Model Context Protocol
The Model Context Protocol and the servers and clients that expose tools and data to models through it.
- All items
- 295
- Last 90 days
- 133
- Change
- +53%vs 87 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 2 |
| Jun 2025 | 4 |
| Jul 2025 | 4 |
| Aug 2025 | 7 |
| Sep 2025 | 3 |
| Oct 2025 | 3 |
| Nov 2025 | 2 |
| Dec 2025 | 4 |
| Jan 2026 | 4 |
| Feb 2026 | 12 |
| Mar 2026 | 22 |
| Apr 2026 | 27 |
| May 2026 | 31 |
| Jun 2026 | 25 |
| Jul 2026 | 43 |
| Aug 2026 | 45 |
| Sep 2026 | 40 |
| Oct 2026 | 16 |
295 items
CVE-2026-101065: Obot Docker quickstart exposes admin access without authentication
Sep 27, 2026CriticalVulnerabilitySecurityCVE-2026-101065Obot, an open-source AI agent and MCP platform, documents a Docker quickstart that starts the container on 0.0.0.0:8080 with authentication disabled by default in all versions up to and including commit d7e6970 (CVE-2026-101065). Unauthenticated users who can reach the port receive a synthetic "nobody" user holding the Owner and Admin roles, which grants full control of the Obot API and UI, including registering and launching attacker-controlled MCP servers. The quickstart also mounts /var/run/docker.sock, giving the MCP runtime backend access to the host's Docker control surface.
Fix: The fix is documentation-only: the quickstart now enables authentication. Operators who followed the previous instructions should set OBOT_SERVER_ENABLE_AUTHENTICATION=true before exposing the host to any untrusted network.
NVD/CVE DatabaseCVE-2026-97228: Rapid7 Bulk Export MCP GraphQL query injection in export-status component
Sep 25, 2026LowVulnerabilitySecurityCVE-2026-97228Rapid7 Bulk Export MCP versions 0.2.5 through 0.6.1 contain a GraphQL query injection in `get_export_status` in `src/export_manager.py`. The unvalidated `export_id` argument, passed via the `check_rapid7_export_status` and `download_rapid7_export` tools, is interpolated directly into the query string, so a crafted value can append attacker-chosen root-level selections such as schema introspection. The injected query runs under the operator's own API key and cannot cross a tenant or account boundary, so the realistic exposure is a compromised or careless upstream MCP client or indirect prompt injection.
Fix: Fixed in version 0.6.2, which passes `export_id` as a parameterized GraphQL variable (`$exportId: ID!`).
NVD/CVE DatabaseGHSA-3cj3-hqcr-g934: Cline: Cross-Origin WebSocket Hijacking in Cline Hub Dashboard (`/browser` endpoint)
Sep 24, 2026HighVulnerabilitySecurityCVE-2026-59723The Cline Hub dashboard server (`@cline/cline-hub`), launched with the `cline dashboard` CLI command, accepts WebSocket connections on `/browser` without validating the HTTP `Origin` header. When `ROOM_SECRET` is unset, which is the default for `127.0.0.1` binds, `isAuthorizedBrowserRequest()` returns `true`, so any website a developer visits can open a cross-origin WebSocket to `ws://127.0.0.1:8787/browser`. Dashboard sessions default to `autoApprove: true` for all tools, and the source reports that an injected `upsert_mcp_server` frame wrote a malicious `stdio` MCP server entry into the victim's Cline settings file.
GitHub Advisory DatabaseGHSA-fm8p-53ww-hf6w: DBHub HTTP transport DNS rebinding allows unauthenticated browser-origin SQL execution
Sep 24, 2026CriticalVulnerabilitySecurityCVE-2026-61742DBHub 0.21.2 exposes an unauthenticated HTTP MCP endpoint at /mcp when run with --transport http. Its origin check only compares Origin and Host hostnames for equality, so a DNS rebinding attack lets a malicious website invoke DBHub MCP tools from a victim's browser without prompt injection or model involvement. With a real configured database, this can read, enumerate, and potentially write database contents depending on configured tool permissions and credentials.
Fix: Suggested remediation: bind HTTP transport to 127.0.0.1 by default and require explicit opt-in for 0.0.0.0 or non-loopback hosts. Add an explicit allowed-hosts policy instead of accepting arbitrary hosts (the source text is truncated at this point).
GitHub Advisory DatabaseCan We Control Every AI Agent Before It Becomes Our Next Privileged Insider?
Sep 24, 2026InfoNewsSecurityIndustryAI agents are spreading into enterprises faster than many security programs were built to handle. They read email, access SaaS applications, query databases, invoke APIs, use MCP tools and modify records. The source text is cut off before it describes any specific controls.
Check Point ResearchCVE-2026-93529: Contributor Broken Access Control in WSP MCP – AI Agents Connector <= 2.7.0 versions.
Sep 23, 2026MediumVulnerabilitySecurityCVE-2026-93529CVE-2026-93529 is a Contributor Broken Access Control flaw in WSP MCP – AI Agents Connector, affecting versions up to and including 2.7.0. The source text provides no further detail on how the flaw is reached or what an attacker gains.
NVD/CVE DatabaseCVE-2026-18875: IBM FTM for RedHat OpenShift RAG poisoning via unauthenticated upsert
Sep 23, 2026HighVulnerabilitySecurityCVE-2026-18875IBM Financial Transaction Manager (FTM) for RedHat OpenShift is affected by CVE-2026-18875, a RAG poisoning flaw (CWE-74) caused by an unauthenticated runbook upsert in the FTM AI agent server at api.vectordb.runbooks.js:51. An unauthenticated attacker can insert malicious runbook content into the agent's vector database. This can steer AI-driven MCP tool calls, potentially triggering unauthorized payment actions or exfiltrating payment data.
NVD/CVE DatabaseWorkforce AI Security Policy Management Is Now Conversational
Sep 23, 2026InfoNewsIndustrySecurityCheck Point has released the Workforce AI MCP, its own Model Context Protocol server for Workforce AI Security. Connecting a compatible AI client lets administrators query, analyze and manage employee AI usage policy in natural language rather than through filters, screens and individual rule checks. The server covers users, managed assets, GenAI application usage, DLP data types, and agent and MCP activity within a single conversation.
Check Point ResearchGHSA-93xw-j965-9mx3: MCP Atlassian: Arbitrary file read/exfiltration via upload_attachment missing validate_safe_path()
Sep 22, 2026HighVulnerabilitySecurityCVE-2026-77258The upload_attachment method in confluence/attachments.py of mcp-atlassian reads and uploads arbitrary local files to Confluence without calling validate_safe_path(), although the download methods do call it. An MCP-connected AI agent, or an attacker influencing it through prompt injection, can read any file the server process can access, such as SSH keys, AWS credentials or .env files, and exfiltrate it as a Confluence page attachment. The issue was reproduced with mcp-atlassian 0.21.1 on Python 3.11.
Fix: Add validate_safe_path(file_path) before the os.path.exists() check in upload_attachment, matching the existing pattern in the download methods. The function is already imported in that file.
GitHub Advisory DatabaseGHSA-f6pj-qv47-g96w: MCP Atlassian: Arbitrary server-local file upload to Jira/Confluence attachments via unrestricted file_path parameters
Sep 22, 2026HighVulnerabilitySecurityCVE-2026-77247The Jira and Confluence attachment upload tools in MCP Atlassian accept caller-controlled file_path parameters and read those paths from the MCP server's local filesystem before uploading them as Atlassian attachments. In local stdio deployments this exposes files readable by the user's MCP process, while in HTTP/SSE or streamable-http deployments any MCP client permitted to invoke upload tools can make the server read a server-local file and upload it to Jira or Confluence. The flaw is deterministic and does not depend on prompt injection or model behavior.
Fix: Server-local file uploads should be denied by default in HTTP/SSE or multi-user deployments, or uploads should be constrained to an explicit allowlisted upload directory after realpath resolution, and dangerous path forms such as remote UNC paths and file:// URLs should be rejected before filesystem checks.
GitHub Advisory DatabaseGHSA-p6hp-93wp-fh6p: MCP Atlassian: Path Traversal / Arbitrary File Read in confluence_upload_attachment MCP tool (incomplete fix of GHSA-xjgw-4wvw-rgm4)
Sep 22, 2026HighVulnerabilitySecurityCVE-2026-77262The mcp-atlassian server's confluence_upload_attachment MCP tool passes its file_path argument straight to open(file_path, "rb") with no path validation, so a caller can read arbitrary files the server process can read and upload them to an attacker-controlled Confluence host. With the default streamable-http transport binding 0.0.0.0 without authentication, this is remotely exploitable without credentials. It is the read-side counterpart of GHSA-xjgw-4wvw-rgm4 / CVE-2026-27825, whose fix in v0.17.0 covered only the download path.
GitHub Advisory DatabaseGHSA-f26r-j276-ggg4: MCP Atlassian: Arbitrary File Read via Upload Attachment Tools
Sep 22, 2026MediumVulnerabilitySecurityCVE-2026-77270The upload_attachment methods in MCP Atlassian's Confluence and Jira integrations accept arbitrary file paths without path traversal validation. The validate_safe_path utility is used in the download paths but never called in the upload paths, so an authenticated MCP client, or an AI assistant manipulated via prompt injection, can read any file the server process can access and upload it to an attacker-chosen Confluence page or Jira issue.
GitHub Advisory DatabaseCritical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials
Sep 22, 2026MediumNewsSecurityIndustryJFrog Security Research's Yuval Moravchick found CVE-2026-90898 (CVSS 9.8) in Bifrost, an open-source AI gateway. Before 2.1.0 with management authentication disabled, which is the default, a single unauthenticated POST to /api/mcp/client registers a stdio MCP client, and Bifrost runs the specified command as the gateway process user before any MCP handshake. Because the gateway stores API keys for every connected provider, the attacker gains access to those credentials.
Fix: Upgrade to transports/v2.1.0, which returns 403 for unauthenticated stdio MCP client registration. If upgrading is not immediately possible, set governance.auth_config.is_enabled to true, use strong credentials, and keep the management listener off untrusted networks. JFrog advises treating any instance that ran with authentication disabled and an exposed management API as compromised and rotating virtual keys and provider API keys.
The Hacker NewsGHSA-jjhp-8crj-mppq: @roomi-fields/notebooklm-mcp has a path traversal in vault.batch tool that allows arbitrary file write outside intended vault directory
Sep 22, 2026HighVulnerabilitySecurityCVE-2026-61647The vault_batch MCP tool and the POST /batch-to-vault HTTP endpoint in @roomi-fields/notebooklm-mcp passed a caller-supplied vault_dir directly to path.resolve() and fs.mkdir() with no containment check, and slug_prefix was concatenated into filenames without sanitization. Affected versions run from v1.6.0 through v2.0.2, and an attacker, or a prompt-injected LLM driving the MCP, could write .md and .json files to any location the server process can write, such as autostart folders or shell startup files.
Fix: Fixed in v2.0.3: set the NOTEBOOKLM_VAULT_ROOT environment variable to a directory that bounds all vault writes, which enables realpath-based containment, since it is unset by default and the legacy unrestricted behaviour remains when it is unset. slug_prefix is now always sanitized regardless of that variable. Users who cannot upgrade should run the server under a dedicated unprivileged user with write access only to the intended vault directory, keep the HTTP endpoint off non-localhost interfaces, and validate vault_dir arguments before forwarding them.
GitHub Advisory DatabaseGHSA-qg2g-g9w3-m5h8: ToolHive: containerized MCP servers can reach host services via host.docker.internal, enabling lateral movement
Sep 18, 2026HighVulnerabilitySecurityCVE-2026-58197A containerized MCP server running under the default `network` permission profile (`insecure_allow_all: true`) can reach host-local services through `host.docker.internal`, including the ToolHive API, other ToolHive-managed MCP server proxies, and other localhost services. Because the ToolHive API and MCP proxy endpoints are unauthenticated, a compromised or malicious MCP server can move laterally without a container escape. The source rates the severity High.
GitHub Advisory DatabaseCVE-2026-54504: MCP Documentation Server Web UI exposes unauthenticated document API
Sep 17, 2026HighVulnerabilitySecurityCVE-2026-54504MCP Documentation Server versions 1.13.0 through 1.13.1 start a Web UI by default on port 3080, and startWebServer in src/web-server.ts calls app.listen(PORT) without a host, binding the unauthenticated document-management API to all interfaces instead of localhost. A network-reachable client can call endpoints such as GET /api/documents, POST /api/documents, DELETE /api/documents/:id and POST /api/search-all without credentials to read, search, insert or delete documents and alter the assistant's knowledge base. The attacker must be able to reach the service over a LAN, VM network, container bridge, VPN or other routed network, and the issue does not grant remote code execution.
Fix: Fixed in 1.13.1.
NVD/CVE DatabaseGHSA-33f5-2c5q-wgwj: RMCP: Missing Resource Field Validation in OAuth Protected Resource Metadata Discovery
Sep 16, 2026HighVulnerabilitySecurityCVE-2026-63127The rmcp library does not validate the resource field in OAuth Protected Resource metadata (RFC 9728), so a malicious MCP server can point an OAuth flow at a legitimate authorization server. The victim completes the authorization prompt, and the resulting access token, valid for the legitimate server, is sent to the attacker's server, which can then impersonate the victim. All MCP clients built on rmcp that use OAuth-protected MCP servers are affected.
Fix: Recommended fix: (1) Add a `resource: Option<String>` field to the `ResourceServerMetadata` struct in `crates/rmcp/src/transport/auth.rs`. (2) After fetching the metadata, compare the `resource` value with the configured base URL (ignoring trailing slashes) and return a `MetadataError` on mismatch.
GitHub Advisory DatabaseGoogle will now let any AI agent run your smart home
Sep 16, 2026InfoNewsIndustrySecurityGoogle is opening its smart home platform to third-party AI agents through a new Google Home MCP integration. The integration lets agents that support the Model Context Protocol, including Claude and Open Claw, control and monitor connected devices and access event history.
The Verge (AI)CVE-2026-57442: MCPVault path filter bypass in nested .git and .obsidian directories
Sep 15, 2026MediumVulnerabilitySecurityCVE-2026-57442MCPVault, a Model Context Protocol server for accessing files in an Obsidian vault, uses root-anchored deny-list patterns in PathFilter (src/pathfilter.ts) prior to 0.11.5. Nested .git, .obsidian, and node_modules path segments therefore pass isAllowed() and isAllowedForListing(). An attacker who influences a path chosen by an AI agent can read nested repository or Obsidian metadata, such as remote URLs or embedded tokens, or pollute the listAllTags index with nested node_modules content.
Fix: Fixed in 0.11.5.
NVD/CVE DatabaseCVE-2026-57441: MCPVault path filter bypass via case variants and trailing dots
Sep 15, 2026MediumVulnerabilitySecurityCVE-2026-57441Prior to version 0.11.4, MCPVault's PathFilter in src/pathfilter.ts matched restricted directory patterns case-sensitively and compared paths without canonicalizing filesystem-equivalent names. On case-insensitive macOS and Windows filesystems, case variants of .git, .obsidian, or node_modules, and Windows names with trailing dots or spaces, bypassed both isAllowed() and isAllowedForListing(). An attacker who influences a path selected by an AI agent can use this in read, write, move, search, or listing operations to expose or modify sensitive repository and Obsidian metadata. Vault-root .. containment is not affected.
Fix: Fixed in version 0.11.4.
NVD/CVE Database
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.