Model Context Protocol
The Model Context Protocol and the servers and clients that expose tools and data to models through it.
- All items
- 295
- Last 90 days
- 133
- Change
- +53%vs 87 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 2 |
| Jun 2025 | 4 |
| Jul 2025 | 4 |
| Aug 2025 | 7 |
| Sep 2025 | 3 |
| Oct 2025 | 3 |
| Nov 2025 | 2 |
| Dec 2025 | 4 |
| Jan 2026 | 4 |
| Feb 2026 | 12 |
| Mar 2026 | 22 |
| Apr 2026 | 27 |
| May 2026 | 31 |
| Jun 2026 | 25 |
| Jul 2026 | 43 |
| Aug 2026 | 45 |
| Sep 2026 | 40 |
| Oct 2026 | 16 |
295 items
CVE-2026-12763: IBM Langflow OSS cross-user MCP server context access via cache key isolation
Sep 14, 2026MediumVulnerabilitySecurityCVE-2026-12763IBM Langflow OSS versions 1.0.0 through 1.11.5 contain a flaw in the MCP Tools component. An authenticated attacker can reach another user's MCP server context because cache keys are not properly isolated.
NVD/CVE DatabaseCVE-2026-81941: IBM Langflow OSS command execution through MCP Tools stdio transport
Sep 10, 2026HighVulnerabilitySecurityCVE-2026-81941IBM Langflow OSS versions 1.0.0 through 1.11.5 contain CVE-2026-81941. An authenticated non-administrative user can build a flow with an MCP Tools component set to a local stdio subprocess transport and run arbitrary operating system commands at the privilege level of the application process. This bypasses the LANGFLOW_CUSTOM_COMPONENT_ADMIN_ONLY and LANGFLOW_BLOCK_CODE_INTERPRETER_COMPONENTS server-side controls. Successful exploitation could expose credentials from the process environment, modify the file system, and reach other services on the server.
NVD/CVE DatabaseCVE-2026-88938: knowns code.find MCP tool path traversal reads files outside project
Sep 10, 2026MediumVulnerabilitySecurityCVE-2026-88938knowns through 0.33.0 does not confine the path argument of its code.find MCP tool to the project root. An attacker can supply absolute paths or relative traversal sequences to read full contents of source files anywhere on the host, from AI agent sessions.
NVD/CVE DatabaseGHSA-wcjj-9m6g-2fr2: functype-mcp-server: MCP `set_functype_version` Package Alias RCE via Unsanitized pnpm install + Dynamic Import
Sep 9, 2026HighVulnerabilitySecurityCVE-2026-59176The `set_functype_version` MCP tool in `functype-mcp-server` accepts an unvalidated `version` string and interpolates it into `functype@<version>`, which `pnpm add` installs without checks. Because package specifiers accept `file:` and `npm:` alias syntax, a client sending an MCP `tools/call` request can make the server install an arbitrary local or remote package as `functype`. The server then calls `initDocsData(true)`, which dynamically imports `functype/cli` from that package, executing attacker-controlled JavaScript in the MCP server process as remote code execution with the server's privileges (CVSS 7.8 High).
GitHub Advisory DatabaseCVE-2026-87912 and CVE-2026-87913: Missing S3 bucket ownership verification in the AWS Security Agent plugin for aws-agents-for-devsecops and MCP Server
Sep 9, 2026HighVulnerabilitySecurityIndustryCVE-2026-87912 affects the AWS Security Agent plugin in aws-agents-for-devsecops before version 1.1.0, and CVE-2026-87913 affects the AWS Security Agent MCP server before 0.2.0. Both stem from missing S3 bucket ownership verification, which may let remote attackers obtain the private source archive of a scanned workspace, including credentials and infrastructure state, via a pre-registered storage bucket whose name is derived from a publicly known account identifier. Impacted versions are <=1.0.0 and >=0.1.0 AND <=0.1.5.
Fix: Upgrade the aws-agents-for-devsecops plugin to version 1.1.0 or later, and the AWS Security Agent MCP server to version 0.2.0 or later.
AWS Security BulletinsCVE-2026-85654 - Code injection in the CDK generator in Amazon awslabs.dynamodb-mcp-server
Sep 4, 2026HighVulnerabilitySecurityCVE-2026-85654 is a code injection flaw in the CDK generator component of Amazon awslabs.dynamodb-mcp-server, an open-source MCP server for DynamoDB. Improper neutralization of special elements in a template engine lets a context-dependent actor run arbitrary code on the host that deploys the generated application, using crafted table, index, or attribute names in a data model file. Impacted versions are >= 2.0.10 AND <= 2.1.5.
AWS Security BulletinsGHSA-h539-c7r8-3xq4: CodeWhale: js_execution leaks parent environment to model context via missing env scrub
Sep 4, 2026HighVulnerabilitySecurityIndustryCVE-2026-75915The js_execution tool in CodeWhale spawns Node with tokio::process::Command::new without calling env_clear or the child_env scrubber that exec_shell, the Python REPL and the MCP launcher use. Model-provided JavaScript can therefore read process.env, and its output returns to the next model turn, exposing API keys, cloud credentials and forge tokens. With auto_approve enabled (YOLO mode), the JS runs without any prompt, so a prompt injection from a README, web page or MCP output can drain the environment.
Fix: Fixed in 0.8.64 (commit 26de44a8bd5051f8f944ea60b2c37ae1d2b7d25e). Users should upgrade to 0.8.64 or later.
GitHub Advisory DatabaseCVE-2026-9186: IBM Langflow OSS MCP configuration bypass via spoofed X-Forwarded-For header
Sep 4, 2026MediumVulnerabilitySecurityCVE-2026-9186IBM Langflow OSS versions 1.0.0 through 1.11.2 contain a flaw tracked as CVE-2026-9186. Remote authenticated attackers can bypass the localhost-only restriction on MCP configuration installation by spoofing the X-Forwarded-For: 127.0.0.1 header. This allows arbitrary writes to IDE configuration files such as ~/.cursor/mcp.json.
NVD/CVE DatabaseCVE-2026-85666: OGX server-side request forgery via MCP server_url in /v1/responses
Sep 4, 2026HighVulnerabilitySecurityCVE-2026-85666OGX (formerly Llama Stack, affected at commit fbe8e0f) has an unauthenticated server-side request forgery flaw in the OpenAI-compatible POST /v1/responses endpoint. The server_url parameter in MCP tool definitions is fetched server-side without the validate_url_not_private() check used for other URL inputs. On the default starter configuration, which runs without authentication, a remote attacker can make the server connect to arbitrary internal addresses, including cloud metadata endpoints such as http://169.254.169.254/, and forward attacker-supplied headers and bearer tokens to them.
NVD/CVE DatabaseCVE-2026-84779: Agentimus AI SEO, llms.txt & MCP for AI Agents broken access control
Sep 3, 2026HighVulnerabilitySecurityCVE-2026-84779CVE-2026-84779 is a Subscriber Broken Access Control flaw in Agentimus – AI SEO, llms.txt & MCP for AI Agents, affecting versions up to and including 1.51.0. The source text provides no further detail on how the flaw is reached or what an attacker gains.
NVD/CVE DatabaseGHSA-78x9-fhhx-v2g6: CKAN MCP Server: Cache-key canonicalization collision enables cache confusion / poisoning
Sep 3, 2026MediumVulnerabilitySecurityCVE-2026-73846The CKAN MCP Server response cache builds its key from an ambiguous serialization of request parameters, because canonicalizeParams does not escape the & and = delimiters or the | separator used in buildCacheKey. Two distinct parameter sets can therefore produce the same key, so an attacker who primes a colliding entry on a shared cache can cause another client's different query to receive the attacker's cached response.
Fix: Build the cache key from an unambiguous, injection-proof encoding: hash a structured, canonical JSON with typed values, or percent-encode or escape each key and value before joining, using a separator that cannot appear in the encoded fields. Include a type tag so object and string values never coincide. Consider partitioning the cache per client or tenant on shared deployments.
GitHub Advisory DatabaseAI Agent Firewall Startup AIR Security Emerges From Stealth With $50 Million
Sep 3, 2026InfoNewsSecurityIndustryAIR Security has emerged from stealth with $50 million in funding, led by Sequoia Capital and Greenoaks, for a firewall that protects AI agents. Its research found more than 17,800 public AI add-ons (6.7M installations) relying on untrusted external instruction sources, and AI Skills impersonating Anthropic and OpenAI. The firewall screens skills, plugins, MCP servers and add-ons before and after deployment and can revoke them organization-wide.
SecurityWeekGHSA-83x6-42hr-jc76: CKAN MCP Server: MQA server allowlist bypass via unanchored regex (`isValidMqaServer`)
Sep 2, 2026MediumVulnerabilitySecurityCVE-2026-73845The `ckan_get_mqa_quality` and `ckan_get_mqa_quality_details` tools in the CKAN MCP Server limit `server_url` to `dati.gov.it` using an unanchored regex in `isValidMqaServer`. URLs such as `https://dati.gov.it.attacker.com/x` and `https://dati.gov.it@attacker.com/x` pass validation, so the tools send requests to attacker-controlled hosts and return their responses to the caller.
Fix: Validate the parsed host instead of the raw string: parse the URL with `new URL()`, require the `https:` protocol, and compare `hostname` exactly against `dati.gov.it` or `www.dati.gov.it`. Anchoring the regex end-to-end (`/^https:\/\/(www\.)?dati\.gov\.it(\/|$)/i`) also closes the suffix trick, but URL parsing with exact host comparison is the robust fix and also neutralizes the `@`-userinfo variant.
GitHub Advisory DatabaseCVE-2026-19591: OpenAI Codex CLI and Desktop approval bypass via PowerShell
Sep 1, 2026HighVulnerabilitySecurityCVE-2026-19591OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows and macOS misclassified certain PowerShell commands as safe because their command-safety parser read the stop-parsing token (--%) differently than PowerShell does. If a user opens an attacker-prepared repository and Codex follows its instructions, Codex can run a file-writing Git command without requesting approval. If filesystem protections permit the write, the attacker can modify Codex's configuration so that a later load launches an attacker-controlled MCP server, executing code with the user's privileges.
NVD/CVE DatabaseAIR raises $50M to help companies vet the skills and add-ons AI agents use
Sep 1, 2026InfoNewsSecurityIndustryAI security startup AIR has come out of stealth with $50 million raised across two seed rounds, led by Sequoia and Greenoaks, to build a product that monitors the supply chain of skills, plug-ins, MCP servers and add-ons used by AI agents. The platform discovers agents running in a company, vets their tools against a whitelist AIR maintains, and blocks those that fail security criteria. AIR says its platform currently filters out about 27% of the add-ons and skills it finds online.
TechCrunch (Security)CrowdStrike Falcon Guardian Defines the Next Generation of AI Security
Sep 1, 2026InfoNewsIndustrySecurityCrowdStrike is introducing Falcon Guardian, the evolution of Falcon AI Detection and Response (AIDR), to secure AI agents at runtime on Windows, macOS and Linux endpoints. The product discovers known and unknown agents and fuses their prompts, tool calls and MCP server use with endpoint telemetry to link prompts to downstream system actions. It also adds an AI gateway and extends MDR and cross-domain threat hunting to the platform.
CrowdStrike BlogCVE-2026-79745: MCPHub endpoints let non-admin users overwrite global records
Aug 31, 2026HighVulnerabilitySecurityCVE-2026-79745MCPHub, a hub for managing and orchestrating multiple MCP servers and APIs, performs no role checking on its built-in prompt and resource controllers before version 1.0.32. Any authenticated non-admin user can call the mutating POST/PUT /api/prompts* and POST/PUT /api/resources* routes, creating, overwriting or shadowing global prompt templates and resources that are served to all users. Because these records are consulted before any connected MCP server, the tampering can also lead to prompt injection in other users' LLM sessions.
Fix: Fixed in 1.0.32.
NVD/CVE DatabaseSecuring Claude Code: The New Compliance API, Local Visibility, and Identity Governance
Aug 31, 2026InfoNewsSecurityIndustryClaude Code runs file reads, shell commands and MCP tool calls on developers' machines, where the harness, not the LLM, executes actions and holds the credentials. Anthropic's new Compliance API endpoints give security teams a clearer view of that local activity, but the article argues activity logs alone cannot show whether an agent's access is legitimate. Token Security reports that local agents account for 68.6% of the AI agents it discovers in customer environments.
The Hacker NewsCVE-2026-82233: SiYuan path traversal in asset.upload MCP tool via absolute file paths
Aug 28, 2026MediumVulnerabilitySecurityIndustryCVE-2026-82233SiYuan before v3.8.1 has a path traversal flaw in its asset.upload MCP tool. The tool accepts arbitrary absolute file paths without validating them against the workspace boundary. An attacker can use prompt injection to make the AI Agent copy sensitive files such as SSH keys or credentials from outside the workspace into the asset directory.
NVD/CVE DatabaseInside 90 days of attacks on AI infrastructure
Aug 27, 2026MediumNewsSecurityIndustryWiz Threat Research reports 90 days of attack telemetry from honeypots imitating AI and ML services, including LiteLLM, Flowise, LangChain, Langflow, ChromaDB and Ollama. Attackers exploited an authentication bypass in LiteLLM's MCP Gateway (CVE-2026-59822), where a failed OAuth2 token check returns an unrestricted UserAPIKeyAuth() object, so any Bearer token grants full MCP access. They also abused a command injection in the MCP server test endpoints (CVE-2026-42271) to run a cryptominer, which is listed in CISA KEV as of June 2026.
Wiz Research Blog
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.