Model Context Protocol
The Model Context Protocol and the servers and clients that expose tools and data to models through it.
- All items
- 295
- Last 90 days
- 133
- Change
- +53%vs 87 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 2 |
| Jun 2025 | 4 |
| Jul 2025 | 4 |
| Aug 2025 | 7 |
| Sep 2025 | 3 |
| Oct 2025 | 3 |
| Nov 2025 | 2 |
| Dec 2025 | 4 |
| Jan 2026 | 4 |
| Feb 2026 | 12 |
| Mar 2026 | 22 |
| Apr 2026 | 27 |
| May 2026 | 31 |
| Jun 2026 | 25 |
| Jul 2026 | 43 |
| Aug 2026 | 45 |
| Sep 2026 | 40 |
| Oct 2026 | 16 |
198 items
GHSA-29w2-fq35-v728: AWS API MCP Server Security Policy Bypass via Startup Initialization Failure
Jul 24, 2026HighVulnerabilitySecurityCVE-2026-16584The AWS API MCP Server, an open source Model Context Protocol server for running AWS CLI commands, skips its per-request security policy check for the lifetime of the process if the policy enforcement data fails to load at startup. Deny and gate rules are then not consulted, so restricted AWS API operations execute, though IAM permissions on the configured credentials still apply. Affected versions are >= 0.2.13 and < 1.3.47.
Fix: Fixed in awslabs.aws-api-mcp-server version 1.3.47. Until upgrading, use least-privilege IAM credentials (for example, a ReadOnlyAccess role) scoped to the task, or restart the server once connectivity is restored if it started during degraded connectivity.
GitHub Advisory DatabaseCVE-2026-66005: Jan local API server CORS misconfiguration allows trusted host bypass
Jul 24, 2026MediumVulnerabilitySecurityCVE-2026-66005CVE-2026-66005 affects Jan through 0.8.4 and is fixed in commit 3e1c1e7. The local API server has a CORS misconfiguration: it replaces user-configured trusted hosts with a wildcard that reflects arbitrary origins with credentials. Network-adjacent attackers, or attackers using DNS rebinding, can reach the unauthenticated OpenAI-compatible API to run inference, enumerate models, invoke MCP tools, and read cross-origin responses.
Fix: Fixed in commit 3e1c1e7.
NVD/CVE DatabaseCVE-2026-16584 - AWS API MCP Server Security Policy Bypass via Startup Failure
Jul 23, 2026HighVulnerabilitySecurityCVE-2026-16584 affects the AWS API MCP Server (awslabs.aws-api-mcp-server) for versions >= 0.2.13 and < 1.3.47. If the server fails to load its optional user-configured security policy at startup, it keeps running with the per-request policy check skipped, so AWS API operations the policy was set to deny or gate can execute without enforcement, provided fail-closed modes are not enabled. IAM permissions on the configured credentials remain in effect.
AWS Security BulletinsGHSA-q5xf-xhwf-cwqf: n8n: Member-Level Users Can Execute Other Users' MCP Server Trigger Workflows via Missing OAuth Authorization Check
Jul 22, 2026MediumVulnerabilitySecurityCVE-2026-65594GHSA-q5xf-xhwf-cwqf affects n8n instances running 2.27.0 or later with an active workflow using an MCP Server Trigger node configured with `n8n OAuth2` authentication. The OAuth 2.1 consent and token-issuance flow does not check whether the authenticated user can access the referenced workflow, so a member-level user can self-approve consent for another user's workflow and obtain a valid token. The workflow then runs in the owner's project context with the owner's stored credentials, letting the attacker set inputs and read outputs, which may include data from the owner's connected integrations.
Fix: Fixed in n8n 2.29.8 and 2.30.1; upgrade to one of these versions or later. If upgrading is not immediately possible, restrict instance access to fully trusted users only and audit active MCP Server Trigger workflows using `n8n OAuth2`, switching their authentication method or deactivating them until the patch is applied. These workarounds do not fully remediate the risk and are short-term measures only.
GitHub Advisory DatabaseGHSA-vhf8-cg2h-cg3p: n8n: SSRF Protection Bypass via MCP Client Node
Jul 22, 2026MediumVulnerabilitySecurityThe MCP Client node in n8n sent requests to user-supplied endpoints without routing them through SSRF protection or pinning the resolved address. An authenticated user who could create or edit a workflow could make the server connect to internal or blocked hosts and read the responses back through the workflow. The issue affects instances with SSRF protection enabled.
Fix: Fixed in n8n versions 2.31.5 and 2.32.1; upgrade to one of these or later. If upgrading is not immediately possible, temporary mitigations include restricting instance access to fully trusted users only, disabling the MCP Client node by adding it to the `NODES_EXCLUDE` environment variable, and restricting network egress from the n8n host to block internal and link-local address ranges. These workarounds do not fully remediate the risk and should only be short-term measures.
GitHub Advisory DatabaseCVE-2026-44192: Ansible Lightspeed MCP server path traversal via indirect prompt injection
Jul 22, 2026MediumVulnerabilitySecurityCVE-2026-44192CVE-2026-44192 is a path traversal flaw in the Ansible Lightspeed Model Context Protocol (MCP) server, classified as CWE-22. An attacker can use indirect prompt injection to manipulate an AI agent, causing the server to write files to unauthorized locations on the user's system. The source says this can expose sensitive host information and enable execution of malicious commands, potentially leading to full system compromise.
NVD/CVE DatabaseCVE-2026-46555: WhatsApp MCP Server bridge API unauthenticated local and DNS rebinding access
Jul 20, 2026HighVulnerabilitySecurityCVE-2026-46555WhatsApp MCP Server, prior to version 0.2.1, exposes its `whatsapp-bridge` HTTP API on `127.0.0.1:8080` without authentication or Host header validation, and the `/api/send` endpoint accepts an absolute `media_path` without confinement to a safe directory. A local process running as the same user, or a remote attacker via DNS rebinding from a visited webpage, can send messages from the paired account, read arbitrary user-readable files such as SSH keys, and exfiltrate them as WhatsApp attachments.
Fix: Fixed in whatsapp-mcp v0.2.1 and corresponding Docker images and release artifacts, which add bearer token authentication, host header allow-list validation, and confinement of `media_path` to a configured directory. This is a breaking change for bridge API clients. Users who cannot upgrade immediately should stop the bridge or block loopback access to port 8080 when unused, avoid running it alongside untrusted MCP servers or local processes, avoid browsing untrusted sites while it runs, and/or run it under a dedicated user account or in a sandbox/container without access to sensitive files.
NVD/CVE DatabaseCVE-2026-7755: IBM Langflow OSS remote code execution via MCP server configuration files
Jul 17, 2026HighVulnerabilitySecurityCVE-2026-7755CVE-2026-7755 affects IBM Langflow OSS versions 1.0.0 through 1.10.0. The flaw is incomplete validation enforcement on MCP server configuration files, which could allow remote code execution. NIST has not yet provided an NVD assessment.
NVD/CVE DatabaseGHSA-f7wf-v2vw-mpcx: mcp-memory-keeper: Arbitrary local file read in context_import via unvalidated filePath
Jul 17, 2026MediumVulnerabilitySecurityCVE-2026-54561GHSA-f7wf-v2vw-mpcx affects mcp-memory-keeper, where the context_import tool passed the caller-supplied filePath directly to fs.readFileSync without path confinement. A malicious MCP client, or an LLM agent prompt-injected into calling the tool, could read any file the server process can access. Valid JSON files are imported in full and retrievable through context_get or context_export, while other files leak their leading bytes through the JSON.parse SyntaxError message.
Fix: Fixed in 0.13.0 (PR #36). Upgrade to >= 0.13.0. There is no configuration-only workaround for affected versions.
GitHub Advisory DatabaseCVE-2026-58195: Agentic-Flow MCP server tools command execution through shell interpolation
Jul 17, 2026HighVulnerabilitySecurityCVE-2026-58195Agentic-Flow, an AI agent orchestration platform, is affected in versions prior to 2.0.14. Several MCP server tool files interpolate attacker-influenceable parameters such as agent, task, name, language and agentdb directly into shell command strings passed to execSync(). This allows arbitrary OS command execution with the privileges of the MCP server user.
Fix: This issue is fixed in version 2.0.14.
NVD/CVE DatabaseCVE-2026-9810: AI Copilot WordPress plugin accepts OAuth tokens not bound to a user
Jul 17, 2026CriticalVulnerabilitySecurityCVE-2026-9810CVE-2026-9810 affects the AI Copilot WordPress plugin before 1.5.4. The plugin does not bind OAuth access tokens to a WordPress user and accepts any valid token as an administrator session. Unauthenticated attackers who complete the public OAuth flow can run privileged MCP tools as an administrator, including arbitrary user creation and role escalation.
NVD/CVE DatabaseGHSA-vj7q-gjh5-988w: MCP Python SDK: WebSocket server transport does not support Host/Origin validation
Jul 16, 2026HighVulnerabilitySecurityCVE-2026-59950The deprecated WebSocket server transport, mcp.server.websocket.websocket_server, in the MCP Python SDK accepted WebSocket handshakes without validating the Host or Origin headers, because TransportSecuritySettings was never wired into it. A malicious web page can open a connection to an exposed server on this transport, complete initialize, and invoke its tools and read its resources, and the transport requires no token or prior session. Only applications that wire this transport into their own ASGI server are affected.
Fix: Upgrade to version 1.28.1 or later, which adds the optional security_settings: TransportSecuritySettings argument and validates Host and Origin headers, rejecting failed requests with HTTP 403 and ValueError("Request validation failed"). The parameter defaults to None, which leaves validation disabled, so pass a TransportSecuritySettings with enable_dns_rebinding_protection=True and appropriate allowed_hosts / allowed_origins. The recommended path is to migrate to Streamable HTTP, where FastMCP enables this protection automatically for localhost binds. The WebSocket transport has been removed entirely in v2.
GitHub Advisory DatabaseGHSA-jpw9-pfvf-9f58: MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal
Jul 16, 2026HighVulnerabilitySecurityCVE-2026-52869Affected versions of the MCP Python SDK route requests on the SSE and Streamable HTTP transports to an existing session using only the session identifier, without checking that the request carries the same authenticated principal that created the session. Anyone who learns or guesses a session ID, such as the `session_id` query parameter or `Mcp-Session-Id` header, can send JSON-RPC messages into that session regardless of their bearer token. Only servers that use an HTTP transport and built-in bearer-token authentication are affected; stdio, stateless Streamable HTTP, and unauthenticated servers are not.
Fix: Upgrade to version 1.27.2 or later, which records the authenticated principal that created each session and returns a 404 to requests presenting a different principal. Deployments where many end users share one OAuth client should ensure the token verifier populates `AccessToken.subject`, for example from the `sub` claim, so sessions are isolated per user. Deployments using a custom authentication backend other than `BearerAuthBackend` should enforce an equivalent check themselves.
GitHub Advisory DatabaseGHSA-hvrp-rf83-w775: MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks
Jul 16, 2026HighVulnerabilitySecurityCVE-2026-52870The MCP Python SDK's experimental task handlers, enabled through `server.experimental.enable_tasks()`, did not check which session created a task before acting on it. On a multi-client server, any connected client could list, read, cancel, and consume queued messages such as elicitation requests belonging to other clients' tasks.
Fix: Upgrade to version 1.27.2 or later, in which task IDs generated by `run_task()` embed an opaque per-session marker and the default handlers restrict each session to its own tasks. Alternatively, leave the experimental tasks feature disabled, or register task handlers that validate session ownership.
GitHub Advisory DatabaseCVE-2026-30623: LiteLLM remote code execution through MCP server creation configuration
Jul 15, 2026CriticalVulnerabilitySecurityCVE-2026-30623CVE-2026-30623 affects LiteLLM 1.18.10 in its MCP server creation functionality. Users can add MCP servers through a JSON configuration that sets arbitrary command and args values, which LiteLLM executes on the host without validation, allowing an attacker to run arbitrary operating system commands. Successful exploitation may result in remote code execution with the privileges of the LiteLLM process.
NVD/CVE DatabaseGHSA-3pvh-63gf-j9mw: LangBot: Authenticated RCE Via MCP Configuration
Jul 15, 2026HighVulnerabilitySecurityCVE-2026-54449Any authenticated LangBot user can execute arbitrary OS commands on the server by adding an STDIO MCP server with a chosen command in the MCP configuration. The flaw is in src/langbot/pkg/provider/tools/loaders/mcp.py, where StdioServerParameters from the mcp package spawns a subprocess with the supplied command. The advisory rates this as authenticated remote code execution (CWE-78) affecting publicly reachable instances and, from the same network, local instances.
GitHub Advisory DatabaseGHSA-2cf7-hpwf-47h9: n8n-MCP: Incorrect authorization can expose default-scope workflow version backups in multi-tenant HTTP mode
Jul 14, 2026MediumVulnerabilitySecurityPrivacyCVE-2026-55608n8n-MCP versions up to and including 2.57.3, when run in multi-tenant HTTP mode (ENABLE_MULTI_TENANT=true), let an authenticated tenant reach the local default-scope workflow_versions backups instead of being confined to its own tenant scope. An attacker with tenant access can read or delete these backups, which may contain sensitive workflow configuration; single-tenant and stdio deployments are not affected.
Fix: Upgrade to n8n-mcp 2.57.4 or later. Workarounds: restrict network access to the HTTP endpoint (firewall, reverse proxy or VPN), run in stdio mode, or remove default-scope backups from a prior single-tenant deployment if they are not needed.
GitHub Advisory DatabaseCVE-2026-15643 - AWS HealthLake MCP Server SSRF via Unvalidated Pagination URL
Jul 14, 2026HighVulnerabilitySecurityCVE-2026-15643 is a server-side request forgery in the pagination handling of the awslabs.healthlake-mcp-server (AWS HealthLake MCP Server) before 0.0.14, on all platforms. A remote authenticated user can craft a next_token parameter so that the server does not validate the pagination URL against the expected HealthLake endpoint, redirecting requests to an actor-controlled server and exfiltrating AWS temporary security credentials.
AWS Security BulletinsGHSA-j6r7-6fhx-77wx: n8n-MCP: Cross-tenant access to workflow version backups in multi-tenant HTTP deployments
Jul 14, 2026CriticalVulnerabilitySecurityCVE-2026-54052In multi-tenant HTTP deployments of n8n-mcp (ENABLE_MULTI_TENANT=true), the locally stored workflow version history was not isolated per tenant. An authenticated tenant could read other tenants' workflow version snapshots, which can include node credential references and authorization headers, and could delete their backups. Affected versions are <= 2.56.0; stdio and single-tenant HTTP deployments are not affected.
Fix: Fixed in 2.56.1, which isolates the stored version history per instance; upgrading runs a one-time migration that isolates existing history and clears previously stored, un-scoped backups. Workarounds: set DISABLED_TOOLS=n8n_workflow_versions in the server environment, run each tenant on a separate instance with its own database, or restrict network access to the HTTP endpoint to trusted operators.
GitHub Advisory DatabaseGHSA-g5r6-gv6m-f5jv: mcp-atlassian: Arbitrary file read via missing path validation in confluence_upload_attachment
Jul 10, 2026HighVulnerabilitySecurityThe mcp-atlassian server's confluence_upload_attachment tool passes a caller-supplied file_path directly to open() in _upload_attachment_direct() in src/mcp_atlassian/confluence/attachments.py, without the validate_safe_path() check that download_attachment() applies. Any authenticated MCP client, or an AI agent steered by prompt injection, can read files the server process can access and upload them to Confluence as attachments. The source reports this was confirmed against v0.21.1 and that /proc/self/environ, which can expose API tokens and other secrets on a Linux deployment, was exfiltrated.
Fix: Add validate_safe_path(file_path) before the open() call in _upload_attachment_direct(), as the source proposes.
GitHub Advisory Database
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.