Model Context Protocol
The Model Context Protocol and the servers and clients that expose tools and data to models through it.
- All items
- 295
- Last 90 days
- 133
- Change
- +53%vs 87 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 2 |
| Jun 2025 | 4 |
| Jul 2025 | 4 |
| Aug 2025 | 7 |
| Sep 2025 | 3 |
| Oct 2025 | 3 |
| Nov 2025 | 2 |
| Dec 2025 | 4 |
| Jan 2026 | 4 |
| Feb 2026 | 12 |
| Mar 2026 | 22 |
| Apr 2026 | 27 |
| May 2026 | 31 |
| Jun 2026 | 25 |
| Jul 2026 | 43 |
| Aug 2026 | 45 |
| Sep 2026 | 40 |
| Oct 2026 | 16 |
198 items
GHSA-f6pj-qv47-g96w: MCP Atlassian: Arbitrary server-local file upload to Jira/Confluence attachments via unrestricted file_path parameters
Sep 22, 2026HighVulnerabilitySecurityCVE-2026-77247The Jira and Confluence attachment upload tools in MCP Atlassian accept caller-controlled file_path parameters and read those paths from the MCP server's local filesystem before uploading them as Atlassian attachments. In local stdio deployments this exposes files readable by the user's MCP process, while in HTTP/SSE or streamable-http deployments any MCP client permitted to invoke upload tools can make the server read a server-local file and upload it to Jira or Confluence. The flaw is deterministic and does not depend on prompt injection or model behavior.
Fix: Server-local file uploads should be denied by default in HTTP/SSE or multi-user deployments, or uploads should be constrained to an explicit allowlisted upload directory after realpath resolution, and dangerous path forms such as remote UNC paths and file:// URLs should be rejected before filesystem checks.
GitHub Advisory DatabaseGHSA-p6hp-93wp-fh6p: MCP Atlassian: Path Traversal / Arbitrary File Read in confluence_upload_attachment MCP tool (incomplete fix of GHSA-xjgw-4wvw-rgm4)
Sep 22, 2026HighVulnerabilitySecurityCVE-2026-77262The mcp-atlassian server's confluence_upload_attachment MCP tool passes its file_path argument straight to open(file_path, "rb") with no path validation, so a caller can read arbitrary files the server process can read and upload them to an attacker-controlled Confluence host. With the default streamable-http transport binding 0.0.0.0 without authentication, this is remotely exploitable without credentials. It is the read-side counterpart of GHSA-xjgw-4wvw-rgm4 / CVE-2026-27825, whose fix in v0.17.0 covered only the download path.
GitHub Advisory DatabaseGHSA-f26r-j276-ggg4: MCP Atlassian: Arbitrary File Read via Upload Attachment Tools
Sep 22, 2026MediumVulnerabilitySecurityCVE-2026-77270The upload_attachment methods in MCP Atlassian's Confluence and Jira integrations accept arbitrary file paths without path traversal validation. The validate_safe_path utility is used in the download paths but never called in the upload paths, so an authenticated MCP client, or an AI assistant manipulated via prompt injection, can read any file the server process can access and upload it to an attacker-chosen Confluence page or Jira issue.
GitHub Advisory DatabaseGHSA-jjhp-8crj-mppq: @roomi-fields/notebooklm-mcp has a path traversal in vault.batch tool that allows arbitrary file write outside intended vault directory
Sep 22, 2026HighVulnerabilitySecurityCVE-2026-61647The vault_batch MCP tool and the POST /batch-to-vault HTTP endpoint in @roomi-fields/notebooklm-mcp passed a caller-supplied vault_dir directly to path.resolve() and fs.mkdir() with no containment check, and slug_prefix was concatenated into filenames without sanitization. Affected versions run from v1.6.0 through v2.0.2, and an attacker, or a prompt-injected LLM driving the MCP, could write .md and .json files to any location the server process can write, such as autostart folders or shell startup files.
Fix: Fixed in v2.0.3: set the NOTEBOOKLM_VAULT_ROOT environment variable to a directory that bounds all vault writes, which enables realpath-based containment, since it is unset by default and the legacy unrestricted behaviour remains when it is unset. slug_prefix is now always sanitized regardless of that variable. Users who cannot upgrade should run the server under a dedicated unprivileged user with write access only to the intended vault directory, keep the HTTP endpoint off non-localhost interfaces, and validate vault_dir arguments before forwarding them.
GitHub Advisory DatabaseGHSA-qg2g-g9w3-m5h8: ToolHive: containerized MCP servers can reach host services via host.docker.internal, enabling lateral movement
Sep 18, 2026HighVulnerabilitySecurityCVE-2026-58197A containerized MCP server running under the default `network` permission profile (`insecure_allow_all: true`) can reach host-local services through `host.docker.internal`, including the ToolHive API, other ToolHive-managed MCP server proxies, and other localhost services. Because the ToolHive API and MCP proxy endpoints are unauthenticated, a compromised or malicious MCP server can move laterally without a container escape. The source rates the severity High.
GitHub Advisory DatabaseCVE-2026-54504: MCP Documentation Server Web UI exposes unauthenticated document API
Sep 17, 2026HighVulnerabilitySecurityCVE-2026-54504MCP Documentation Server versions 1.13.0 through 1.13.1 start a Web UI by default on port 3080, and startWebServer in src/web-server.ts calls app.listen(PORT) without a host, binding the unauthenticated document-management API to all interfaces instead of localhost. A network-reachable client can call endpoints such as GET /api/documents, POST /api/documents, DELETE /api/documents/:id and POST /api/search-all without credentials to read, search, insert or delete documents and alter the assistant's knowledge base. The attacker must be able to reach the service over a LAN, VM network, container bridge, VPN or other routed network, and the issue does not grant remote code execution.
Fix: Fixed in 1.13.1.
NVD/CVE DatabaseGHSA-33f5-2c5q-wgwj: RMCP: Missing Resource Field Validation in OAuth Protected Resource Metadata Discovery
Sep 16, 2026HighVulnerabilitySecurityCVE-2026-63127The rmcp library does not validate the resource field in OAuth Protected Resource metadata (RFC 9728), so a malicious MCP server can point an OAuth flow at a legitimate authorization server. The victim completes the authorization prompt, and the resulting access token, valid for the legitimate server, is sent to the attacker's server, which can then impersonate the victim. All MCP clients built on rmcp that use OAuth-protected MCP servers are affected.
Fix: Recommended fix: (1) Add a `resource: Option<String>` field to the `ResourceServerMetadata` struct in `crates/rmcp/src/transport/auth.rs`. (2) After fetching the metadata, compare the `resource` value with the configured base URL (ignoring trailing slashes) and return a `MetadataError` on mismatch.
GitHub Advisory DatabaseCVE-2026-57442: MCPVault path filter bypass in nested .git and .obsidian directories
Sep 15, 2026MediumVulnerabilitySecurityCVE-2026-57442MCPVault, a Model Context Protocol server for accessing files in an Obsidian vault, uses root-anchored deny-list patterns in PathFilter (src/pathfilter.ts) prior to 0.11.5. Nested .git, .obsidian, and node_modules path segments therefore pass isAllowed() and isAllowedForListing(). An attacker who influences a path chosen by an AI agent can read nested repository or Obsidian metadata, such as remote URLs or embedded tokens, or pollute the listAllTags index with nested node_modules content.
Fix: Fixed in 0.11.5.
NVD/CVE DatabaseCVE-2026-57441: MCPVault path filter bypass via case variants and trailing dots
Sep 15, 2026MediumVulnerabilitySecurityCVE-2026-57441Prior to version 0.11.4, MCPVault's PathFilter in src/pathfilter.ts matched restricted directory patterns case-sensitively and compared paths without canonicalizing filesystem-equivalent names. On case-insensitive macOS and Windows filesystems, case variants of .git, .obsidian, or node_modules, and Windows names with trailing dots or spaces, bypassed both isAllowed() and isAllowedForListing(). An attacker who influences a path selected by an AI agent can use this in read, write, move, search, or listing operations to expose or modify sensitive repository and Obsidian metadata. Vault-root .. containment is not affected.
Fix: Fixed in version 0.11.4.
NVD/CVE DatabaseCVE-2026-12763: IBM Langflow OSS cross-user MCP server context access via cache key isolation
Sep 14, 2026MediumVulnerabilitySecurityCVE-2026-12763IBM Langflow OSS versions 1.0.0 through 1.11.5 contain a flaw in the MCP Tools component. An authenticated attacker can reach another user's MCP server context because cache keys are not properly isolated.
NVD/CVE DatabaseCVE-2026-81941: IBM Langflow OSS command execution through MCP Tools stdio transport
Sep 10, 2026HighVulnerabilitySecurityCVE-2026-81941IBM Langflow OSS versions 1.0.0 through 1.11.5 contain CVE-2026-81941. An authenticated non-administrative user can build a flow with an MCP Tools component set to a local stdio subprocess transport and run arbitrary operating system commands at the privilege level of the application process. This bypasses the LANGFLOW_CUSTOM_COMPONENT_ADMIN_ONLY and LANGFLOW_BLOCK_CODE_INTERPRETER_COMPONENTS server-side controls. Successful exploitation could expose credentials from the process environment, modify the file system, and reach other services on the server.
NVD/CVE DatabaseCVE-2026-88938: knowns code.find MCP tool path traversal reads files outside project
Sep 10, 2026MediumVulnerabilitySecurityCVE-2026-88938knowns through 0.33.0 does not confine the path argument of its code.find MCP tool to the project root. An attacker can supply absolute paths or relative traversal sequences to read full contents of source files anywhere on the host, from AI agent sessions.
NVD/CVE DatabaseGHSA-wcjj-9m6g-2fr2: functype-mcp-server: MCP `set_functype_version` Package Alias RCE via Unsanitized pnpm install + Dynamic Import
Sep 9, 2026HighVulnerabilitySecurityCVE-2026-59176The `set_functype_version` MCP tool in `functype-mcp-server` accepts an unvalidated `version` string and interpolates it into `functype@<version>`, which `pnpm add` installs without checks. Because package specifiers accept `file:` and `npm:` alias syntax, a client sending an MCP `tools/call` request can make the server install an arbitrary local or remote package as `functype`. The server then calls `initDocsData(true)`, which dynamically imports `functype/cli` from that package, executing attacker-controlled JavaScript in the MCP server process as remote code execution with the server's privileges (CVSS 7.8 High).
GitHub Advisory DatabaseCVE-2026-87912 and CVE-2026-87913: Missing S3 bucket ownership verification in the AWS Security Agent plugin for aws-agents-for-devsecops and MCP Server
Sep 9, 2026HighVulnerabilitySecurityIndustryCVE-2026-87912 affects the AWS Security Agent plugin in aws-agents-for-devsecops before version 1.1.0, and CVE-2026-87913 affects the AWS Security Agent MCP server before 0.2.0. Both stem from missing S3 bucket ownership verification, which may let remote attackers obtain the private source archive of a scanned workspace, including credentials and infrastructure state, via a pre-registered storage bucket whose name is derived from a publicly known account identifier. Impacted versions are <=1.0.0 and >=0.1.0 AND <=0.1.5.
Fix: Upgrade the aws-agents-for-devsecops plugin to version 1.1.0 or later, and the AWS Security Agent MCP server to version 0.2.0 or later.
AWS Security BulletinsCVE-2026-85654 - Code injection in the CDK generator in Amazon awslabs.dynamodb-mcp-server
Sep 4, 2026HighVulnerabilitySecurityCVE-2026-85654 is a code injection flaw in the CDK generator component of Amazon awslabs.dynamodb-mcp-server, an open-source MCP server for DynamoDB. Improper neutralization of special elements in a template engine lets a context-dependent actor run arbitrary code on the host that deploys the generated application, using crafted table, index, or attribute names in a data model file. Impacted versions are >= 2.0.10 AND <= 2.1.5.
AWS Security BulletinsGHSA-h539-c7r8-3xq4: CodeWhale: js_execution leaks parent environment to model context via missing env scrub
Sep 4, 2026HighVulnerabilitySecurityIndustryCVE-2026-75915The js_execution tool in CodeWhale spawns Node with tokio::process::Command::new without calling env_clear or the child_env scrubber that exec_shell, the Python REPL and the MCP launcher use. Model-provided JavaScript can therefore read process.env, and its output returns to the next model turn, exposing API keys, cloud credentials and forge tokens. With auto_approve enabled (YOLO mode), the JS runs without any prompt, so a prompt injection from a README, web page or MCP output can drain the environment.
Fix: Fixed in 0.8.64 (commit 26de44a8bd5051f8f944ea60b2c37ae1d2b7d25e). Users should upgrade to 0.8.64 or later.
GitHub Advisory DatabaseCVE-2026-9186: IBM Langflow OSS MCP configuration bypass via spoofed X-Forwarded-For header
Sep 4, 2026MediumVulnerabilitySecurityCVE-2026-9186IBM Langflow OSS versions 1.0.0 through 1.11.2 contain a flaw tracked as CVE-2026-9186. Remote authenticated attackers can bypass the localhost-only restriction on MCP configuration installation by spoofing the X-Forwarded-For: 127.0.0.1 header. This allows arbitrary writes to IDE configuration files such as ~/.cursor/mcp.json.
NVD/CVE DatabaseCVE-2026-85666: OGX server-side request forgery via MCP server_url in /v1/responses
Sep 4, 2026HighVulnerabilitySecurityCVE-2026-85666OGX (formerly Llama Stack, affected at commit fbe8e0f) has an unauthenticated server-side request forgery flaw in the OpenAI-compatible POST /v1/responses endpoint. The server_url parameter in MCP tool definitions is fetched server-side without the validate_url_not_private() check used for other URL inputs. On the default starter configuration, which runs without authentication, a remote attacker can make the server connect to arbitrary internal addresses, including cloud metadata endpoints such as http://169.254.169.254/, and forward attacker-supplied headers and bearer tokens to them.
NVD/CVE DatabaseCVE-2026-84779: Agentimus AI SEO, llms.txt & MCP for AI Agents broken access control
Sep 3, 2026HighVulnerabilitySecurityCVE-2026-84779CVE-2026-84779 is a Subscriber Broken Access Control flaw in Agentimus – AI SEO, llms.txt & MCP for AI Agents, affecting versions up to and including 1.51.0. The source text provides no further detail on how the flaw is reached or what an attacker gains.
NVD/CVE DatabaseGHSA-78x9-fhhx-v2g6: CKAN MCP Server: Cache-key canonicalization collision enables cache confusion / poisoning
Sep 3, 2026MediumVulnerabilitySecurityCVE-2026-73846The CKAN MCP Server response cache builds its key from an ambiguous serialization of request parameters, because canonicalizeParams does not escape the & and = delimiters or the | separator used in buildCacheKey. Two distinct parameter sets can therefore produce the same key, so an attacker who primes a colliding entry on a shared cache can cause another client's different query to receive the attacker's cached response.
Fix: Build the cache key from an unambiguous, injection-proof encoding: hash a structured, canonical JSON with typed values, or percent-encode or escape each key and value before joining, using a separator that cannot appear in the encoded fields. Include a type tag so object and string values never coincide. Consider partitioning the cache per client or tenant on shared deployments.
GitHub Advisory Database
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.