DatabaseGHSA-rcfx-77hg-w2wv: FastMCP updated to MCP 1.23+ due to CVE-2025-66416
Dec 26, 2025HighVulnerabilitySecurityGHSA-rcfx-77hg-w2wv concerns FastMCP, which does not use the affected components of the MCP SDK directly. However, FastMCP versions prior to 2.14.0 allowed MCP SDK versions below 1.23, which are vulnerable to CVE-2025-66416.
Fix: Upgrade to FastMCP 2.14.0 or later.
GitHub Advisory DatabaseCVE-2025-66404: MCP Server Kubernetes command injection in exec_in_pod tool
Dec 3, 2025MediumVulnerabilitySecurityCVE-2025-66404CVE-2025-66404 affects the exec_in_pod tool in mcp-server-kubernetes, an MCP Server that connects to and manages Kubernetes clusters, in versions prior to 2.9.8. When the tool receives a command as a string, it is passed directly to sh -c without input validation, so shell metacharacters are interpreted. Exploitation can occur through direct command injection or through indirect prompt injection, where AI agents may run commands without explicit user intent.
Fix: Fixed in 2.9.8.
NVD/CVE DatabaseGHSA-9h52-p55h-vw2f: Model Context Protocol (MCP) Python SDK does not enable DNS rebinding protection by default
Dec 2, 2025HighVulnerabilitySecurityCVE-2025-66416The Model Context Protocol (MCP) Python SDK did not enable DNS rebinding protection by default for HTTP-based servers. A malicious website could exploit DNS rebinding to send requests to an unauthenticated HTTP MCP server running on localhost that was built with FastMCP using streamable HTTP or SSE transport and without TransportSecuritySettings, invoking its tools or accessing its resources on the user's behalf. Servers using stdio transport are not affected.
Fix: Fixed in 1.23.0: FastMCP() servers now enable DNS rebinding protection by default when host is 127.0.0.1 or localhost. Users with custom low-level configurations using StreamableHTTPSessionManager or SseServerTransport directly should explicitly configure TransportSecuritySettings when running an unauthenticated server on localhost.
GitHub Advisory DatabaseGHSA-w48q-cv73-mx4w: Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
Dec 2, 2025HighVulnerabilitySecurityCVE-2025-66414The Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default for HTTP-based servers. When such a server runs on localhost without authentication, using StreamableHTTPServerTransport or SSEServerTransport without enableDnsRebindingProtection enabled, a malicious website could bypass same-origin policy restrictions and invoke tools or access resources on the user's behalf. The issue does not affect servers using stdio transport.
Fix: Servers created via createMcpExpressApp() now have this protection enabled by default when binding to localhost. Users with custom Express configurations are advised to update to version 1.24.0 and apply the exported hostHeaderValidation() middleware when running an unauthenticated server on localhost.
GitHub Advisory DatabaseGHSA-c2jp-c369-7pvx: FastMCP Auth Integration Allows for Confused Deputy Account Takeover
Oct 29, 2025HighVulnerabilitySecurityFastMCP's Entra ID integration, as documented, makes the MCP server act as both an OAuth client to Entra ID and an authorization server to MCP clients, with its own `/authorize`, `/token` and `/register` endpoints. The reported issue is a confused deputy scenario that can lead to account takeover, though the source text provided is truncated before the attack details are stated.
GitHub Advisory DatabaseCVE-2025-61591: Cursor command injection via MCP OAuth with untrusted server
Oct 3, 2025HighVulnerabilitySecurityCVE-2025-61591CVE-2025-61591 affects Cursor, a code editor built for programming with AI, in versions 1.7 and below. When MCP uses OAuth authentication with an untrusted MCP server, an attacker can impersonate that server and return crafted commands during interaction, enabling command injection. Chained with an untrusted MCP service via OAuth, the flaw could let the agent execute arbitrary code on the host with full user privileges.
Fix: This issue does not currently have a fixed release version, but there is a patch, 2025.09.17-25b418f.
NVD/CVE DatabaseCVE-2025-61590: Cursor remote code execution through Visual Studio Code workspaces
Oct 3, 2025HighVulnerabilitySecurityCVE-2025-61590Cursor versions 1.6 and below are vulnerable to remote code execution through Visual Studio Code workspace files. An attacker who hijacks the victim's chat context, for example via a compromised MCP server, can use prompt injection to make the Cursor Agent write to a .code-workspace file. This bypasses the fix for CVE-2025-54130 by modifying workspace settings, which leads to RCE.
Fix: Fixed in version 1.7.
NVD/CVE DatabaseCVE-2025-59417: Lobe Chat cross-site scripting in chat messages via SVG artifacts
Sep 18, 2025MediumVulnerabilitySecurityCVE-2025-59417Lobe Chat versions prior to 1.129.4 contain a cross-site scripting flaw in chat message handling. When a server response includes a lobeArtifact tag with type image/svg+xml, the SVGRender component inserts the content through dangerouslySetInnerHTML, enabling XSS that can be escalated to remote code execution on the user's machine. Anyone able to inject content into chat messages, such as through a malicious page used for prompt injection, a compromised MCP server, or tool integrations, can exploit it.
Fix: Fixed in 1.129.4.
NVD/CVE DatabaseCVE-2025-58357: 5ire content injection through chat page script gadgets
Sep 4, 2025CriticalVulnerabilitySecurityCVE-2025-58357CVE-2025-58357 affects 5ire, a cross-platform desktop AI assistant and model context protocol client, in version 0.13.2. The chat page's script gadgets enable content injection attacks through malicious prompt injection pages, compromised MCP servers, and exploited tool integrations. The source does not state the attacker's resulting impact.
Fix: Fixed in version 0.14.0.
NVD/CVE DatabaseCVE-2025-54424: 1Panel remote code execution via incomplete certificate verification
Aug 1, 2025HighVulnerabilitySecurityCVE-2025-544241Panel, a web interface and MCP Server for managing websites, files, containers, databases and LLMs on Linux servers, is affected through versions 2.0.5 and below. Its HTTPS communication between the Core and Agent endpoints does not fully verify certificates, which allows unauthorized access to interfaces. Because 1Panel exposes many command execution and high-privilege interfaces, this leads to Remote Code Execution.
Fix: Fixed in version 2.0.6.
NVD/CVE DatabaseGHSA-3qhf-m339-9g5v: MCP Python SDK vulnerability in the FastMCP Server causes validation error, leading to DoS
Jul 4, 2025HighVulnerabilitySecurityCVE-2025-53366A validation error in the MCP Python SDK can cause an unhandled exception when it processes malformed requests. The result is service unavailability, returning 500 errors until the server is manually restarted. Impact depends on deployment conditions and any infrastructure-level resilience measures in place.
GitHub Advisory DatabaseGHSA-j975-95f5-7wqh: MCP Python SDK has Unhandled Exception in Streamable HTTP Transport, Leading to Denial of Service
Jul 4, 2025HighVulnerabilitySecurityCVE-2025-53365The MCP Python SDK's streamable HTTP transport has an unhandled exception. A client that deliberately triggers an exception after establishing a streamable HTTP session can cause an uncaught ClosedResourceError on the server. The server then crashes and needs a restart to restore service. Impact depends on deployment conditions and any infrastructure-level resilience measures.
GitHub Advisory DatabaseCVE-2025-34072: Anthropic Slack MCP Server data exfiltration via automatic link unfurling
Jul 2, 2025HighVulnerabilitySecurityPrivacyCVE-2025-34072CVE-2025-34072 is a data exfiltration flaw in Anthropic's deprecated Slack Model Context Protocol (MCP) Server, reached through automatic link unfurling. When an AI agent using the server processes untrusted data, it can be manipulated into posting messages with attacker-crafted hyperlinks that embed sensitive data. Slack's link preview bots (Slack-LinkExpanding, Slackbot, Slack-ImgProxy) then request the attacker-controlled URL, leaking private data with no user interaction.
NVD/CVE DatabaseCVE-2025-53107: @cyanheads/git-mcp-server command injection via unsanitized input
Jul 1, 2025HighVulnerabilitySecurityCVE-2025-53107EPSS: 24.5%@cyanheads/git-mcp-server, an MCP server for Git repositories, prior to version 2.1.5 has a command injection flaw. Unsanitized input parameters are passed into a child_process.exec call, so an attacker can inject shell metacharacters such as |, >, and && to run arbitrary system commands with the server process's privileges, potentially leading to remote code execution. An MCP client can also be steered into this through indirect prompt injection when asked to read git logs.
Fix: This issue has been patched in version 2.1.5.
NVD/CVE DatabaseCVE-2025-53098: Roo Code arbitrary command execution via MCP configuration file writes
Jun 27, 2025HighVulnerabilitySecurityCVE-2025-53098Roo Code, an AI-powered autonomous coding agent, stored project-specific MCP configuration in `.roo/mcp.json` within the VS Code workspace. Before version 3.20.3, an attacker who could submit prompts to the agent could have it write a malicious command into that file, leading to arbitrary command execution if the user had enabled auto-approved file writes.
Fix: Fixed in 3.20.3, which adds an additional opt-in configuration layer for auto-approving writes to Roo's configuration files, including all files within the `.roo/` folder.
NVD/CVE DatabaseCVE-2025-52573: iOS Simulator MCP Server command injection through ui_tap tool
Jun 26, 2025MediumVulnerabilitySecurityCVE-2025-52573iOS Simulator MCP Server (ios-simulator-mcp) versions prior to 1.3.3 are vulnerable to command injection through the `ui_tap` tool, which passes LLM-supplied `duration`, `udid`, `x` and `y` arguments into Node.js `exec`. Shell meta-characters in these inputs, which prompt injection can induce, let an attacker run arbitrary commands on the host running the MCP server. Tracked as CVE-2025-52573.
Fix: Fixed in version 1.3.3, which contains a patch for the issue.
NVD/CVE DatabaseCVE-2025-5277: aws-mcp-server command injection via crafted prompts
May 28, 2025CriticalVulnerabilitySecurityCVE-2025-5277CVE-2025-5277 affects the aws-mcp-server MCP server, which is vulnerable to command injection under CWE-78. An attacker can craft a prompt that, once accessed by the MCP client, runs arbitrary commands on the host system. Snyk scored it CVSS 4.0 9.4 (Critical) with no user privileges required and user interaction required; NIST had not yet provided an assessment.
NVD/CVE Database
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.