Model Context Protocol
The Model Context Protocol and the servers and clients that expose tools and data to models through it.
- All items
- 295
- Last 90 days
- 133
- Change
- +53%vs 87 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 2 |
| Jun 2025 | 4 |
| Jul 2025 | 4 |
| Aug 2025 | 7 |
| Sep 2025 | 3 |
| Oct 2025 | 3 |
| Nov 2025 | 2 |
| Dec 2025 | 4 |
| Jan 2026 | 4 |
| Feb 2026 | 12 |
| Mar 2026 | 22 |
| Apr 2026 | 27 |
| May 2026 | 31 |
| Jun 2026 | 25 |
| Jul 2026 | 43 |
| Aug 2026 | 45 |
| Sep 2026 | 40 |
| Oct 2026 | 16 |
295 items
GHSA-537j-gqpc-p7fq: n8n Vulnerable to XSS via MCP OAuth client
Apr 29, 2026HighVulnerabilitySecurityCVE-2026-42235An unauthenticated attacker can register a malicious MCP OAuth client with a crafted client_name. When a second user revokes access after a victim authorized the OAuth consent dialog, a toast notification renders the injected script. Clicking the link runs arbitrary JavaScript in the victim's authenticated n8n browser session, enabling credential and session token theft, workflow manipulation, or privilege escalation.
Fix: Fixed in n8n version 2.14.2; users should upgrade to this version or later. Until then, administrators should consider restricting access to the n8n instance and the MCP OAuth registration endpoint to trusted users only, and disabling MCP server functionality if it is not actively required. The source states these workarounds do not fully remediate the risk and are only short-term measures.
GitHub Advisory DatabaseGHSA-49m9-pgww-9vq6: n8n Vulnerable to Unauthenticated Denial of Service via MCP Client Registration
Apr 29, 2026HighVulnerabilitySecurityCVE-2026-42236The MCP OAuth client registration endpoint in n8n accepted unauthenticated requests and stored client data without adequate resource controls. A remote attacker can exhaust server memory with large registration payloads, making the instance unavailable, and the endpoint remains reachable even when MCP is disabled.
Fix: Fixed in n8n 1.123.32, 2.17.4, and 2.18.1; upgrade to one of these versions or later. If upgrading is not immediately possible, restrict network access to the n8n instance to untrusted sources and lower the N8N_PAYLOAD_SIZE_MAX environment variable from its default value. These workarounds do not fully remediate the risk and are short-term measures only.
GitHub Advisory DatabaseGHSA-f6x8-65q6-j9m9: n8n has Open Redirect in MCP OAuth Consent Flow
Apr 29, 2026MediumVulnerabilitySecurityCVE-2026-42230n8n's `/mcp-oauth/register` endpoint accepts OAuth client registrations without authentication, so arbitrary `redirect_uri` values can be registered. When a user clicks Deny on the MCP OAuth consent dialog, the `handleDeny` handler redirects them to that registered URI without validation, creating an open redirect. An attacker can send a phishing link that silently sends a victim to an external site after they deny consent.
Fix: Fixed in n8n 1.123.32, 2.17.4, and 2.18.1. Upgrade to one of these versions or later. If upgrading is not immediately possible, restrict network access to the n8n instance so untrusted users cannot reach the MCP OAuth endpoints, and limit access to fully trusted users only. The source states these workarounds do not fully remediate the risk and are short-term measures only.
GitHub Advisory DatabaseGHSA-wg4g-395p-mqv3: n8n-MCP: Sensitive MCP tool-call arguments logged on authenticated requests in HTTP mode
Apr 25, 2026MediumVulnerabilitySecurityPrivacyIn HTTP transport mode, n8n-mcp versions v2.47.12 and earlier wrote full MCP tools/call arguments and JSON-RPC params to server logs for authenticated requests, before redaction. When a call carried credentials, such as through n8n_manage_credentials.data, the raw values could be persisted in logs, exposing bearer tokens, OAuth credentials, API keys and webhook auth headers to anyone with access to collected or forwarded logs. The issue requires a valid AUTH_TOKEN, and the stdio transport is not affected in practice.
Fix: Fixed in v2.47.13 (npm: npx n8n-mcp@latest or >= 2.47.13; Docker: ghcr.io/czlonkowski/n8n-mcp:latest). Interim workarounds: restrict access to the HTTP port, restrict access to server logs, or switch to stdio transport (MCP_MODE=stdio).
GitHub Advisory DatabaseGHSA-v4p8-mg3p-g94g: LiteLLM: Authenticated command execution via MCP stdio test endpoints
Apr 25, 2026HighVulnerabilitySecurityLiteLLM's two MCP preview endpoints, POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list, accepted full server configurations including command, args and env for the stdio transport. Calling them with a stdio configuration spawned the supplied command as a subprocess on the proxy host with the proxy process's privileges. Because the endpoints checked only for a valid proxy API key and no role, any authenticated user, including low-privilege internal-user keys, could run arbitrary commands on the host.
Fix: Fixed in 1.83.7. Both test endpoints now require the PROXY_ADMIN role. If upgrading is not immediately possible, block POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list at the reverse proxy or API gateway.
GitHub Advisory DatabaseGHSA-pfm2-2mhg-8wpx: n8n-MCP Logs Sensitive Request Data on Unauthorized /mcp Requests
Apr 23, 2026MediumVulnerabilitySecurityCVE-2026-41495Versions 2.47.10 and earlier of n8n-mcp, when run in HTTP transport mode, wrote request metadata for incoming POST /mcp requests to server logs even when authentication failed. Sensitive values from those rejected requests, including bearer tokens from the Authorization header, per-tenant x-n8n-key API keys, and JSON-RPC payloads, could therefore be persisted and exposed to anyone with access to collected logs. Access control itself was not bypassed, since unauthenticated requests received 401 Unauthorized, and the stdio transport is not affected.
Fix: Fixed in v2.47.11 (npm: npx n8n-mcp@latest or >= 2.47.11; Docker: ghcr.io/czlonkowski/n8n-mcp:latest). Workarounds: restrict network access to the HTTP port with a firewall, reverse proxy, or VPN, or switch to stdio transport (MCP_MODE=stdio).
GitHub Advisory DatabaseCVE-2026-40933: Flowise command execution through Custom MCP stdio server configuration
Apr 21, 2026CriticalVulnerabilitySecurityCVE-2026-40933Flowise versions prior to 3.1.0 contain a flaw in the MCP adapter's serialization of stdio commands. An authenticated user can add an MCP stdio server through the "Custom MCP" configuration with an arbitrary command, bypassing validateCommandInjection and validateArgsForLocalFileAccess by pairing an allowed command such as "npx" with code execution arguments like "-c touch /tmp/pwn", which achieves command execution on the underlying OS.
Fix: Fixed in 3.1.0.
NVD/CVE DatabaseClosing the Security Gap in the Age of Agentic Coding
Apr 21, 2026InfoNewsSecurityIndustryWiz has added Wiz Code plugins and skills, powered by the Wiz MCP server and WizCLI, that bring its security context into AI-native IDEs and coding agents. The tooling scans AI-generated code in real time and lets coding agents apply Green Agent remediation guidance, which can create pull requests. The announcement responds to frontier models such as Anthropic's Claude Mythos Preview, which the source says can autonomously discover and exploit zero-day vulnerabilities.
Fix: The source describes the Wiz Code plugins, skills, Green Agent remediation plans and automated scans at file save, pre-commit and pre-push as the approach; it does not state a patch, fixed version or configuration fix for a specific vulnerability.
Wiz Research BlogAnthropic MCP Design Vulnerability Enables RCE, Threatening AI Supply Chain
Apr 20, 2026MediumNewsSecurityIndustryOX Security researchers reported a design weakness in Anthropic's Model Context Protocol (MCP) that enables arbitrary command execution on any system running a vulnerable MCP implementation, exposing user data, internal databases, API keys and chat histories. The flaw sits in unsafe defaults in how MCP configuration works over the STDIO transport, and it is present in Anthropic's official SDK across Python, TypeScript, Java and Rust, affecting more than 7,000 publicly accessible servers and software packages with over 150 million downloads. Anthropic declined to modify the protocol's architecture, and some vendors have issued patches while the reference implementation remains unaddressed.
Fix: To counter the threat, it's advised to block public IP access to sensitive services, monitor MCP tool invocations, run MCP-enabled services in a sandbox, treat external MCP configuration input as untrusted, and only install MCP servers from verified sources.
The Hacker NewsRCE by design: MCP architectural choice haunts AI agent ecosystem
Apr 16, 2026MediumNewsSecuritySafetyOX Security researchers report that the STDIO transport in Anthropic's MCP reference implementation lets client applications pass arbitrary commands to StdioServerParameters, which execute with the parent process's permissions, exposing systems to remote code execution. Anthropic, LangChain and FastMCP maintain this is by design and that client developers must sanitize MCP configurations. The researchers say they executed commands on six official services and took over thousands of public servers across more than 200 open-source GitHub projects.
CSO OnlineGHSA-cvrr-qhgw-2mm6: Flowise: Parameter Override Bypass Remote Command Execution
Apr 16, 2026HighVulnerabilitySecurityFlowise is vulnerable to unauthenticated remote command execution through a parameter override bypass. The FILE-STORAGE:: check in replaceInputsWithConfig in packages/server/src/utils/index.ts uses .includes() rather than .startsWith(), so an attacker can embed the keyword in a string and skip the isParameterEnabled() check. This lets the attacker set NODE_OPTIONS through the Custom MCP node, which does not block it, and run arbitrary code with root privileges in the container. The attack requires a single HTTP request, plus API Override enabled and a public chatflow containing an MCP tool node.
GitHub Advisory DatabaseCodex for (almost) everything
Apr 16, 2026InfoNewsIndustryOpenAI released a major update to Codex, its coding agent used by more than 3 million developers weekly. The update adds background computer use, where multiple agents can operate Mac apps in parallel by seeing, clicking and typing with their own cursor, plus an in-app browser, image generation with gpt-image-1.5, memory of user preferences, and more than 90 plugins that combine skills, app integrations and MCP servers.
OpenAI BlogCritical Nginx UI auth bypass flaw now actively exploited in the wild
Apr 15, 2026MediumNewsSecurityA critical flaw in Nginx UI, a web-based management interface for Nginx with Model Context Protocol (MCP) support, is being actively exploited. Tracked as CVE-2026-33032, it stems from the unprotected '/mcp_message' endpoint, letting remote attackers invoke MCP tools, including config file writes and nginx reloads, without credentials. Pluto Security's scans found 2,600 publicly exposed instances potentially vulnerable.
Fix: NGNIX released a fix in version 2.3.4, and the latest secure version of nginx-ui is 2.3.6.
BleepingComputerCritical nginx UI tool vulnerability opens web servers to full compromise
Apr 15, 2026MediumNewsSecurityIndustryPluto Security published details of CVE-2026-33032, a critical flaw in the open-source nginx UI configuration tool, with a CVSS score of 9.8. The flaw sits in the MCP server support added in late 2025, where the /mcp_message endpoint lacks authentication, exposing 12 MCP tools that include config writes with automatic nginx reload. The flaw has been under active exploitation since March, and Pluto Security found 2,689 internet-reachable vulnerable instances using Shodan.
Fix: Apply the recommended fix, version 2.3.4, released March 15. For those who cannot patch immediately, disable MCP or lock the IP whitelist to trusted hosts, and review access logs for unusual configuration changes.
CSO OnlineCVE-2026-30617: LangChain-ChatChat remote code execution through MCP STDIO server configuration
Apr 15, 2026CriticalVulnerabilitySecurityCVE-2026-30617LangChain-ChatChat 0.3.1 contains a remote code execution flaw in its MCP STDIO server configuration and execution handling. A remote attacker who can reach the publicly exposed MCP management interface can configure an MCP STDIO server with attacker-controlled commands and arguments, and once the server starts with MCP enabled for agent execution, arbitrary commands run within the context of the LangChain-ChatChat service.
NVD/CVE DatabaseCVE-2026-30615: Windsurf prompt injection allows arbitrary command execution via HTML content
Apr 15, 2026CriticalVulnerabilitySecurityCVE-2026-30615A prompt injection flaw in Windsurf 1.9544.26 lets remote attackers run arbitrary commands on a victim system. When Windsurf processes attacker-controlled HTML, injected instructions can modify the local MCP configuration and automatically register a malicious MCP STDIO server, with no further user interaction. Successful exploitation can execute commands as the user, persist the malicious configuration, and expose sensitive information accessible through the application.
NVD/CVE Database‘By Design’ Flaw in MCP Could Enable Widespread AI Supply Chain Attacks
Apr 15, 2026MediumNewsSecurityIndustryResearchers warn that a flaw in Anthropic's Model Context Protocol lets unsanitized commands execute silently. The flaw could enable full system compromise across widely used AI environments.
SecurityWeekCVE-2026-39884: mcp-server-kubernetes argument injection in port_forward tool
Apr 15, 2026HighVulnerabilitySecurityCVE-2026-39884mcp-server-kubernetes, a Model Context Protocol server for Kubernetes cluster management, versions 3.4.0 and prior, contains an argument injection flaw (CVE-2026-39884) in the port_forward tool in src/tools/port_forward.ts. The tool builds a kubectl command by string concatenation and splits it on spaces before calling spawn(), so spaces in namespace, resourceType, resourceName, localPort and targetPort become argument boundaries. An attacker can inject arbitrary kubectl flags, such as --address=0.0.0.0 to expose internal Kubernetes services to the network or additional -n flags to target other namespaces, including through prompt injection against connected AI agents.
Fix: Fixed in 3.5.0.
NVD/CVE DatabaseSecure AI agent access patterns to AWS resources using Model Context Protocol
Apr 14, 2026InfoNewsSecurityIndustryThis AWS blog post explains how to secure AI agents and coding assistants that access AWS resources through the Model Context Protocol (MCP). It argues that agents can do anything their granted entitlements allow, so IAM permissions must be designed as deterministic controls, and it presents three IAM security principles with policy examples.
AWS Security BlogCVE-2025-61260: OpenAI Codex CLI code execution through malicious MCP configuration files
Apr 14, 2026HighVulnerabilitySecurityCVE-2025-61260CVE-2025-61260 affects OpenAI Codex CLI v0.23.0 and earlier. A malicious or compromised repository can trigger code execution when a user runs the codex command inside it, because Codex automatically loads project-local .env and .codex/config.toml files, including malicious MCP (Model Context Protocol) configuration, without user confirmation. Attackers can embed arbitrary commands that execute immediately.
NVD/CVE Database
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.