Model Context Protocol
The Model Context Protocol and the servers and clients that expose tools and data to models through it.
- All items
- 295
- Last 90 days
- 133
- Change
- +53%vs 87 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 2 |
| Jun 2025 | 4 |
| Jul 2025 | 4 |
| Aug 2025 | 7 |
| Sep 2025 | 3 |
| Oct 2025 | 3 |
| Nov 2025 | 2 |
| Dec 2025 | 4 |
| Jan 2026 | 4 |
| Feb 2026 | 12 |
| Mar 2026 | 22 |
| Apr 2026 | 27 |
| May 2026 | 31 |
| Jun 2026 | 25 |
| Jul 2026 | 43 |
| Aug 2026 | 45 |
| Sep 2026 | 40 |
| Oct 2026 | 16 |
295 items
CVE-2026-4270 - AWS API MCP File Access Restriction Bypass
Mar 16, 2026HighVulnerabilitySecurityCVE-2026-4270 is an Improper Protection of Alternate Path flaw in the no-access and workdir file access features of the AWS API MCP Server, affecting awslabs.aws-api-mcp-server versions >= 0.2.14 and < 1.3.9 on all platforms. The flaw may allow an attacker to bypass the intended file access restriction and expose arbitrary local file contents in the MCP client application context.
AWS Security BulletinsGHSA-5h2m-4q8j-pqpj: FastMCP OAuth Proxy token reuse across MCP servers
Mar 16, 2026HighVulnerabilitySecurityCVE-2025-69196The FastMCP OAuth Proxy ignores the client-supplied `resource` parameter in authorization and token requests and issues tokens for the `base_url` set at initialization instead. Because the tokens carry no resource information, a benign MCP server cannot verify that a token was issued for it. An attacker can run a malicious MCP server that advertises the benign proxy as its authorization server, capture the token from a victim's OAuth flow, and replay it against other MCP servers that share that authorization server.
Fix: To mitigate this vulnerability, it is recommended to issue tokens specifically for the MCP server submitted in the authorization URL's `resource` GET parameter. In this way, the receiving MCP server will be able to properly verify that the token was indeed issued for it, allowing it to reject tokens stolen by an attack like the one demonstrated above.
GitHub Advisory DatabaseCVE-2026-31944: LibreChat MCP OAuth callback stores tokens for the wrong user
Mar 13, 2026HighVulnerabilitySecurityCVE-2026-31944LibreChat versions 0.8.2 through 0.8.2-rc3 have a flaw in the MCP (Model Context Protocol) OAuth callback endpoint. It stores OAuth tokens for the user who started the flow without checking that the browser completing the redirect is logged in or belongs to that same user. An attacker can send a victim the authorization URL, and the victim's tokens for linked services such as Atlassian and Outlook end up on the attacker's account, enabling account takeover.
Fix: Fixed in 0.8.3-rc1.
NVD/CVE DatabaseGHSA-xjgw-4wvw-rgm4: MCP Atlassian has an arbitrary file write leading to arbitrary code execution via unconstrained download_path in confluence_download_attachment
Mar 10, 2026CriticalVulnerabilitySecurityCVE-2026-27825GHSA-xjgw-4wvw-rgm4 affects MCP Atlassian. The confluence_download_attachment tool accepts a download_path parameter that is written to without any directory boundary enforcement, so an attacker who controls an attachment's content can write it to any path the server process can write, such as /etc/cron.d/, leading to arbitrary code execution. The MCP HTTP transport carries no authentication by default and binds to 0.0.0.0, so the issue is reachable from the local network.
GitHub Advisory DatabaseGHSA-7r34-79r5-rcc9: MCP Atlassian has SSRF via unvalidated X-Atlassian-Jira-Url / X-Atlassian-Confluence-Url headers
Mar 10, 2026HighVulnerabilitySecurityCVE-2026-27826mcp-atlassian's HTTP middleware and dependency layer accept an unvalidated X-Atlassian-Jira-Url (and the Confluence equivalent) from unauthenticated requests when no Authorization header is present. The server then issues an outbound GET to {header_url}/rest/api/2/myself, enabling server-side request forgery, which the advisory says can expose IAM credentials via 169.254.169.254 in cloud deployments and enable internal network reconnaissance and injection of attacker-controlled content into LLM tool results.
GitHub Advisory DatabaseGHSA-67q9-58vj-32qx: WeKnora Vulnerable to Tool Execution Hijacking via Ambigous Naming Convention In MCP client and Indirect Prompt Injection
Mar 6, 2026MediumVulnerabilitySecurityCVE-2026-30856WeKnora's MCP client builds internal tool names as `mcp_{service}_{tool}` after sanitizing each part, and its registry (`internal/agent/tools/registry.go`) silently overwrites existing entries. A malicious remote MCP server can register a tool such as `tavily_extract` that replaces the legitimate one, and the client also feeds MCP tool descriptions and results into the LLM context without sanitization. The source states that this lets an attacker redirect LLM execution, exfiltrate system prompts and context, and potentially run other tools with the user's privileges, with a precondition that the user registers the malicious service before the legitimate one.
GitHub Advisory DatabaseCVE-2026-29791: Agentgateway input validation flaw in MCP tools/call to OpenAPI conversion
Mar 6, 2026MediumVulnerabilitySecurityCVE-2026-29791CVE-2026-29791 affects Agentgateway, an open source data plane for agentic AI connectivity, prior to version 0.12.0. When converting an MCP tools/call request to an OpenAPI request, input path, query, and header values are not sanitized, which is classified as CWE-20 Improper Input Validation. The NVD assessment has not yet been provided.
Fix: This issue has been patched in version 0.12.0.
NVD/CVE DatabaseGHSA-g8r9-g2v8-jv6f: GitHub Copilot CLI Dangerous Shell Expansion Patterns Enable Arbitrary Code Execution
Mar 6, 2026HighVulnerabilitySecurityCVE-2026-29783GitHub Copilot CLI's shell tool contains a vulnerability in which crafted bash parameter expansion patterns (such as ${var@P}, assignment forms like ${var=value}, indirect ${!var}, and nested $(cmd) inside ${...}) can hide command execution inside commands the safety assessment classifies as read-only. An attacker who can influence the commands the agent runs, for example through prompt injection in repository files, MCP server responses, or user instructions, could achieve arbitrary code execution on the user's workstation, even in modes that require approval for write operations. The issue affects versions prior to 0.0.423.
Fix: Fixed in 0.0.423. The fix adds parse-time detection that downgrades commands containing dangerous ${...} expansion operators or nested command/process substitutions from read-only to write-capable, and unconditionally blocks such commands at the tool execution layer regardless of permission mode, including --yolo / autopilot.
GitHub Advisory DatabaseAI Agents: The Next Wave Identity Dark Matter - Powerful, Invisible, and Unmanaged
Mar 3, 2026LowNewsSecurityIndustryAn article argues that AI agents built on the Model Context Protocol (MCP) are spreading through enterprises faster than governance controls, and that these non-human identities sit outside traditional IAM as "identity dark matter." It cites a Team8 2025 CISO Village Survey finding that nearly 70% of enterprises already run AI agents in production.
The Hacker NewsGHSA-wvj2-96wp-fq3f: MCP Go SDK Vulnerable to Improper Handling of Case Sensitivity
Feb 26, 2026HighVulnerabilitySecurityCVE-2026-27896The Go MCP SDK parsed JSON-RPC and MCP messages with Go's standard encoding/json.Unmarshal, which matches keys case-insensitively and folds Unicode characters such as ſ (U+017F) and K (U+212A) to ASCII. A malicious MCP peer could send non-standard field casing, such as "Method" instead of "method", that the SDK silently accepted. This could let such messages bypass intermediary proxies or policy layers that match exact field names, and it made the Go SDK inconsistent with the case-sensitive TypeScript and Python SDKs.
Fix: Fixed in v1.3.1. The SDK replaced Go's standard JSON unmarshaling with a case-sensitive decoder (github.com/segmentio/encoding) in commit 7b8d81c. Users are advised to update to v1.3.1.
GitHub Advisory DatabaseThreatsDay Bulletin: Kali Linux + Claude, Chrome Crash Traps, WinRAR Flaws, LockBit & 15+ Stories
Feb 26, 2026LowNewsSecurityIndustryThis ThreatsDay bulletin covers several stories, including Kali Linux adding an integration with Anthropic's Claude through the Model Context Protocol (MCP) to turn natural language into technical commands. It also reports Belarus-linked Android spyware ResidentBat, used by Belarusian authorities for surveillance, and CrowdStrike's finding that the average e-crime breakout time dropped to 29 minutes in 2025, a 65% increase in speed from 2024.
The Hacker NewsFigma partners with OpenAI to bake in support for Codex
Feb 26, 2026InfoNewsIndustryFigma is integrating OpenAI's coding tool Codex so users can create and tweak designs from within their coding environments. The integration lets users move between Figma and Codex through Figma's MCP (Model Context Protocol) server, and it follows a similar Figma partnership with Anthropic for Claude Code a week earlier. OpenAI said over a million users use Codex weekly.
TechCrunchClaude Code Flaws Allow Remote Code Execution and API Key Exfiltration
Feb 25, 2026MediumNewsSecurityIndustryCheck Point Research disclosed multiple flaws in Anthropic's Claude Code that let a malicious repository run arbitrary shell commands and exfiltrate Anthropic API keys when a user opens it. The flaws span hooks, MCP server configuration and environment variables, and CVE-2026-21852 involves a settings file that redirects API requests via ANTHROPIC_BASE_URL before the trust prompt appears.
Fix: Fixed in version 1.0.87 (September 2025) for the untrusted project hooks issue, fixed in version 1.0.111 (October 2025) for CVE-2025-59536, and fixed in version 2.0.65 (January 2026) for CVE-2026-21852.
The Hacker NewsNew Relic launches new AI agent platform and OpenTelemetry tools
Feb 24, 2026InfoNewsIndustryNew Relic launched the New Relic Agentic Platform, a no-code system for building and managing data observability AI agents that monitor company data for bugs and issues. The platform supports the model context protocol (MCP) and integrates with other New Relic tools. The company also added OpenTelemetry capabilities to its application performance monitoring (APM) agents, letting enterprises manage OTel data streams alongside other data sources.
TechCrunchShai-Hulud-style NPM worm hits CI pipelines and AI coding tools
Feb 24, 2026MediumNewsSecurityIndustrySocket researchers uncovered an active npm supply chain campaign they named SANDWORM_MODE, a Shai-Hulud-style worm that spreads through at least 19 typosquatted packages impersonating developer utilities and AI tools, including three that impersonate Claude Code and one that targets OpenClaw. The malware harvests npm and GitHub tokens, environment secrets and cloud keys, then uses them to push malicious changes into other repositories. It also deploys a malicious MCP server into AI assistant configurations, where prompt injection can trick the assistant into sending local SSH keys or cloud credentials to the attacker.
Fix: The source states that npm has hardened the registry against Shai-Hulud-class worms, with short-lived, scoped tokens, mandatory two-factor authentication for publishing, and identity-bound "trusted publishing" from CI. It says these controls are designed to contain the blast radius from stolen secrets, but their effectiveness depends on how quickly maintainers adopt them.
CSO OnlineThe rise of the evasive adversary
Feb 24, 2026LowNewsSecurityIndustryCrowdStrike's 12th annual Global Threat Report finds that AI-enabled adversary attacks rose 89% year over year, with threat actors using generative tools to refine phishing lures, generate malware scripts, and accelerate reconnaissance. Malware-free techniques accounted for 82% of detections in 2025, up from 51% in 2020. The report also describes a malicious MCP server, postmark-mcp, that impersonated a Postmark-maintained server and bcc'd an adversary on every email sent.
CSO OnlineSmartLoader Attack Uses Trojanized Oura MCP Server to Deploy StealC Infostealer
Feb 17, 2026MediumNewsSecurityIndustryStraiker's AI Research (STAR) Labs reports a SmartLoader campaign that distributes a trojanized version of the Oura MCP server, which connects AI assistants to Oura Ring health data. The threat actors built fake GitHub forks and contributor accounts to manufacture credibility, then submitted the malicious server to the MCP Market registry, where it remains listed. Launching it via a ZIP archive runs an obfuscated Lua script that drops SmartLoader, which deploys the StealC infostealer to steal credentials, browser passwords and cryptocurrency wallet data.
Fix: As mitigations to combat the threat, organizations are recommended to inventory installed MCP servers, establish a formal security review before installation, verify the origin of MCP servers, and monitor for suspicious egress traffic and persistence mechanisms.
The Hacker NewsGHSA-w5cr-2qhr-jqc5: Cloudflare Agents has a Reflected Cross-Site Scripting (XSS) vulnerability in AI Playground site
Feb 13, 2026MediumVulnerabilitySecurityCloudflare Agents' AI Playground OAuth callback handler in site/ai-playground/src/server.ts inserted the error_description query parameter into an inline script tag without escaping. A crafted link lets an attacker run JavaScript in a victim's session, exposing chat history, LLM interactions and connected MCP servers, and enabling actions on the victim's behalf.
Fix: Agents-sdk users should upgrade to agents@0.3.10 (fix in PR https://github.com/cloudflare/agents/pull/841). Developers using configureOAuthCallback with custom error handling should escape all user-controlled input before interpolation.
GitHub Advisory DatabaseCVE-2026-1721: AI Playground reflected XSS through OAuth callback error parameter
Feb 12, 2026MediumVulnerabilitySecurityCVE-2026-1721A reflected XSS flaw in the AI Playground's OAuth callback handler (`site/ai-playground/src/server.ts`) interpolates the `error_description` query parameter into an inline `<script>` tag without escaping. A victim who clicks a crafted link lets an attacker run arbitrary JavaScript in their session, exposing stored LLM chat history and allowing actions on any MCP servers connected to that session, public or authenticated.
Fix: Agents-sdk users should upgrade to agents@0.3.10. Developers using configureOAuthCallback with custom error handling should escape all user-controlled input before interpolation. The source also links PR https://github.com/cloudflare/agents/pull/841.
NVD/CVE DatabaseCVE-2026-26029: sf-mcp-server command injection through Salesforce CLI commands
Feb 11, 2026HighVulnerabilitySecurityCVE-2026-26029CVE-2026-26029 affects sf-mcp-server, an implementation of the Salesforce MCP server for Claude for Desktop. The flaw is an OS command injection (CWE-78) caused by unsafe use of child_process.exec when building Salesforce CLI commands from user-controlled input. Successful exploitation lets an attacker run arbitrary shell commands with the privileges of the MCP server process.
Fix: The source links a commit (99fba0171b8c22b5ee3c0405053ccfd2910a066d) and a GitHub security advisory (GHSA-h4w9-g9c5-vfwq), but does not state a fixed version, configuration change or workaround in the text provided.
NVD/CVE Database
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.