Model Context Protocol
The Model Context Protocol and the servers and clients that expose tools and data to models through it.
- All items
- 295
- Last 90 days
- 133
- Change
- +53%vs 87 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 2 |
| Jun 2025 | 4 |
| Jul 2025 | 4 |
| Aug 2025 | 7 |
| Sep 2025 | 3 |
| Oct 2025 | 3 |
| Nov 2025 | 2 |
| Dec 2025 | 4 |
| Jan 2026 | 4 |
| Feb 2026 | 12 |
| Mar 2026 | 22 |
| Apr 2026 | 27 |
| May 2026 | 31 |
| Jun 2026 | 25 |
| Jul 2026 | 43 |
| Aug 2026 | 45 |
| Sep 2026 | 40 |
| Oct 2026 | 16 |
198 items
CVE-2026-75130: Context7 prompt injection through Custom AI Instructions served via MCP server
Aug 18, 2026CriticalVulnerabilitySecurityCVE-2026-75130Context7 through version 2.1.2 contains a prompt injection flaw in its Custom AI Instructions feature, served through the MCP server. An attacker can inject unsanitized content into those instructions, which connected AI coding agents then execute. The poisoned instructions can exfiltrate credentials from environment files to an attacker-controlled service and delete files on the victim's machine when the agent makes a routine library documentation request.
NVD/CVE DatabaseCVE-2026-50143: Apify MCP server token exposure through Actor MCP server URL redirect
Aug 18, 2026HighVulnerabilitySecurityCVE-2026-50143The Apify MCP server, prior to version 0.10.11, builds the Actor MCP server URL in getActorMCPServerURL (src/mcp/actors.ts) by concatenating the trusted Actor standby URL with the attacker-controlled webServerMcpPath from an Actor definition, without checking the resulting origin. A malicious Actor publisher can use a userinfo-style authority value to redirect connectMCPClient to a third-party host. The call-actor, fetch-actor-details, and actor-mcp paths then send the victim's Authorization bearer token, exposing the Apify API token and granting access to Actors, stored data, and billable compute. Exploitation requires that a victim invoke or inspect the attacker-controlled Actor.
Fix: Fixed in 0.10.11.
NVD/CVE DatabaseCVE-2026-75858: CodeWhale rlm_eval remote code execution via prompt injection
Aug 18, 2026HighVulnerabilitySecurityCVE-2026-75858CodeWhale (packages codewhale and codewhale-tui), versions >= 0.8.41 and < 0.8.64, contains a remote code execution flaw in the rlm_eval tool. Its approval_requirement() returns ApprovalRequirement::Auto, so the engine never prompts and runs model-supplied Python in a python3 interpreter without consulting --approval-policy. An attacker can trigger this through prompt injection in untrusted content the agent reads, such as a web page, fetched URL, repository file or MCP tool result, with the companion rlm_open tool able to stage that content. Code runs at the user's privilege level.
Fix: Fixed in 0.8.64.
NVD/CVE DatabaseGHSA-xhcr-cqfr-m3hv: atomic-agents-stack: HTTP MCP catalog accepts cleartext http and spawns catalog-supplied commands (MITM to RCE)
Aug 17, 2026HighVulnerabilitySecurityThe HTTP MCP server-registry backend, `atomic_agents/mcp_registry/http.py` (`make_http_mcp_server_registry_backend_from_url`), accepts both `http` and `https` catalog URLs, affecting all versions through 1.0.0. Catalog `command`/`args` values are type-validated but not content-restricted, and `MCPClientPool` spawns them as local stdio subprocesses. Over a cleartext `http://` catalog, a network man-in-the-middle can rewrite the response to inject arbitrary commands and gain code execution on the agent host without LLM involvement. The `https` path is stated to be sound, and `mcp_allow_fn` defaults to None, so no allowlist applies unless an operator configures one.
Fix: Require `https` by default and gate `http://` behind a loud explicit opt-in. Defense-in-depth: allowlist the resolved command basename (or require confirmation) before any registry-sourced subprocess spawn. Document the consequence in spec/36.
GitHub Advisory DatabaseCVE-2026-49986: Cortex MCP server code execution via malicious project directory
Aug 14, 2026HighVulnerabilitySecurityCVE-2026-49986The Cortex MCP server (`neuro-cortex-memory`) before version 3.17.1 treats the `CLAUDE_PROJECT_DIR` environment variable, which Claude Code sets to the open project directory, as a trusted Cortex developer checkout. When `open_visualization` runs, `_find_dev_source()` accepts that directory as a source root if `_is_cortex_root()` finds an `mcp_server/` subdirectory and a `ui/unified-viz.html` file. An attacker who places those two marker files in a malicious repository can make Cortex run `mcp_server/server/visualize_bootstrap.py` from it via `subprocess.run`, executing code with the victim's local user privileges.
Fix: Fixed in 3.17.1.
NVD/CVE DatabaseCVE-2026-49856: @jshookmcp/jshook SSRF policy bypass through ICMP probe and traceroute tools
Aug 13, 2026MediumVulnerabilitySecurityCVE-2026-49856@jshookmcp/jshook, an MCP server giving AI agents JavaScript analysis tools, has a flaw in version 0.3.1 where the ICMP probe and traceroute tools bypass the central SSRF authorization policy that the raw HTTP, TCP and TLS RTT tools enforce. An MCP client with access to an active network domain can make the server probe internal addresses, even when local SSRF access is disabled, exposing internal reachability and route mapping from the server's network position.
Fix: Fixed in 0.3.2.
NVD/CVE DatabaseCVE-2026-73498: MCP Atlassian arbitrary file read through confluence_upload_attachment
Aug 12, 2026HighVulnerabilitySecurityCVE-2026-73498MCP Atlassian, a Model Context Protocol server for Confluence and Jira, is affected by CVE-2026-73498 in versions prior to 0.22.0. The confluence_upload_attachment tool passes a client-supplied file_path directly to open() without calling validate_safe_path, so an authenticated MCP client can read any file the server process can access and upload it to Confluence as an attachment. If an AI agent is induced through untrusted content to call the tool, the flaw can also expose server environment variables such as CONFLUENCE_API_TOKEN.
Fix: Fixed in 0.22.0.
NVD/CVE DatabaseGHSA-49m4-vp58-wgc9: MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package_install`
Aug 12, 2026HighVulnerabilitySecurityCVE-2026-55071The `ado_package_install` MCP tool in `stata-mcp` interpolates its `package` argument into a Stata command string without validation, and `Controller` sends the result to Stata via `pexpect.sendline()`. Embedded newlines let an attacker inject Stata's `shell` command, giving OS command execution under the account running the Stata-MCP server. The tool is enabled in the default `all` profile, and the base CVSS score is 8.4 (High).
GitHub Advisory DatabaseCVE-2026-67531: FrontMCP sandbox escape to remote code execution through codecall:execute tool
Aug 5, 2026CriticalVulnerabilitySecurityCVE-2026-67531FrontMCP, a TypeScript framework for the Model Context Protocol, is affected by CVE-2026-67531 in versions prior to 1.5.7. The sandboxed codecall:execute tool exposes live host Zod schema instances through getTool(), and because Zod v4 defines _zod as non-configurable and non-writable, the Proxy invariants return the raw host object, letting a script reach the host Function constructor and run arbitrary code in the server process. A single tools/call is enough, and the attacker gains the server user's privileges, including OAuth client secrets, JWT_SECRET, session keys, database credentials, and cloud instance metadata. Because DEFAULT_AUTH_OPTIONS defaults to public mode, unconfigured servers expose this to unauthenticated callers, and on authenticated servers an indirect prompt injection in tool output or fetched content can trigger it without a human attacker.
Fix: Fixed in version 1.5.7.
NVD/CVE DatabaseCVE-2026-18954 - Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server
Aug 5, 2026HighVulnerabilitySecurityCVE-2026-18954 is an incorrect authorization issue in the aggregation pipeline tool of the Amazon DocumentDB MCP Server, an open-source Model Context Protocol server for AI assistants. Write-capable pipeline stages ($out, $merge) bypass the read-only mode enforcement, potentially letting an authenticated MCP client perform write operations on the connected database. Impacted versions are below 1.0.12.
Fix: Fixed in 1.0.12 or later. The source otherwise directs readers to the linked AWS Security Bulletin article for complete information.
AWS Security BulletinsCVE-2026-18953 - Improper limitation of a pathname in AWS Transform MCP Server
Aug 5, 2026HighVulnerabilitySecurityCVE-2026-18953 is an improper limitation of a pathname to a restricted directory in the get_resource tool of awslabs.aws-transform-mcp-server, a locally run MCP server, in versions 0.1.0 through 0.1.4. A context-dependent actor can use the savePath parameter to write arbitrary files outside the intended working directory, which could lead to local code execution.
Fix: Fixed in 0.1.5 (the source states the flaw is present before 0.1.5).
AWS Security BulletinsCVE-2026-9077: IBM Langflow OSS localhost restriction bypass via remote authenticated access
Aug 5, 2026HighVulnerabilitySecurityCVE-2026-9077CVE-2026-9077 affects IBM Langflow OSS versions 1.0.0 through 1.10.3. A remote authenticated attacker can bypass localhost-only restrictions and write arbitrary MCP server configurations to IDE configuration files on the host system. The weakness is classified as CWE-807, Reliance on Untrusted Inputs in a Security Decision.
NVD/CVE DatabaseCVE-2026-8446: IBM Langflow OSS authentication bypass in MCP composer endpoint
Aug 5, 2026HighVulnerabilitySecurityCVE-2026-8446CVE-2026-8446 is an authentication bypass in IBM Langflow OSS versions 1.0.0 through 1.10.3. The flaw sits in the Model Context Protocol (MCP) composer endpoint when mcp_composer_enabled=true, which is the default, and projects are configured with auth_type=oauth. It is classified as CWE-306, Missing Authentication for Critical Function, and IBM is the listed source. NVD had not yet provided an assessment at the time of the source text.
NVD/CVE DatabaseCVE-2026-17626: IBM Langflow OSS file read and modify via Docker-based MCP servers
Aug 5, 2026HighVulnerabilitySecurityCVE-2026-17626CVE-2026-17626 affects IBM Langflow OSS versions 1.0.0 through 1.10.3. An authenticated attacker can read, modify, or expose sensitive host files through Docker-based MCP servers, because Langflow incompletely filters dangerous Docker volume-mount and device-mapping arguments. The weakness is classified as CWE-266, Incorrect Privilege Assignment. NVD had not yet provided an assessment when the entry was published on 08/05/2026.
NVD/CVE DatabaseCVE-2026-17623: IBM Langflow OSS command execution through MCP server configuration
Aug 5, 2026HighVulnerabilitySecurityCVE-2026-17623CVE-2026-17623 affects IBM Langflow OSS versions 1.0.0 through 1.10.3. A remote authenticated attacker can execute arbitrary commands because the command field in MCP server configurations is not properly validated, classified as CWE-78 (OS Command Injection). The NVD assessment was not yet provided at publication on 08/05/2026.
NVD/CVE DatabaseGHSA-xc48-889x-5qmw: Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable blocklist (Unauthenticated RCE)
Aug 4, 2026HighVulnerabilitySecurityCVE-2026-69263The mitigation for CVE-2025-8943 in Flowise 3.1.1 blocks the `-y` and `--yes` flags on `npx`, but its environment-variable check denies only four names by exact match: PATH, LD_LIBRARY_PATH, DYLD_LIBRARY_PATH and NODE_OPTIONS. Because npm reads `npm_config_*` environment variables, setting `npm_config_yes=true` in an MCP server configuration makes `npx` auto-install and execute the named package, bypassing the patch. With `CUSTOM_MCP_SECURITY_CHECK=true`, the source says a default deployment without authentication allows unauthenticated remote code execution.
Fix: The source recommends allowlisting or stripping the environment before it reaches the child process rather than extending the denylist. No fixed version is stated.
GitHub Advisory DatabaseCVE-2026-18655: Amazon MQ MCP Server RabbitMQ broker tools leak credentials via crafted endpoint
Aug 3, 2026MediumVulnerabilitySecurityCVE-2026-18655CVE-2026-18655 is an improper restriction of intended endpoints in the RabbitMQ broker connection tools of the Amazon MQ MCP Server (awslabs.amazon-mq-mcp-server) before 2.0.24. A remote unauthenticated actor, via prompt injection, may obtain Amazon MQ for RabbitMQ broker credentials or OAuth access tokens sent to a crafted endpoint controlled through a broker hostname introduced in the MCP client context. The CNA, AMZN, rates it CVSS 4.0 7.1 HIGH, and NIST has not yet provided an assessment.
Fix: To remediate this issue, users should upgrade to version 2.0.24.
NVD/CVE DatabaseCVE-2026-18655 - Broker Credential and OAuth Token Disclosure in AWS Labs Amazon MQ MCP Server via Prompt Injection
Aug 3, 2026HighVulnerabilitySecurityCVE-2026-18655 is an improper restriction of intended endpoints in the RabbitMQ broker connection tools of the AWS Labs Amazon MQ MCP Server (awslabs.amazon-mq-mcp-server) before 2.0.24, affecting versions <= 2.0.23. A remote unauthenticated actor may obtain Amazon MQ for RabbitMQ broker credentials or OAuth access tokens by sending them to a crafted endpoint controlled through a broker hostname introduced in the MCP client context.
Fix: Fixed in 2.0.24. Upgrade awslabs.amazon-mq-mcp-server to version 2.0.24 or later.
AWS Security BulletinsGHSA-c5px-58j2-7fqp: gemini-bridge vulnerable to arbitrary local file read via consult_gemini_with_files inline mode
Jul 31, 2026MediumVulnerabilitySecurityCVE-2026-54785gemini-bridge's consult_gemini_with_files tool, in inline mode, read any file path given in the files argument without confining it to the working directory, then forwarded the contents to the Gemini CLI. Because the caller also controls query, file contents are echoed back through the Gemini round-trip and sent to Google, letting an MCP client or a prompt-injected LLM read any file the server process can access.
Fix: Fixed in 1.3.1. _resolve_path now resolves symlinks and confines paths via Path.relative_to(root), and inline mode skips any entry that resolves outside the working directory. Before upgrading, avoid mode="inline" with untrusted files input, or run the server with a restricted-permission user.
GitHub Advisory DatabaseCVE-2026-12940: IBM Langflow OSS unauthenticated code execution via MCP stdio launcher
Jul 30, 2026CriticalVulnerabilitySecurityCVE-2026-12940CVE-2026-12940 affects IBM Langflow OSS versions 1.0.0 through 1.10.1. The flaw is in the MCP (Model Context Protocol) stdio launcher, in src/lfx/src/lfx/base/mcp/util.py, where the DANGEROUS_ENV_VARS blocklist omits SHELLOPTS, BASHOPTS, and PS4. Per the source, this allows unauthenticated remote code execution through environment variable injection and is classified as CWE-78, OS Command Injection. NVD had not yet provided an assessment at publication on 07/30/2026.
NVD/CVE Database
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.