Model Context Protocol
The Model Context Protocol and the servers and clients that expose tools and data to models through it.
- All items
- 295
- Last 90 days
- 133
- Change
- +53%vs 87 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 2 |
| Jun 2025 | 4 |
| Jul 2025 | 4 |
| Aug 2025 | 7 |
| Sep 2025 | 3 |
| Oct 2025 | 3 |
| Nov 2025 | 2 |
| Dec 2025 | 4 |
| Jan 2026 | 4 |
| Feb 2026 | 12 |
| Mar 2026 | 22 |
| Apr 2026 | 27 |
| May 2026 | 31 |
| Jun 2026 | 25 |
| Jul 2026 | 43 |
| Aug 2026 | 45 |
| Sep 2026 | 40 |
| Oct 2026 | 16 |
295 items
GHSA-8jxr-pr72-r468: Java-SDK has a DNS Rebinding Vulnerability
Apr 7, 2026HighVulnerabilitySecurityCVE-2026-35568The java-sdk MCP server contained a DNS rebinding vulnerability because it performed no Origin header validation before version 1.0.0, contrary to the MCP specification. An attacker can use a malicious website opened in a victim's browser to make arbitrary tool calls to a locally or privately networked MCP server, acting as a locally connected AI agent. Servers built on frameworks with built-in Origin validation, such as Spring AI, are not affected.
Fix: Fixed in 1.0.0 (Origin validation was absent prior to that release). Workarounds: run the MCP server behind a reverse proxy such as Nginx or HAProxy configured to strictly validate the Host and Origin headers, or use a framework that enforces strict CORS and Origin validation, such as Spring AI.
GitHub Advisory Database6 ways attackers abuse AI services to hack your business
Apr 6, 2026MediumNewsSecurityIndustryAttackers are abusing AI services that enterprises rely on, a trend experts describe as living off the AI land. One example is a counterfeit MCP server package impersonating Postmark, which ran silently for 15 versions and siphoned sensitive email until detected, and was downloaded 1,500 times per week from the node.js package registry. Other examples include the SesameOp backdoor hiding command traffic in the OpenAI Assistants API and researchers showing Microsoft Copilot and Grok could be manipulated to fetch attacker-controlled URLs.
CSO OnlineGHSA-5qhv-x9j4-c3vm: @mobilenext/mobile-mcp: Arbitrary Android Intent Execution via mobile_open_url
Apr 4, 2026HighVulnerabilitySecurityCVE-2026-35394The mobile_open_url tool in @mobilenext/mobile-mcp passes user-supplied URLs straight to Android's intent system through adb shell am start without scheme validation. Because MCP servers are driven by AI agents that can be manipulated through prompt injection, a malicious document or website could make the agent open tel:, sms:, mailto:, content:// or market:// URLs, enabling USSD codes, calls, SMS drafts, content provider access and app installation prompts.
Fix: Upgrade to version 0.0.50 or later, which restricts mobile_open_url to http:// and https:// schemes by default. Users who need other URL schemes can opt in by setting MOBILEMCP_ALLOW_UNSAFE_URLS=1.
GitHub Advisory DatabaseCVE-2025-64340: FastMCP command injection through server names in install commands on Windows
Apr 3, 2026MediumVulnerabilitySecurityCVE-2025-64340CVE-2025-64340 affects FastMCP, a framework for building MCP applications, before version 3.2.0. On Windows, server names containing shell metacharacters such as & can trigger command injection when passed to fastmcp install claude-code or fastmcp install gemini-cli. The install paths call subprocess.run() with a list argument, but target CLIs that resolve to .cmd wrappers run through cmd.exe, which interprets the metacharacters in the flattened command string.
Fix: Fixed in 3.2.0.
NVD/CVE DatabaseTools, um MCP-Server abzusichern
Apr 2, 2026InfoNewsSecurityIndustryA German B2B article on MCP security says the Model Context Protocol connects AI agents to data sources and is gaining popularity in enterprises, though vulnerabilities were found at Asana and Atlassian. It notes progress such as OAuth support and an official MCP Registry, while ongoing risks include prompt injection, tool poisoning and token theft. The piece then outlines what MCP security tools should offer, starting with MCP server discovery.
CSO OnlineGHSA-xw59-hvm2-8pj6: DNS Rebinding Protection Disabled by Default in Model Context Protocol Go SDK for Servers Running on Localhost
Apr 1, 2026HighVulnerabilitySecurityCVE-2026-34742The Model Context Protocol (MCP) Go SDK does not enable DNS rebinding protection by default for HTTP-based servers. A malicious website could use DNS rebinding to bypass same-origin restrictions and send requests to an HTTP-based MCP server running on localhost without authentication, using `StreamableHTTPHandler` or `SSEHandler`. This could let an attacker invoke tools or access resources on the user's behalf, and servers using stdio transport are not affected.
Fix: Fixed in 1.4.0: servers created via `StreamableHTTPHandler` or `SSEHandler` now have DNS rebinding protection enabled by default when binding to `localhost`. Users are advised to update to version 1.4.0.
GitHub Advisory DatabaseAI can push your Stream Deck buttons for you
Apr 1, 2026InfoNewsIndustryElgato's Stream Deck 7.4 software update adds Model Context Protocol (MCP) support. This lets AI assistants such as Claude, ChatGPT, and Nvidia G-Assist find and activate Stream Deck actions for users, who can type or speak requests. Users still configure actions in the Stream Deck app as before.
The Verge (AI)GHSA-vv7q-7jx5-f767: FastMCP OpenAPI Provider has an SSRF & Path Traversal Vulnerability
Mar 31, 2026CriticalVulnerabilitySecurityCVE-2026-32871GHSA-vv7q-7jx5-f767 affects the OpenAPIProvider in FastMCP, which parses OpenAPI specifications to expose internal APIs to MCP clients. The _build_url() method in fastmcp/utilities/openapi/director.py substitutes path parameter values into URL templates without URL-encoding, and urljoin() then resolves ../ sequences, letting an attacker reach arbitrary backend endpoints. Because requests carry the MCP provider's configured authorization headers, the flaw results in authenticated SSRF.
GitHub Advisory DatabaseGHSA-rww4-4w9c-7733: FastMCP: Missing Consent Verification in OAuth Proxy Callback Facilitates Confused Deputy Vulnerabilities
Mar 31, 2026HighVulnerabilitySecurityCVE-2026-27124The FastMCP OAuthProxy does not verify user consent when it receives an authorization code from the identity provider, in its _handle_idp_callback function. Because GitHub skips the consent page for previously authorized clients, an attacker can capture a GitHub authorization URL after consenting and lure a logged-in victim to open it. The victim's browser then redirects to the malicious client's callback with a valid authorization code, which the attacker can exchange for an access token to the benign MCP server tied to the victim's GitHub account. The issue was verified only for GitHubProvider, but the flaw affects any OAuth integration whose identity provider skips consent.
GitHub Advisory DatabaseCVE-2026-34163: FastGPT MCP tools endpoints server-side request forgery via user-supplied URL
Mar 31, 2026HighVulnerabilitySecurityCVE-2026-34163FastGPT, an AI Agent building platform, has an SSRF flaw in its MCP tools endpoints, /api/core/app/mcpTools/getTools and /api/core/app/mcpTools/runTool, before version 4.14.9.5. These endpoints accept a user-supplied URL and send server-side HTTP requests to it without checking for internal or private network addresses. The application's isInternalAddress() function exists but these endpoints do not call it. An authenticated attacker can scan internal networks, reach cloud metadata services, and interact with internal services such as MongoDB and Redis.
Fix: Fixed in 4.14.9.5.
NVD/CVE Databasev5.5.0
Mar 30, 2026InfoResearchIndustrySecurityResearchThe v5.5.0 release of the MITRE ATLAS knowledge base adds new techniques, including AI Agent Tool Poisoning, AI Supply Chain Rug Pull, Machine Compromise variants, and Cost Harvesting variants. It also adds case studies such as LLMSmith, the Poisoned Postmark MCP Server email exfiltration, and Model Distillation Campaigns Targeting Anthropic Claude, and updates mitigations including Code Signing, AI Telemetry Logging, and Segmentation of AI Agent Components.
MITRE ATLAS ReleasesCVE-2026-31951: LibreChat OAuth token exfiltration through user-created MCP server headers
Mar 27, 2026MediumVulnerabilitySecurityCVE-2026-31951CVE-2026-31951 affects LibreChat versions 0.8.2-rc1 through 0.8.3-rc1. User-created MCP (Model Context Protocol) servers can set arbitrary HTTP headers that undergo credential placeholder substitution, so a malicious server using `{{LIBRECHAT_OPENID_ACCESS_TOKEN}}` in its headers can exfiltrate the OAuth tokens of users who call tools on that server. The weakness is classified as CWE-200, Exposure of Sensitive Information to an Unauthorized Actor.
Fix: Fixed in 0.8.3-rc2.
NVD/CVE DatabaseGHSA-vphc-468g-8rfp: Azure Data Explorer MCP Server: KQL Injection in multiple tools allows MCP client to execute arbitrary Kusto queries
Mar 27, 2026HighVulnerabilitySecurityCVE-2026-33980adx-mcp-server, at latest and commit 48b2933, contains KQL injection in three MCP tool handlers: get_table_schema, sample_table_data and get_table_details. The table_name parameter is interpolated into KQL via f-strings with no validation, so a caller or a prompt-injected agent can run arbitrary KQL against the Azure Data Explorer cluster, including reading other tables and issuing management commands such as .drop table. The flaw bypasses client trust boundaries because these tools are presented as safe metadata tools.
GitHub Advisory DatabaseGHSA-647h-p824-99w7: @grackle-ai/mcp has a workspace authorization bypass in its knowledge_search MCP tool
Mar 25, 2026HighVulnerabilitySecurityThe knowledge_search and knowledge_get_node MCP tools in @grackle-ai/mcp are listed in SCOPED_TOOLS, so scoped agents can call them, but their handlers do not receive authContext or enforce workspace scoping. A scoped agent in Workspace A can pass an arbitrary workspaceId to read knowledge graph data from Workspace B, bypassing workspace isolation (CWE-284).
Fix: Fix: Add an authContext parameter to the knowledge_search and knowledge_get_node handlers and enforce workspace scoping, matching knowledge_create_node, using resolvedWorkspaceId = authContext?.type === "scoped" ? authContext.workspaceId ?? "" : workspaceId ?? "". Workarounds: do not use scoped agent tokens in multi-workspace deployments until patched, or remove knowledge_search and knowledge_get_node from the SCOPED_TOOLS set in tool-scoping.ts.
GitHub Advisory DatabaseAI Conundrum: Why MCP Security Can't Be Patched Away
Mar 19, 2026LowNewsSecurityResearchA researcher speaking at the RSAC 2026 Conference argues that MCP introduces security risks into LLM environments. According to the source, these risks are architectural rather than easily fixable.
Dark ReadingGHSA-89xv-2j6f-qhc8: Cross-Site Tool Execution for HTTP Servers without Authorizatrion in github.com/modelcontextprotocol/go-sdk
Mar 19, 2026HighVulnerabilitySecurityCVE-2026-33252The Go SDK for MCP (github.com/modelcontextprotocol/go-sdk) had a flaw in its Streamable HTTP transport. It accepted browser-generated cross-site POST requests without validating the Origin header or requiring Content-Type: application/json. Without Authorization configured, especially in stateless or sessionless setups, any website could send MCP requests to a local server and potentially trigger tool execution. Cross-site POSTs with Content-Type: text/plain could reach message handling without a CORS preflight barrier.
Fix: Fixed in v1.4.1, which adds Content-Type header validation for POST requests and a configurable origin verification protection (commit a433a83). Note: v1.4.1 requires Go 1.25 or later.
GitHub Advisory DatabaseGHSA-q382-vc8q-7jhj: Improper handling of null Unicode character when parsing JSON in github.com/modelcontextprotocol/go-sdk
Mar 19, 2026HighVulnerabilitySecurityThe Go SDK for the Model Context Protocol moved to the segmentio/encoding library for JSON parsing in version 1.3.1. The new parser matched keys that had null Unicode characters appended to their base names, so combined with duplicate keys, a "last key wins" resolution could override the intended MCP message. This could let messages evade proxies or policy layers that match exact field names, and other MCP SDKs in TypeScript and Python would reject the same messages.
Fix: The segmentio/encoding package was patched and released as v0.5.4, and the SDK switched to the patched dependency in 724dd47aa. Users are advised to update to v1.4.1.
GitHub Advisory DatabaseNavigating Security Tradeoffs of AI Agents
Mar 18, 2026LowNewsSecurityIndustryPalo Alto Networks' Unit 42 argues that AI agent security is a tradeoff between safety and productivity, and that agent risk comes from the privileges granted to them. The authors predict intrusions will follow two pathways: attacks on the open-source AI ecosystem, and attacks on an organization's internal AI agents. They describe model file attacks, where malicious model files hide executable code, and rug pull attacks, where a compromised MCP server is modified to act maliciously after an LLM integrates with it.
Fix: Teams must scan model files with tools that can parse machine learning formats, and load models in isolated containers, virtual machines or browser sandboxes. Organizations should prefer remote MCP servers whose code is maintained by trusted organizations, which reduces but does not eliminate the risk of rug pull attacks.
Palo Alto Unit 42GHSA-3xm7-qw7j-qc8v: SSRF in @aborruso/ckan-mcp-server via base_url allows access to internal networks
Mar 18, 2026MediumVulnerabilitySecurityCVE-2026-33060The @aborruso/ckan-mcp-server MCP server accepts a base_url parameter in tools such as ckan_package_search and sparql_query and sends HTTP requests to it without restriction. Exploitation needs prompt injection through malicious content while the assistant has this server connected, and a proof of concept sent 9 requests to a canary endpoint. An attacker could scan internal networks, steal cloud metadata credentials via 169.254.169.254, and attempt SQL or SPARQL injection.
Fix: Recommended fix: 1. Validate base_url against a configurable allowlist of permitted CKAN portals. 2. Block private IP ranges (RFC 1918, link-local). 3. Block cloud metadata endpoints (169.254.169.254). 4. Sanitize SQL input for datastore queries. 5. Apply a SPARQL endpoint allowlist.
GitHub Advisory DatabaseGHSA-2cpp-j2fc-qhp7: AWS API MCP File Access Restriction Bypass
Mar 17, 2026MediumVulnerabilitySecurityCVE-2026-4270The AWS API MCP Server, an open source Model Context Protocol server that lets AI assistants run AWS CLI commands, contains an Improper Protection of Alternate Path flaw in its no-access and workdir file access features. Versions >= 0.2.14 and < 1.3.9, on all platforms, can bypass the intended file restriction and expose arbitrary local file contents in the MCP client application context.
Fix: Upgrade to version 1.3.9.
GitHub Advisory Database
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.