Model Context Protocol
The Model Context Protocol and the servers and clients that expose tools and data to models through it.
- All items
- 295
- Last 90 days
- 133
- Change
- +53%vs 87 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 2 |
| Jun 2025 | 4 |
| Jul 2025 | 4 |
| Aug 2025 | 7 |
| Sep 2025 | 3 |
| Oct 2025 | 3 |
| Nov 2025 | 2 |
| Dec 2025 | 4 |
| Jan 2026 | 4 |
| Feb 2026 | 12 |
| Mar 2026 | 22 |
| Apr 2026 | 27 |
| May 2026 | 31 |
| Jun 2026 | 25 |
| Jul 2026 | 43 |
| Aug 2026 | 45 |
| Sep 2026 | 40 |
| Oct 2026 | 16 |
295 items
CVE-2026-25904: Pydantic-AI MCP Run Python tool SSRF via Deno sandbox localhost access
Feb 9, 2026MediumVulnerabilitySecurityCVE-2026-25904CVE-2026-25904 affects the Pydantic-AI MCP Run Python tool, which configures its Deno sandbox too permissively. Python code run through the tool can reach the host's localhost interface and perform server-side request forgery (CWE-918). The project mcp-run-python is archived and unlikely to receive a fix. NVD published the entry on 02/09/2026, citing JFrog as the source.
NVD/CVE DatabaseCVE-2025-15063: Ollama MCP Server execAsync command injection leading to remote code execution
Jan 23, 2026HighVulnerabilitySecurityCVE-2025-15063CVE-2025-15063 is a command injection flaw in the execAsync method of the Ollama MCP Server. It stems from the lack of proper validation of a user-supplied string before the string is used in a system call. Remote attackers can exploit it without authentication to execute code in the context of the service account.
NVD/CVE DatabaseCVE-2026-0757: MCP Manager for Claude Desktop command injection sandbox escape
Jan 22, 2026HighVulnerabilitySecurityCVE-2026-0757MCP Manager for Claude Desktop contains a command injection sandbox escape flaw tracked as CVE-2026-0757, reported as ZDI-CAN-27810. The flaw lies in processing of MCP config objects, where a user-supplied string is used in a system call without proper validation. A remote attacker who gets a target to visit a malicious page or open a malicious file can escape the sandbox and run arbitrary code at medium integrity.
NVD/CVE DatabaseCVE-2026-22252: LibreChat MCP stdio transport accepts arbitrary commands without validation
Jan 12, 2026CriticalVulnerabilitySecurityCVE-2026-22252CVE-2026-22252 affects LibreChat before v0.8.2-rc2. Its MCP stdio transport accepts arbitrary commands without validation, so any authenticated user can run shell commands as root inside the container with a single API request. The weakness is classified as CWE-285, Improper Authorization.
Fix: Fixed in v0.8.2-rc2.
NVD/CVE DatabaseCVE-2026-0621: Anthropic MCP TypeScript SDK ReDoS in UriTemplate array pattern matching
Jan 5, 2026HighVulnerabilitySecurityCVE-2026-0621Anthropic's MCP TypeScript SDK, versions up to and including 1.25.1, contains a regular expression denial of service (ReDoS) flaw (CVE-2026-0621) in the UriTemplate class when it processes RFC 6570 exploded array patterns. The dynamically generated regular expression contains nested quantifiers that can cause catastrophic backtracking on crafted input, driving CPU use up. An attacker who supplies a malicious URI can make the Node.js process unresponsive.
NVD/CVE DatabaseGHSA-rcfx-77hg-w2wv: FastMCP updated to MCP 1.23+ due to CVE-2025-66416
Dec 26, 2025HighVulnerabilitySecurityGHSA-rcfx-77hg-w2wv concerns FastMCP, which does not use the affected components of the MCP SDK directly. However, FastMCP versions prior to 2.14.0 allowed MCP SDK versions below 1.23, which are vulnerable to CVE-2025-66416.
Fix: Upgrade to FastMCP 2.14.0 or later.
GitHub Advisory DatabaseCVE-2025-66404: MCP Server Kubernetes command injection in exec_in_pod tool
Dec 3, 2025MediumVulnerabilitySecurityCVE-2025-66404CVE-2025-66404 affects the exec_in_pod tool in mcp-server-kubernetes, an MCP Server that connects to and manages Kubernetes clusters, in versions prior to 2.9.8. When the tool receives a command as a string, it is passed directly to sh -c without input validation, so shell metacharacters are interpreted. Exploitation can occur through direct command injection or through indirect prompt injection, where AI agents may run commands without explicit user intent.
Fix: Fixed in 2.9.8.
NVD/CVE DatabaseGHSA-9h52-p55h-vw2f: Model Context Protocol (MCP) Python SDK does not enable DNS rebinding protection by default
Dec 2, 2025HighVulnerabilitySecurityCVE-2025-66416The Model Context Protocol (MCP) Python SDK did not enable DNS rebinding protection by default for HTTP-based servers. A malicious website could exploit DNS rebinding to send requests to an unauthenticated HTTP MCP server running on localhost that was built with FastMCP using streamable HTTP or SSE transport and without TransportSecuritySettings, invoking its tools or accessing its resources on the user's behalf. Servers using stdio transport are not affected.
Fix: Fixed in 1.23.0: FastMCP() servers now enable DNS rebinding protection by default when host is 127.0.0.1 or localhost. Users with custom low-level configurations using StreamableHTTPSessionManager or SseServerTransport directly should explicitly configure TransportSecuritySettings when running an unauthenticated server on localhost.
GitHub Advisory DatabaseGHSA-w48q-cv73-mx4w: Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
Dec 2, 2025HighVulnerabilitySecurityCVE-2025-66414The Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default for HTTP-based servers. When such a server runs on localhost without authentication, using StreamableHTTPServerTransport or SSEServerTransport without enableDnsRebindingProtection enabled, a malicious website could bypass same-origin policy restrictions and invoke tools or access resources on the user's behalf. The issue does not affect servers using stdio transport.
Fix: Servers created via createMcpExpressApp() now have this protection enabled by default when binding to localhost. Users with custom Express configurations are advised to update to version 1.24.0 and apply the exported hostHeaderValidation() middleware when running an unauthenticated server on localhost.
GitHub Advisory Database2025-11-25
Nov 25, 2025InfoResearchIndustryIndustryThe Model Context Protocol has published its stable 2025-11-25 revision. The specification is available on the official Model Context Protocol website, and a changelog describes the changes in detail.
MCP Specification ReleasesLevel up your Solidity LLM tooling with Slither-MCP
Nov 15, 2025InfoNewsIndustryResearchTrail of Bits has released Slither-MCP, an MCP server that exposes Slither's static analysis engine to LLMs for Solidity projects such as Foundry and Hardhat. It lets LLMs locate function sources, callers and callees, inherited members, and run Slither's detectors instead of relying on grep and read_file. The tool is licensed AGPLv3, and Trail of Bits is now offering dual licensing for Slither and Slither-MCP.
Trail of Bits BlogGHSA-c2jp-c369-7pvx: FastMCP Auth Integration Allows for Confused Deputy Account Takeover
Oct 29, 2025HighVulnerabilitySecurityFastMCP's Entra ID integration, as documented, makes the MCP server act as both an OAuth client to Entra ID and an authorization server to MCP clients, with its own `/authorize`, `/token` and `/register` endpoints. The reported issue is a confused deputy scenario that can lead to account takeover, though the source text provided is truncated before the attack details are stated.
GitHub Advisory DatabaseCVE-2025-61591: Cursor command injection via MCP OAuth with untrusted server
Oct 3, 2025HighVulnerabilitySecurityCVE-2025-61591CVE-2025-61591 affects Cursor, a code editor built for programming with AI, in versions 1.7 and below. When MCP uses OAuth authentication with an untrusted MCP server, an attacker can impersonate that server and return crafted commands during interaction, enabling command injection. Chained with an untrusted MCP service via OAuth, the flaw could let the agent execute arbitrary code on the host with full user privileges.
Fix: This issue does not currently have a fixed release version, but there is a patch, 2025.09.17-25b418f.
NVD/CVE DatabaseCVE-2025-61590: Cursor remote code execution through Visual Studio Code workspaces
Oct 3, 2025HighVulnerabilitySecurityCVE-2025-61590Cursor versions 1.6 and below are vulnerable to remote code execution through Visual Studio Code workspace files. An attacker who hijacks the victim's chat context, for example via a compromised MCP server, can use prompt injection to make the Cursor Agent write to a .code-workspace file. This bypasses the fix for CVE-2025-54130 by modifying workspace settings, which leads to RCE.
Fix: Fixed in version 1.7.
NVD/CVE DatabaseCross-Agent Privilege Escalation: When Agents Free Each Other
Sep 24, 2025MediumNewsSecurityResearchJohann Rehberger describes a design flaw in agentic systems that lets one coding agent rewrite another agent's configuration, freeing it from its sandbox. In his demo, a prompt-injected GitHub Copilot writes a malicious MCP server into Claude Code's config, which then runs arbitrary code. The post notes that Claude can reciprocate by modifying Copilot's configuration.
Fix: Mitigations and Recommendations: the source states that vendors should adopt secure defaults and that users should be aware of several points, including isolating the agent's configuration so it is less accessible to others and not automatically overwriting or creating files. The remainder of the mitigation text is cut off in the source.
Embrace The RedCVE-2025-59417: Lobe Chat cross-site scripting in chat messages via SVG artifacts
Sep 18, 2025MediumVulnerabilitySecurityCVE-2025-59417Lobe Chat versions prior to 1.129.4 contain a cross-site scripting flaw in chat message handling. When a server response includes a lobeArtifact tag with type image/svg+xml, the SVGRender component inserts the content through dangerouslySetInnerHTML, enabling XSS that can be escalated to remote code execution on the user's machine. Anyone able to inject content into chat messages, such as through a malicious page used for prompt injection, a compromised MCP server, or tool integrations, can exploit it.
Fix: Fixed in 1.129.4.
NVD/CVE DatabaseCVE-2025-58357: 5ire content injection through chat page script gadgets
Sep 4, 2025CriticalVulnerabilitySecurityCVE-2025-58357CVE-2025-58357 affects 5ire, a cross-platform desktop AI assistant and model context protocol client, in version 0.13.2. The chat page's script gadgets enable content injection attacks through malicious prompt injection pages, compromised MCP servers, and exploited tool integrations. The source does not state the attacker's resulting impact.
Fix: Fixed in version 0.14.0.
NVD/CVE DatabaseWrap Up: The Month of AI Bugs
Aug 30, 2025InfoNewsSecurityResearchThis is a wrap-up post for a month-long series that published AI coding-tool and agent security research. It lists about 30 write-ups covering ChatGPT, ChatGPT Codex, Anthropic's Filesystem MCP Server, Cursor, Amp Code, Devin AI, OpenHands, Claude Code, GitHub Copilot, Google Jules, Amazon Q Developer, Windsurf, Deep Research Agents, Manus, AWS Kiro, Cline, and an AgentHopper research demo. The titles point to prompt injection as the common vector, with data exfiltration and remote code execution as recurring outcomes.
Embrace The RedWindsurf MCP Integration: Missing Security Controls Put Users at Risk
Aug 28, 2025LowNewsSecurityIndustryThe author tested how Windsurf's MCP integration handles tool permissions in coding agents. They found that basic security controls are missing, which matters more when the agent runs on a local computer.
Embrace The RedAWS Kiro: Arbitrary Code Execution via Indirect Prompt Injection
Aug 26, 2025MediumNewsSecuritySafetyResearcher Johann Rehberger reported that AWS Kiro, a coding agent, can be hijacked through indirect prompt injection to run arbitrary operating system commands. An attacker who controls data Kiro processes can make it write to .vscode/settings.json and add "kiroAgent.trustedCommands": ["*"], allowlisting all Bash commands without developer approval. A second path adds malicious MCP servers through .kiro/settings/mcp.json. The proof of concept opened the Calculator app and changed the VS Code color theme with no user interaction beyond a chat prompt.
Embrace The Red
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.