Model Context Protocol
The Model Context Protocol and the servers and clients that expose tools and data to models through it.
- All items
- 295
- Last 90 days
- 133
- Change
- +53%vs 87 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 2 |
| Jun 2025 | 4 |
| Jul 2025 | 4 |
| Aug 2025 | 7 |
| Sep 2025 | 3 |
| Oct 2025 | 3 |
| Nov 2025 | 2 |
| Dec 2025 | 4 |
| Jan 2026 | 4 |
| Feb 2026 | 12 |
| Mar 2026 | 22 |
| Apr 2026 | 27 |
| May 2026 | 31 |
| Jun 2026 | 25 |
| Jul 2026 | 43 |
| Aug 2026 | 45 |
| Sep 2026 | 40 |
| Oct 2026 | 16 |
295 items
Extend Amazon Bedrock Guardrails to Tool Interactions Using the Strands Agents SDK
Aug 27, 2026InfoNewsSecurityIndustryAmazon Bedrock Guardrails validates model inputs and outputs, but data that flows through tool calls, external data sources and MCP servers sits outside the model boundary. The article proposes three validation checkpoints built with Strands Agents SDK lifecycle hooks and Amazon Bedrock guardrails to extend coverage to those trust boundaries without changing existing tools or agent logic. The first checkpoint, inbound data validation, uses a BeforeInvocationEvent hook to block policy-violating content before it reaches the model.
Fix: The source describes three validation checkpoints implemented with Strands Agents SDK lifecycle hooks (Checkpoint 1: inbound data validation using a BeforeInvocationEvent hook; Checkpoint 2: tool interaction supervision using a BeforeToolCallEvent hook; Checkpoint 3 is not visible in the excerpt), and scoping guardrails to specific tools. The excerpt does not state a patch or fixed version.
AWS Security BlogGHSA-hvfh-5mj3-5f3j: Chainlist has SSRF via MCP SSE and streamable-http transports that allows unauthenticated internal network access
Aug 25, 2026HighVulnerabilitySecurityCVE-2026-45019Chainlist, the Chainlit MCP server component, contains a blind SSRF (CVE-2026-45019) in the POST /mcp endpoint for the sse and streamable-http transports when features.mcp.enabled is true. The endpoint accepts an unvalidated, user-controlled url and headers dictionary, and passes them to the MCP SDK's sse_client() or streamablehttp_client(), letting an unauthenticated attacker make the server send requests with attacker-chosen headers such as Authorization and Cookie. Affected ranges are >=2.4.0rc0 for URL-based SSRF and >=2.6.4 for header forwarding, both before 2.12.0.
Fix: Fixed in 2.12.0 (releasing 2026-08-25).
GitHub Advisory DatabaseGHSA-w3fx-mc44-mf6j: Chainlit has command injection via MCP stdio transport that allows unauthenticated remote code execution
Aug 25, 2026CriticalVulnerabilitySecurityCVE-2026-45018Chainlit versions from 2.4.0rc0 up to but not including 2.12.0 are affected when features.mcp.enabled is set to true in .chainlit/config.toml, tracked as CVE-2026-45018. The POST /mcp endpoint for stdio transport accepts a user-controlled fullCommand string, and validate_mcp_command() checks only the executable name against allowed_executables without restricting its arguments, so an unauthenticated attacker can pass npx -y -c with a payload to run arbitrary shell commands with the privileges of the Chainlit process. Since v2.7.0, MCP is disabled by default.
Fix: Fixed in 2.12.0. The fix removes fullCommand from the client request; stdio MCP servers are declared by the developer in .chainlit/config.toml under [[features.mcp.servers]] and selected by name, and per-server environment variables are set via an env mapping on the server entry. The source's Workarounds section is empty, so no interim workaround is stated.
GitHub Advisory DatabaseGHSA-m9mq-7m7q-xc6p: browse-mcp has an arbitrary file write via unconfined download and state paths
Aug 25, 2026HighVulnerabilitySecurityCVE-2026-55557browse-mcp, an MCP server, has an arbitrary file write flaw in `browser_download`, `browser_save_state` and `browser_load_state`. Their `save_dir` and `path` arguments are not validated, so a caller controlling the MCP arguments can write attacker-supplied response bytes to any path the process can reach, such as `~/.bashrc` or a cron file, which can lead to host code execution. The `force_fetch` fallback also bypassed the `BROWSE_MCP_ALLOWED_ORIGINS` origin fence. The estimated CVSS 3.1 score is around 7.8 (High) for the local, agent-mediated case.
Fix: Fixed in 0.8.2. Upgrade to browse-mcp 0.8.2. The fix confines `save_dir` under `~/.browse-mcp/downloads` and the state `path` under `~/.browse-mcp/state`, rejects absolute paths and `..` escapes, reduces download filenames to a bare basename, and makes `force_fetch` honor the origin fence. Workaround: restrict `BROWSE_MCP_TOOLS` to exclude `browser_download`, `browser_save_state` and `browser_load_state`, noting this does not stop a malicious MCP client from calling them by name.
GitHub Advisory DatabaseCVE-2026-55640: Nextcloud MCP Server unauthenticated webhook allows forged vector index changes
Aug 25, 2026CriticalVulnerabilitySecurityCVE-2026-55640CVE-2026-55640 affects the Nextcloud MCP Server before 0.117.2. The POST /webhooks/nextcloud endpoint in nextcloud_mcp_server/vector/webhook_receiver.py accepts unauthenticated requests when WEBHOOK_SECRET is unset, which is the default, because startup validation does not require it. The payload["user"]["uid"] field from webhook_parser.py is attacker-controlled and used for Qdrant operations without an authenticated-session cross-check, so a network attacker can delete or trigger re-indexing of vector embeddings for any user and destroy the semantic search index with forged deletion events.
Fix: Fixed in 0.117.2.
NVD/CVE DatabaseGHSA-f5pj-2738-996m: mcp-shell — Security Disabled by Default in Bare-Binary Deploy Path + Shell Interpreter in Secure-Mode Allowlist
Aug 25, 2026HighVulnerabilitySecurityCVE-2026-55580mcp-shell at commit 17ac0eef5c9a5a42b8fb132d3d034973d55a5433 ships with its security layer disabled: config.go sets SecurityConfig Enabled to false, and the from-source install path and MCP client example never set MCP_SHELL_SEC_CONFIG_FILE, so any connected LLM can call shell_exec with arbitrary commands. Separately, the official security.yaml baked into the Docker image lists /bin/bash and /usr/bin/python3 in allowed_executables, so secure mode can be bypassed by calling /bin/bash -i, which passes validation and yields an interactive shell.
Fix: Flip the default to SecurityConfig{Enabled: true}, making secure mode the operating default, and keep unrestricted mode behind an affirmative opt-in flag or environment variable such as --allow-unsafe.
GitHub Advisory DatabaseGHSA-3x77-wg38-92r3: mcp-shell has a Secure Mode Allowlist Bypass via Default `/bin/bash` Executable
Aug 25, 2026HighVulnerabilitySecurityCVE-2026-55581mcp-shell's default Docker configuration (security.yaml) includes /bin/bash in allowed_executables, and the command validator in security.go checks only the first token, so it does not block shell flags such as -c. Any MCP tool caller can send command=/bin/bash -c <arbitrary-command> to shell_exec, with no authentication or configuration changes needed, and run binaries outside the allowlist as mcpuser inside the container.
GitHub Advisory DatabaseGHSA-74hp-mggr-hv58: mcp-shell has a Secure Mode Allowlist Bypass via Git Shell Alias
Aug 25, 2026HighVulnerabilitySecurityCVE-2026-55582mcp-shell's secure mode, which restricts execution to an allowlist defined in security.yaml, can be bypassed through the shell_exec MCP tool. The default allowlist includes /usr/bin/git, and the metacharacter validator in security.go omits the ! character, which Git uses for shell aliases, so passing /usr/bin/git -c alias.pwn=!<command> yields arbitrary OS command execution as the mcp-shell process user, with no authentication required in the default Docker deployment.
GitHub Advisory DatabaseGHSA-pvph-5j39-v8qc: PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MCP HTTP server
Aug 25, 2026HighVulnerabilitySecurityCVE-2026-55532The PraisonAI MCP server's HTTP-stream transport, started with praisonai mcp serve --transport http-stream, validates Origin with a startswith prefix match against http://localhost and http://127.0.0.1. An attacker can therefore host a page on a hostname such as localhost.attacker.com, and when a victim visits it, the server accepts and executes unauthenticated cross-site requests, including a tools/call that creates a rule file with activation "always" to inject persistent prompt instructions into later agent runs. The request can be sent as a CORS simple request with Content-Type: text/plain, requiring no preflight, and no session is needed for tools/call. This is a blind CSRF against a local agent runtime.
GitHub Advisory DatabaseMarimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode
Aug 25, 2026MediumNewsSecurityIndustryMarimo fixed a high-severity code injection flaw, CVE-2026-75149, in its notebook software affecting versions prior to 0.23.15. A crafted notebook can supply an attacker-controlled MCP server command through notebook configuration, and the command runs as a local subprocess when the victim opens the notebook in edit mode, before any cell executes. The CNA record assigns CVSS v4 8.7 and CVSS v3.1 8.8, requiring user interaction.
Fix: Marimo has addressed the issue in version 0.23.15. Users running an affected release should move to a version outside the affected range. Marimo's PEP 723 hardening patch treats notebook metadata as attacker-controlled and passes notebook-supplied configuration through an allowlist that removes the ai, mcp, completion, secrets and server sections.
The Hacker NewsCVE-2026-62674: Omnigent shared agent replacement enables command execution via MCP
Aug 21, 2026CriticalVulnerabilitySecurityCVE-2026-62674CVE-2026-62674 affects Omnigent, an open-source AI agent framework and meta-harness, before version 0.3.0. The PUT /sessions/{session_id}/agent endpoint checks LEVEL_EDIT permission but does not reject a bound shared or template agent whose agent.session_id is None. An authenticated user with edit access to a session can replace that shared agent bundle, add a stdio MCP server, and cause later sessions using the shared agent to run an attacker-controlled command with the Omnigent runner's permissions, exposing files, credentials, workspace data, internal services, and runner availability.
Fix: Fixed in version 0.3.0.
NVD/CVE DatabaseCVE-2026-18482: Neo.mjs command injection in FileSystemService.mjs via checkSyntax
Aug 20, 2026HighVulnerabilitySecurityCVE-2026-18482CVE-2026-18482 is a command injection vulnerability in the FileSystemService.mjs component of the ai/mcp/server/file-system MCP server in Neo.mjs. The checkSyntax() and runPlaywrightTest() functions unsafely interpolate caller-controlled absolutePath values into shell commands, enabling arbitrary OS command execution when an AI agent is induced to invoke these tools.
Fix: Commit 88c77fc fixes these vulnerabilities.
NVD/CVE DatabaseGHSA-wppf-h75h-6pm6: SearXNG MCP Server: Additional hardened-mode SSRF bypasses
Aug 19, 2026MediumVulnerabilitySecurityCVE-2026-54689GHSA-wppf-h75h-6pm6 reports that hardened mode in mcp-searxng's web_url_read still permits SSRF to internal addresses despite PR #79, which blocks only the DNS-resolves-to-loopback case. The reporter tested PR commit e55d28e7be6786a71cd7a0eaf13d3ec9d0b734d4 with MCP_HTTP_HARDEN=true and MCP_HTTP_ALLOW_PRIVATE_URLS unset, and found three bypasses: redirects to 127.0.0.1 are followed without re-validation, 0.0.0.0 is not treated as internal, and [::ffff:127.0.0.1] is canonicalized to [::ffff:7f00:1] and missed by the dotted-decimal regex. All three returned a loopback sentinel service.
GitHub Advisory DatabaseGHSA-q87f-qc2r-2gw4: SearXNG MCP Server is Vulnerable to SSRF in web_url_read: the internal-address guard is disabled by default (MCP_HTTP_HARDEN off)
Aug 19, 2026MediumVulnerabilitySecurityCVE-2026-54688The web_url_read tool in mcp-searxng 1.1.0 fetches caller-supplied URLs server-side, but its internal-address guard, assertUrlAllowed, runs only when MCP_HTTP_HARDEN=true, which is off by default. With default settings an attacker who can influence the URL can make the server fetch internal HTTP services and cloud metadata endpoints and return their contents, confirmed with a loopback request to 127.0.0.1.
Fix: Enable the internal-address filtering by default (fail safe): make assertUrlAllowed run unconditionally and require an explicit opt-out only for trusted environments. Strengthen the check to resolve the host and reject loopback, link-local/metadata (169.254.0.0/16), 0.0.0.0/8, and private ranges, and re-validate on every redirect hop (or pin to the validated IP).
GitHub Advisory DatabaseGHSA-2xhg-73j7-rrgx: Contentful MCP Server: export_space/import_space tools pass LLM-controlled `host`/`proxy` args to CMA client, redirecting server PAT to attacker-controlled endpoint
Aug 19, 2026HighVulnerabilitySecurityCVE-2026-53957The export_space and import_space tools in @contentful/mcp-tools accept LLM-controlled host and proxy parameters and spread them unfiltered into the options passed to contentful-export and contentful-import. Those options, including the server's CMA Personal Access Token, reach the Contentful Management API client, which sends the token as a Bearer header to the attacker-supplied host. An attacker who can invoke MCP tools, or plant instructions in Contentful content the LLM reads, can redirect CMA requests and the PAT to an attacker-controlled endpoint.
GitHub Advisory DatabaseGHSA-rr55-jp92-8wp2: claude-faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools
Aug 19, 2026HighVulnerabilitySecurityclaude-faf-mcp, an MCP server, resolves caller-supplied `path` arguments into filesystem reads and writes without confining them to a trusted project directory. A caller, or an LLM prompt-injected through attacker-controlled content, can read files such as SSH keys, cloud credentials and `.env` files, and `faf_write` can write outside the project.
Fix: Fixed in 5.7.2, which confines every caller-supplied `path` before filesystem access. Upgrade with `npm install -g claude-faf-mcp@5.7.2` or the one-click `.mcpb` install. Workaround if upgrading is not immediate: run the server only against trusted local projects and set `FAF_ALLOWED_ROOTS` (patched versions) to a single project directory.
GitHub Advisory DatabaseGHSA-j4r7-8ph4-43g3: faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools
Aug 19, 2026HighVulnerabilitySecurityfaf-mcp versions before 2.1.3 accept a caller-controlled `path` argument in the shared `getProjectPath()` chokepoint and the `faf_read` and `faf_write` tools, resolving it without confinement to a project directory. An MCP client, or a prompt-injected LLM issuing a tool call, can read files such as SSH keys, cloud credentials and `.env` files, and `faf_write` can write outside the project (CWE-200).
Fix: Fixed in 2.1.3, which confines every caller-supplied `path` before filesystem access. Upgrade with `npm install -g faf-mcp@2.1.3` or `npx faf-mcp`. If upgrading is not possible immediately, run the server only against trusted local projects and set `FAF_ALLOWED_ROOTS` (patched versions) to a single project directory.
GitHub Advisory DatabaseGHSA-cc2g-gq8c-r332: grok-faf-mcp has an arbitrary local file read via unconfined `path` argument in FAF tools
Aug 19, 2026HighVulnerabilitySecuritygrok-faf-mcp, an MCP server, has several FAF tools (refresh_faf, faf_score, faf_get_orchestration_policy, refresh_blend, faf_read, faf_write) that accept a caller-controlled path argument and read it without confinement to a trusted project directory. An MCP client, or an LLM prompt-injected through attacker-controlled content, can use absolute paths or ../ traversal to read files such as SSH keys, cloud credentials and .env files, with OS file permissions as the only remaining limit.
Fix: Fixed in 1.5.3, which confines every caller-supplied path before filesystem access: reads are restricted to .faf and .fafm context files, general file operations are confined to the project root (override with FAF_ALLOWED_ROOTS), paths are canonicalized through symlinks, and absolute paths and ../ escapes are rejected. Upgrade with `npm install -g grok-faf-mcp@1.5.3` or `bunx grok-faf-mcp`. If upgrading is not possible immediately, run the server only against trusted local projects and set FAF_ALLOWED_ROOTS to a single project directory.
GitHub Advisory DatabaseCVE-2026-75130: Context7 prompt injection through Custom AI Instructions served via MCP server
Aug 18, 2026CriticalVulnerabilitySecurityCVE-2026-75130Context7 through version 2.1.2 contains a prompt injection flaw in its Custom AI Instructions feature, served through the MCP server. An attacker can inject unsanitized content into those instructions, which connected AI coding agents then execute. The poisoned instructions can exfiltrate credentials from environment files to an attacker-controlled service and delete files on the victim's machine when the agent makes a routine library documentation request.
NVD/CVE DatabaseCVE-2026-50143: Apify MCP server token exposure through Actor MCP server URL redirect
Aug 18, 2026HighVulnerabilitySecurityCVE-2026-50143The Apify MCP server, prior to version 0.10.11, builds the Actor MCP server URL in getActorMCPServerURL (src/mcp/actors.ts) by concatenating the trusted Actor standby URL with the attacker-controlled webServerMcpPath from an Actor definition, without checking the resulting origin. A malicious Actor publisher can use a userinfo-style authority value to redirect connectMCPClient to a third-party host. The call-actor, fetch-actor-details, and actor-mcp paths then send the victim's Authorization bearer token, exposing the Apify API token and granting access to Actors, stored data, and billable compute. Exploitation requires that a victim invoke or inspect the attacker-controlled Actor.
Fix: Fixed in 0.10.11.
NVD/CVE Database
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.