Model Context Protocol
The Model Context Protocol and the servers and clients that expose tools and data to models through it.
- All items
- 295
- Last 90 days
- 133
- Change
- +53%vs 87 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 2 |
| Jun 2025 | 4 |
| Jul 2025 | 4 |
| Aug 2025 | 7 |
| Sep 2025 | 3 |
| Oct 2025 | 3 |
| Nov 2025 | 2 |
| Dec 2025 | 4 |
| Jan 2026 | 4 |
| Feb 2026 | 12 |
| Mar 2026 | 22 |
| Apr 2026 | 27 |
| May 2026 | 31 |
| Jun 2026 | 25 |
| Jul 2026 | 43 |
| Aug 2026 | 45 |
| Sep 2026 | 40 |
| Oct 2026 | 16 |
198 items
GHSA-83x6-42hr-jc76: CKAN MCP Server: MQA server allowlist bypass via unanchored regex (`isValidMqaServer`)
Sep 2, 2026MediumVulnerabilitySecurityCVE-2026-73845The `ckan_get_mqa_quality` and `ckan_get_mqa_quality_details` tools in the CKAN MCP Server limit `server_url` to `dati.gov.it` using an unanchored regex in `isValidMqaServer`. URLs such as `https://dati.gov.it.attacker.com/x` and `https://dati.gov.it@attacker.com/x` pass validation, so the tools send requests to attacker-controlled hosts and return their responses to the caller.
Fix: Validate the parsed host instead of the raw string: parse the URL with `new URL()`, require the `https:` protocol, and compare `hostname` exactly against `dati.gov.it` or `www.dati.gov.it`. Anchoring the regex end-to-end (`/^https:\/\/(www\.)?dati\.gov\.it(\/|$)/i`) also closes the suffix trick, but URL parsing with exact host comparison is the robust fix and also neutralizes the `@`-userinfo variant.
GitHub Advisory DatabaseCVE-2026-19591: OpenAI Codex CLI and Desktop approval bypass via PowerShell
Sep 1, 2026HighVulnerabilitySecurityCVE-2026-19591OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows and macOS misclassified certain PowerShell commands as safe because their command-safety parser read the stop-parsing token (--%) differently than PowerShell does. If a user opens an attacker-prepared repository and Codex follows its instructions, Codex can run a file-writing Git command without requesting approval. If filesystem protections permit the write, the attacker can modify Codex's configuration so that a later load launches an attacker-controlled MCP server, executing code with the user's privileges.
NVD/CVE DatabaseCVE-2026-79745: MCPHub endpoints let non-admin users overwrite global records
Aug 31, 2026HighVulnerabilitySecurityCVE-2026-79745MCPHub, a hub for managing and orchestrating multiple MCP servers and APIs, performs no role checking on its built-in prompt and resource controllers before version 1.0.32. Any authenticated non-admin user can call the mutating POST/PUT /api/prompts* and POST/PUT /api/resources* routes, creating, overwriting or shadowing global prompt templates and resources that are served to all users. Because these records are consulted before any connected MCP server, the tampering can also lead to prompt injection in other users' LLM sessions.
Fix: Fixed in 1.0.32.
NVD/CVE DatabaseCVE-2026-82233: SiYuan path traversal in asset.upload MCP tool via absolute file paths
Aug 28, 2026MediumVulnerabilitySecurityIndustryCVE-2026-82233SiYuan before v3.8.1 has a path traversal flaw in its asset.upload MCP tool. The tool accepts arbitrary absolute file paths without validating them against the workspace boundary. An attacker can use prompt injection to make the AI Agent copy sensitive files such as SSH keys or credentials from outside the workspace into the asset directory.
NVD/CVE DatabaseGHSA-hvfh-5mj3-5f3j: Chainlist has SSRF via MCP SSE and streamable-http transports that allows unauthenticated internal network access
Aug 25, 2026HighVulnerabilitySecurityCVE-2026-45019Chainlist, the Chainlit MCP server component, contains a blind SSRF (CVE-2026-45019) in the POST /mcp endpoint for the sse and streamable-http transports when features.mcp.enabled is true. The endpoint accepts an unvalidated, user-controlled url and headers dictionary, and passes them to the MCP SDK's sse_client() or streamablehttp_client(), letting an unauthenticated attacker make the server send requests with attacker-chosen headers such as Authorization and Cookie. Affected ranges are >=2.4.0rc0 for URL-based SSRF and >=2.6.4 for header forwarding, both before 2.12.0.
Fix: Fixed in 2.12.0 (releasing 2026-08-25).
GitHub Advisory DatabaseGHSA-w3fx-mc44-mf6j: Chainlit has command injection via MCP stdio transport that allows unauthenticated remote code execution
Aug 25, 2026CriticalVulnerabilitySecurityCVE-2026-45018Chainlit versions from 2.4.0rc0 up to but not including 2.12.0 are affected when features.mcp.enabled is set to true in .chainlit/config.toml, tracked as CVE-2026-45018. The POST /mcp endpoint for stdio transport accepts a user-controlled fullCommand string, and validate_mcp_command() checks only the executable name against allowed_executables without restricting its arguments, so an unauthenticated attacker can pass npx -y -c with a payload to run arbitrary shell commands with the privileges of the Chainlit process. Since v2.7.0, MCP is disabled by default.
Fix: Fixed in 2.12.0. The fix removes fullCommand from the client request; stdio MCP servers are declared by the developer in .chainlit/config.toml under [[features.mcp.servers]] and selected by name, and per-server environment variables are set via an env mapping on the server entry. The source's Workarounds section is empty, so no interim workaround is stated.
GitHub Advisory DatabaseGHSA-m9mq-7m7q-xc6p: browse-mcp has an arbitrary file write via unconfined download and state paths
Aug 25, 2026HighVulnerabilitySecurityCVE-2026-55557browse-mcp, an MCP server, has an arbitrary file write flaw in `browser_download`, `browser_save_state` and `browser_load_state`. Their `save_dir` and `path` arguments are not validated, so a caller controlling the MCP arguments can write attacker-supplied response bytes to any path the process can reach, such as `~/.bashrc` or a cron file, which can lead to host code execution. The `force_fetch` fallback also bypassed the `BROWSE_MCP_ALLOWED_ORIGINS` origin fence. The estimated CVSS 3.1 score is around 7.8 (High) for the local, agent-mediated case.
Fix: Fixed in 0.8.2. Upgrade to browse-mcp 0.8.2. The fix confines `save_dir` under `~/.browse-mcp/downloads` and the state `path` under `~/.browse-mcp/state`, rejects absolute paths and `..` escapes, reduces download filenames to a bare basename, and makes `force_fetch` honor the origin fence. Workaround: restrict `BROWSE_MCP_TOOLS` to exclude `browser_download`, `browser_save_state` and `browser_load_state`, noting this does not stop a malicious MCP client from calling them by name.
GitHub Advisory DatabaseCVE-2026-55640: Nextcloud MCP Server unauthenticated webhook allows forged vector index changes
Aug 25, 2026CriticalVulnerabilitySecurityCVE-2026-55640CVE-2026-55640 affects the Nextcloud MCP Server before 0.117.2. The POST /webhooks/nextcloud endpoint in nextcloud_mcp_server/vector/webhook_receiver.py accepts unauthenticated requests when WEBHOOK_SECRET is unset, which is the default, because startup validation does not require it. The payload["user"]["uid"] field from webhook_parser.py is attacker-controlled and used for Qdrant operations without an authenticated-session cross-check, so a network attacker can delete or trigger re-indexing of vector embeddings for any user and destroy the semantic search index with forged deletion events.
Fix: Fixed in 0.117.2.
NVD/CVE DatabaseGHSA-f5pj-2738-996m: mcp-shell — Security Disabled by Default in Bare-Binary Deploy Path + Shell Interpreter in Secure-Mode Allowlist
Aug 25, 2026HighVulnerabilitySecurityCVE-2026-55580mcp-shell at commit 17ac0eef5c9a5a42b8fb132d3d034973d55a5433 ships with its security layer disabled: config.go sets SecurityConfig Enabled to false, and the from-source install path and MCP client example never set MCP_SHELL_SEC_CONFIG_FILE, so any connected LLM can call shell_exec with arbitrary commands. Separately, the official security.yaml baked into the Docker image lists /bin/bash and /usr/bin/python3 in allowed_executables, so secure mode can be bypassed by calling /bin/bash -i, which passes validation and yields an interactive shell.
Fix: Flip the default to SecurityConfig{Enabled: true}, making secure mode the operating default, and keep unrestricted mode behind an affirmative opt-in flag or environment variable such as --allow-unsafe.
GitHub Advisory DatabaseGHSA-3x77-wg38-92r3: mcp-shell has a Secure Mode Allowlist Bypass via Default `/bin/bash` Executable
Aug 25, 2026HighVulnerabilitySecurityCVE-2026-55581mcp-shell's default Docker configuration (security.yaml) includes /bin/bash in allowed_executables, and the command validator in security.go checks only the first token, so it does not block shell flags such as -c. Any MCP tool caller can send command=/bin/bash -c <arbitrary-command> to shell_exec, with no authentication or configuration changes needed, and run binaries outside the allowlist as mcpuser inside the container.
GitHub Advisory DatabaseGHSA-74hp-mggr-hv58: mcp-shell has a Secure Mode Allowlist Bypass via Git Shell Alias
Aug 25, 2026HighVulnerabilitySecurityCVE-2026-55582mcp-shell's secure mode, which restricts execution to an allowlist defined in security.yaml, can be bypassed through the shell_exec MCP tool. The default allowlist includes /usr/bin/git, and the metacharacter validator in security.go omits the ! character, which Git uses for shell aliases, so passing /usr/bin/git -c alias.pwn=!<command> yields arbitrary OS command execution as the mcp-shell process user, with no authentication required in the default Docker deployment.
GitHub Advisory DatabaseGHSA-pvph-5j39-v8qc: PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MCP HTTP server
Aug 25, 2026HighVulnerabilitySecurityCVE-2026-55532The PraisonAI MCP server's HTTP-stream transport, started with praisonai mcp serve --transport http-stream, validates Origin with a startswith prefix match against http://localhost and http://127.0.0.1. An attacker can therefore host a page on a hostname such as localhost.attacker.com, and when a victim visits it, the server accepts and executes unauthenticated cross-site requests, including a tools/call that creates a rule file with activation "always" to inject persistent prompt instructions into later agent runs. The request can be sent as a CORS simple request with Content-Type: text/plain, requiring no preflight, and no session is needed for tools/call. This is a blind CSRF against a local agent runtime.
GitHub Advisory DatabaseCVE-2026-62674: Omnigent shared agent replacement enables command execution via MCP
Aug 21, 2026CriticalVulnerabilitySecurityCVE-2026-62674CVE-2026-62674 affects Omnigent, an open-source AI agent framework and meta-harness, before version 0.3.0. The PUT /sessions/{session_id}/agent endpoint checks LEVEL_EDIT permission but does not reject a bound shared or template agent whose agent.session_id is None. An authenticated user with edit access to a session can replace that shared agent bundle, add a stdio MCP server, and cause later sessions using the shared agent to run an attacker-controlled command with the Omnigent runner's permissions, exposing files, credentials, workspace data, internal services, and runner availability.
Fix: Fixed in version 0.3.0.
NVD/CVE DatabaseCVE-2026-18482: Neo.mjs command injection in FileSystemService.mjs via checkSyntax
Aug 20, 2026HighVulnerabilitySecurityCVE-2026-18482CVE-2026-18482 is a command injection vulnerability in the FileSystemService.mjs component of the ai/mcp/server/file-system MCP server in Neo.mjs. The checkSyntax() and runPlaywrightTest() functions unsafely interpolate caller-controlled absolutePath values into shell commands, enabling arbitrary OS command execution when an AI agent is induced to invoke these tools.
Fix: Commit 88c77fc fixes these vulnerabilities.
NVD/CVE DatabaseGHSA-wppf-h75h-6pm6: SearXNG MCP Server: Additional hardened-mode SSRF bypasses
Aug 19, 2026MediumVulnerabilitySecurityCVE-2026-54689GHSA-wppf-h75h-6pm6 reports that hardened mode in mcp-searxng's web_url_read still permits SSRF to internal addresses despite PR #79, which blocks only the DNS-resolves-to-loopback case. The reporter tested PR commit e55d28e7be6786a71cd7a0eaf13d3ec9d0b734d4 with MCP_HTTP_HARDEN=true and MCP_HTTP_ALLOW_PRIVATE_URLS unset, and found three bypasses: redirects to 127.0.0.1 are followed without re-validation, 0.0.0.0 is not treated as internal, and [::ffff:127.0.0.1] is canonicalized to [::ffff:7f00:1] and missed by the dotted-decimal regex. All three returned a loopback sentinel service.
GitHub Advisory DatabaseGHSA-q87f-qc2r-2gw4: SearXNG MCP Server is Vulnerable to SSRF in web_url_read: the internal-address guard is disabled by default (MCP_HTTP_HARDEN off)
Aug 19, 2026MediumVulnerabilitySecurityCVE-2026-54688The web_url_read tool in mcp-searxng 1.1.0 fetches caller-supplied URLs server-side, but its internal-address guard, assertUrlAllowed, runs only when MCP_HTTP_HARDEN=true, which is off by default. With default settings an attacker who can influence the URL can make the server fetch internal HTTP services and cloud metadata endpoints and return their contents, confirmed with a loopback request to 127.0.0.1.
Fix: Enable the internal-address filtering by default (fail safe): make assertUrlAllowed run unconditionally and require an explicit opt-out only for trusted environments. Strengthen the check to resolve the host and reject loopback, link-local/metadata (169.254.0.0/16), 0.0.0.0/8, and private ranges, and re-validate on every redirect hop (or pin to the validated IP).
GitHub Advisory DatabaseGHSA-2xhg-73j7-rrgx: Contentful MCP Server: export_space/import_space tools pass LLM-controlled `host`/`proxy` args to CMA client, redirecting server PAT to attacker-controlled endpoint
Aug 19, 2026HighVulnerabilitySecurityCVE-2026-53957The export_space and import_space tools in @contentful/mcp-tools accept LLM-controlled host and proxy parameters and spread them unfiltered into the options passed to contentful-export and contentful-import. Those options, including the server's CMA Personal Access Token, reach the Contentful Management API client, which sends the token as a Bearer header to the attacker-supplied host. An attacker who can invoke MCP tools, or plant instructions in Contentful content the LLM reads, can redirect CMA requests and the PAT to an attacker-controlled endpoint.
GitHub Advisory DatabaseGHSA-rr55-jp92-8wp2: claude-faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools
Aug 19, 2026HighVulnerabilitySecurityclaude-faf-mcp, an MCP server, resolves caller-supplied `path` arguments into filesystem reads and writes without confining them to a trusted project directory. A caller, or an LLM prompt-injected through attacker-controlled content, can read files such as SSH keys, cloud credentials and `.env` files, and `faf_write` can write outside the project.
Fix: Fixed in 5.7.2, which confines every caller-supplied `path` before filesystem access. Upgrade with `npm install -g claude-faf-mcp@5.7.2` or the one-click `.mcpb` install. Workaround if upgrading is not immediate: run the server only against trusted local projects and set `FAF_ALLOWED_ROOTS` (patched versions) to a single project directory.
GitHub Advisory DatabaseGHSA-j4r7-8ph4-43g3: faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools
Aug 19, 2026HighVulnerabilitySecurityfaf-mcp versions before 2.1.3 accept a caller-controlled `path` argument in the shared `getProjectPath()` chokepoint and the `faf_read` and `faf_write` tools, resolving it without confinement to a project directory. An MCP client, or a prompt-injected LLM issuing a tool call, can read files such as SSH keys, cloud credentials and `.env` files, and `faf_write` can write outside the project (CWE-200).
Fix: Fixed in 2.1.3, which confines every caller-supplied `path` before filesystem access. Upgrade with `npm install -g faf-mcp@2.1.3` or `npx faf-mcp`. If upgrading is not possible immediately, run the server only against trusted local projects and set `FAF_ALLOWED_ROOTS` (patched versions) to a single project directory.
GitHub Advisory DatabaseGHSA-cc2g-gq8c-r332: grok-faf-mcp has an arbitrary local file read via unconfined `path` argument in FAF tools
Aug 19, 2026HighVulnerabilitySecuritygrok-faf-mcp, an MCP server, has several FAF tools (refresh_faf, faf_score, faf_get_orchestration_policy, refresh_blend, faf_read, faf_write) that accept a caller-controlled path argument and read it without confinement to a trusted project directory. An MCP client, or an LLM prompt-injected through attacker-controlled content, can use absolute paths or ../ traversal to read files such as SSH keys, cloud credentials and .env files, with OS file permissions as the only remaining limit.
Fix: Fixed in 1.5.3, which confines every caller-supplied path before filesystem access: reads are restricted to .faf and .fafm context files, general file operations are confined to the project root (override with FAF_ALLOWED_ROOTS), paths are canonicalized through symlinks, and absolute paths and ../ escapes are rejected. Upgrade with `npm install -g grok-faf-mcp@1.5.3` or `bunx grok-faf-mcp`. If upgrading is not possible immediately, run the server only against trusted local projects and set FAF_ALLOWED_ROOTS to a single project directory.
GitHub Advisory Database
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.