Model Context Protocol
The Model Context Protocol and the servers and clients that expose tools and data to models through it.
- All items
- 295
- Last 90 days
- 133
- Change
- +53%vs 87 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 2 |
| Jun 2025 | 4 |
| Jul 2025 | 4 |
| Aug 2025 | 7 |
| Sep 2025 | 3 |
| Oct 2025 | 3 |
| Nov 2025 | 2 |
| Dec 2025 | 4 |
| Jan 2026 | 4 |
| Feb 2026 | 12 |
| Mar 2026 | 22 |
| Apr 2026 | 27 |
| May 2026 | 31 |
| Jun 2026 | 25 |
| Jul 2026 | 43 |
| Aug 2026 | 45 |
| Sep 2026 | 40 |
| Oct 2026 | 16 |
295 items
CVE-2026-75858: CodeWhale rlm_eval remote code execution via prompt injection
Aug 18, 2026HighVulnerabilitySecurityCVE-2026-75858CodeWhale (packages codewhale and codewhale-tui), versions >= 0.8.41 and < 0.8.64, contains a remote code execution flaw in the rlm_eval tool. Its approval_requirement() returns ApprovalRequirement::Auto, so the engine never prompts and runs model-supplied Python in a python3 interpreter without consulting --approval-policy. An attacker can trigger this through prompt injection in untrusted content the agent reads, such as a web page, fetched URL, repository file or MCP tool result, with the companion rlm_open tool able to stage that content. Code runs at the user's privilege level.
Fix: Fixed in 0.8.64.
NVD/CVE DatabaseGHSA-xhcr-cqfr-m3hv: atomic-agents-stack: HTTP MCP catalog accepts cleartext http and spawns catalog-supplied commands (MITM to RCE)
Aug 17, 2026HighVulnerabilitySecurityThe HTTP MCP server-registry backend, `atomic_agents/mcp_registry/http.py` (`make_http_mcp_server_registry_backend_from_url`), accepts both `http` and `https` catalog URLs, affecting all versions through 1.0.0. Catalog `command`/`args` values are type-validated but not content-restricted, and `MCPClientPool` spawns them as local stdio subprocesses. Over a cleartext `http://` catalog, a network man-in-the-middle can rewrite the response to inject arbitrary commands and gain code execution on the agent host without LLM involvement. The `https` path is stated to be sound, and `mcp_allow_fn` defaults to None, so no allowlist applies unless an operator configures one.
Fix: Require `https` by default and gate `http://` behind a loud explicit opt-in. Defense-in-depth: allowlist the resolved command basename (or require confirmation) before any registry-sourced subprocess spawn. Document the consequence in spec/36.
GitHub Advisory DatabaseHow MCP Servers Can Expose Enterprise Secrets
Aug 17, 2026InfoNewsSecurityIndustryMCP servers can expose enterprise secrets through plaintext configuration files, over-permissioned access and prompt injection, often before security teams know the server is running. The MCP server sits between an AI agent and enterprise systems, so it typically holds credentials such as service account keys, API tokens and other secrets for every system it touches.
The Hacker NewsCVE-2026-49986: Cortex MCP server code execution via malicious project directory
Aug 14, 2026HighVulnerabilitySecurityCVE-2026-49986The Cortex MCP server (`neuro-cortex-memory`) before version 3.17.1 treats the `CLAUDE_PROJECT_DIR` environment variable, which Claude Code sets to the open project directory, as a trusted Cortex developer checkout. When `open_visualization` runs, `_find_dev_source()` accepts that directory as a source root if `_is_cortex_root()` finds an `mcp_server/` subdirectory and a `ui/unified-viz.html` file. An attacker who places those two marker files in a malicious repository can make Cortex run `mcp_server/server/visualize_bootstrap.py` from it via `subprocess.run`, executing code with the victim's local user privileges.
Fix: Fixed in 3.17.1.
NVD/CVE DatabaseCVE-2026-49856: @jshookmcp/jshook SSRF policy bypass through ICMP probe and traceroute tools
Aug 13, 2026MediumVulnerabilitySecurityCVE-2026-49856@jshookmcp/jshook, an MCP server giving AI agents JavaScript analysis tools, has a flaw in version 0.3.1 where the ICMP probe and traceroute tools bypass the central SSRF authorization policy that the raw HTTP, TCP and TLS RTT tools enforce. An MCP client with access to an active network domain can make the server probe internal addresses, even when local SSRF access is disabled, exposing internal reachability and route mapping from the server's network position.
Fix: Fixed in 0.3.2.
NVD/CVE DatabaseCVE-2026-73498: MCP Atlassian arbitrary file read through confluence_upload_attachment
Aug 12, 2026HighVulnerabilitySecurityCVE-2026-73498MCP Atlassian, a Model Context Protocol server for Confluence and Jira, is affected by CVE-2026-73498 in versions prior to 0.22.0. The confluence_upload_attachment tool passes a client-supplied file_path directly to open() without calling validate_safe_path, so an authenticated MCP client can read any file the server process can access and upload it to Confluence as an attachment. If an AI agent is induced through untrusted content to call the tool, the flaw can also expose server environment variables such as CONFLUENCE_API_TOKEN.
Fix: Fixed in 0.22.0.
NVD/CVE DatabaseGHSA-49m4-vp58-wgc9: MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package_install`
Aug 12, 2026HighVulnerabilitySecurityCVE-2026-55071The `ado_package_install` MCP tool in `stata-mcp` interpolates its `package` argument into a Stata command string without validation, and `Controller` sends the result to Stata via `pexpect.sendline()`. Embedded newlines let an attacker inject Stata's `shell` command, giving OS command execution under the account running the Stata-MCP server. The tool is enabled in the default `all` profile, and the base CVSS score is 8.4 (High).
GitHub Advisory DatabaseMalicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets
Aug 11, 2026MediumNewsSecuritySafetyASSET Research Group disclosed GhostSplice, a technique in which a malicious MCP server splits a data-theft request across a tool description, a tool result and a later project-scan result, so AI coding agents assemble and send SSH keys, environment secrets, source code and customer data to the attacker's tool. Tests in isolated projects with fake credentials reported average compliance rising from 42% to 82% across eleven API-tested models when the request was split in two. The source text says the attack assumes the developer has already connected the attacker's MCP server and that the agent can read the target files.
Fix: The source text does not state a fix or patch, but says the defense lands on the client: the MCP specification says clients should keep a human able to deny tool invocations and must treat annotations from untrusted servers as untrusted.
The Hacker NewsCVE-2026-67531: FrontMCP sandbox escape to remote code execution through codecall:execute tool
Aug 5, 2026CriticalVulnerabilitySecurityCVE-2026-67531FrontMCP, a TypeScript framework for the Model Context Protocol, is affected by CVE-2026-67531 in versions prior to 1.5.7. The sandboxed codecall:execute tool exposes live host Zod schema instances through getTool(), and because Zod v4 defines _zod as non-configurable and non-writable, the Proxy invariants return the raw host object, letting a script reach the host Function constructor and run arbitrary code in the server process. A single tools/call is enough, and the attacker gains the server user's privileges, including OAuth client secrets, JWT_SECRET, session keys, database credentials, and cloud instance metadata. Because DEFAULT_AUTH_OPTIONS defaults to public mode, unconfigured servers expose this to unauthenticated callers, and on authenticated servers an indirect prompt injection in tool output or fetched content can trigger it without a human attacker.
Fix: Fixed in version 1.5.7.
NVD/CVE DatabaseCVE-2026-18954 - Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server
Aug 5, 2026HighVulnerabilitySecurityCVE-2026-18954 is an incorrect authorization issue in the aggregation pipeline tool of the Amazon DocumentDB MCP Server, an open-source Model Context Protocol server for AI assistants. Write-capable pipeline stages ($out, $merge) bypass the read-only mode enforcement, potentially letting an authenticated MCP client perform write operations on the connected database. Impacted versions are below 1.0.12.
Fix: Fixed in 1.0.12 or later. The source otherwise directs readers to the linked AWS Security Bulletin article for complete information.
AWS Security BulletinsCVE-2026-18953 - Improper limitation of a pathname in AWS Transform MCP Server
Aug 5, 2026HighVulnerabilitySecurityCVE-2026-18953 is an improper limitation of a pathname to a restricted directory in the get_resource tool of awslabs.aws-transform-mcp-server, a locally run MCP server, in versions 0.1.0 through 0.1.4. A context-dependent actor can use the savePath parameter to write arbitrary files outside the intended working directory, which could lead to local code execution.
Fix: Fixed in 0.1.5 (the source states the flaw is present before 0.1.5).
AWS Security BulletinsCVE-2026-9077: IBM Langflow OSS localhost restriction bypass via remote authenticated access
Aug 5, 2026HighVulnerabilitySecurityCVE-2026-9077CVE-2026-9077 affects IBM Langflow OSS versions 1.0.0 through 1.10.3. A remote authenticated attacker can bypass localhost-only restrictions and write arbitrary MCP server configurations to IDE configuration files on the host system. The weakness is classified as CWE-807, Reliance on Untrusted Inputs in a Security Decision.
NVD/CVE DatabaseCVE-2026-8446: IBM Langflow OSS authentication bypass in MCP composer endpoint
Aug 5, 2026HighVulnerabilitySecurityCVE-2026-8446CVE-2026-8446 is an authentication bypass in IBM Langflow OSS versions 1.0.0 through 1.10.3. The flaw sits in the Model Context Protocol (MCP) composer endpoint when mcp_composer_enabled=true, which is the default, and projects are configured with auth_type=oauth. It is classified as CWE-306, Missing Authentication for Critical Function, and IBM is the listed source. NVD had not yet provided an assessment at the time of the source text.
NVD/CVE DatabaseCVE-2026-17626: IBM Langflow OSS file read and modify via Docker-based MCP servers
Aug 5, 2026HighVulnerabilitySecurityCVE-2026-17626CVE-2026-17626 affects IBM Langflow OSS versions 1.0.0 through 1.10.3. An authenticated attacker can read, modify, or expose sensitive host files through Docker-based MCP servers, because Langflow incompletely filters dangerous Docker volume-mount and device-mapping arguments. The weakness is classified as CWE-266, Incorrect Privilege Assignment. NVD had not yet provided an assessment when the entry was published on 08/05/2026.
NVD/CVE DatabaseCVE-2026-17623: IBM Langflow OSS command execution through MCP server configuration
Aug 5, 2026HighVulnerabilitySecurityCVE-2026-17623CVE-2026-17623 affects IBM Langflow OSS versions 1.0.0 through 1.10.3. A remote authenticated attacker can execute arbitrary commands because the command field in MCP server configurations is not properly validated, classified as CWE-78 (OS Command Injection). The NVD assessment was not yet provided at publication on 08/05/2026.
NVD/CVE DatabaseVeeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug
Aug 5, 2026MediumNewsSecurityHashiCorp, Veeam, and the Django Software Foundation patched 11 vulnerabilities across Terraform MCP Server, Veeam Service Provider Console, and Django. The most serious is CVE-2026-16498 (CVSS score: 10.0), a cross-tenant flaw in Terraform MCP Server's stateless HTTP mode where one user's Terraform token can be reused for later users' requests, because the underlying MCP library does not assign unique session identifiers. Veeam's CVE-2026-58073 (CVSS score: 9.5) lets an unauthenticated attacker impersonate a managed agent and obtain its credentials, though its high attack complexity limits exploitation.
Fix: Update Terraform MCP Server to version 1.1.0 or later, Veeam Service Provider Console to 9.3.0.35057, and Django to 6.0.8 or 5.2.17.
The Hacker NewsGHSA-xc48-889x-5qmw: Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable blocklist (Unauthenticated RCE)
Aug 4, 2026HighVulnerabilitySecurityCVE-2026-69263The mitigation for CVE-2025-8943 in Flowise 3.1.1 blocks the `-y` and `--yes` flags on `npx`, but its environment-variable check denies only four names by exact match: PATH, LD_LIBRARY_PATH, DYLD_LIBRARY_PATH and NODE_OPTIONS. Because npm reads `npm_config_*` environment variables, setting `npm_config_yes=true` in an MCP server configuration makes `npx` auto-install and execute the named package, bypassing the patch. With `CUSTOM_MCP_SECURITY_CHECK=true`, the source says a default deployment without authentication allows unauthenticated remote code execution.
Fix: The source recommends allowlisting or stripping the environment before it reaches the child process rather than extending the denylist. No fixed version is stated.
GitHub Advisory DatabaseObsidian Security Raises $85 Million at $1.1 Billion Valuation
Aug 4, 2026InfoNewsIndustrySecurityObsidian Security announced an $85 million Series D round at a $1.1 billion valuation, led by Crescent Cove Advisors with Greylock Partners and Menlo Ventures participating, bringing total funding above $200 million. The company will use the funds to expand into agentic AI security, offering runtime governance over agents such as Claude Code and Cowork and an inventory of connected MCP servers.
SecurityWeekGemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pull Request Tampering
Aug 4, 2026MediumNewsSecurityIndustryPillar Security found an agent-to-agent attack method in Google's Agent Development Kit for Python (google/adk-python) that could expose secrets and enable pull request poisoning. A public-facing low-privileged agent could be manipulated into passing a prompt to a high-privileged maintainer agent, which exposed its tools via the MCP server and allowed remote command execution and extraction of its GitHub token. Google addressed the issue through hardening but did not consider it eligible for a bug bounty, and a later remote code execution flaw in the Antigravity-SDK-based agent's automation features was fixed in late July.
Fix: Google addressed the first issue through hardening and fixed the second weakness in late July. No further mitigation details are given in source.
SecurityWeekCVE-2026-18655: Amazon MQ MCP Server RabbitMQ broker tools leak credentials via crafted endpoint
Aug 3, 2026MediumVulnerabilitySecurityCVE-2026-18655CVE-2026-18655 is an improper restriction of intended endpoints in the RabbitMQ broker connection tools of the Amazon MQ MCP Server (awslabs.amazon-mq-mcp-server) before 2.0.24. A remote unauthenticated actor, via prompt injection, may obtain Amazon MQ for RabbitMQ broker credentials or OAuth access tokens sent to a crafted endpoint controlled through a broker hostname introduced in the MCP client context. The CNA, AMZN, rates it CVSS 4.0 7.1 HIGH, and NIST has not yet provided an assessment.
Fix: To remediate this issue, users should upgrade to version 2.0.24.
NVD/CVE Database
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.