Model Context Protocol
The Model Context Protocol and the servers and clients that expose tools and data to models through it.
- All items
- 295
- Last 90 days
- 133
- Change
- +53%vs 87 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 2 |
| Jun 2025 | 4 |
| Jul 2025 | 4 |
| Aug 2025 | 7 |
| Sep 2025 | 3 |
| Oct 2025 | 3 |
| Nov 2025 | 2 |
| Dec 2025 | 4 |
| Jan 2026 | 4 |
| Feb 2026 | 12 |
| Mar 2026 | 22 |
| Apr 2026 | 27 |
| May 2026 | 31 |
| Jun 2026 | 25 |
| Jul 2026 | 43 |
| Aug 2026 | 45 |
| Sep 2026 | 40 |
| Oct 2026 | 16 |
295 items
CVE-2026-18655 - Broker Credential and OAuth Token Disclosure in AWS Labs Amazon MQ MCP Server via Prompt Injection
Aug 3, 2026HighVulnerabilitySecurityCVE-2026-18655 is an improper restriction of intended endpoints in the RabbitMQ broker connection tools of the AWS Labs Amazon MQ MCP Server (awslabs.amazon-mq-mcp-server) before 2.0.24, affecting versions <= 2.0.23. A remote unauthenticated actor may obtain Amazon MQ for RabbitMQ broker credentials or OAuth access tokens by sending them to a crafted endpoint controlled through a broker hostname introduced in the MCP client context.
Fix: Fixed in 2.0.24. Upgrade awslabs.amazon-mq-mcp-server to version 2.0.24 or later.
AWS Security BulletinsGHSA-c5px-58j2-7fqp: gemini-bridge vulnerable to arbitrary local file read via consult_gemini_with_files inline mode
Jul 31, 2026MediumVulnerabilitySecurityCVE-2026-54785gemini-bridge's consult_gemini_with_files tool, in inline mode, read any file path given in the files argument without confining it to the working directory, then forwarded the contents to the Gemini CLI. Because the caller also controls query, file contents are echoed back through the Gemini round-trip and sent to Google, letting an MCP client or a prompt-injected LLM read any file the server process can access.
Fix: Fixed in 1.3.1. _resolve_path now resolves symlinks and confines paths via Path.relative_to(root), and inline mode skips any entry that resolves outside the working directory. Before upgrading, avoid mode="inline" with untrusted files input, or run the server with a restricted-permission user.
GitHub Advisory DatabaseBalancing speed and safety: A control framework for AI coding agents
Jul 30, 2026InfoNewsSecurityIndustryThis AWS Security Blog post presents an application security control framework for AI coding agents such as Kiro and Claude Code, which can open many pull requests quickly and reach beyond the IDE through the Model Context Protocol (MCP). The framework has two pillars: author-time controls that shape agent output in the IDE, and build-time controls that verify and gate code before production. It lists risks ordered by severity, starting with prompt and context injection (R001), and uses AWS Kiro and AWS CodePipeline as a running example.
Fix: For R001, treat non-developer input as untrusted, separate the orchestrating agent from the agent exposed to untrusted content, grant the exposed agent only read-only, least-privilege access, require human approval for irreversible actions, and use version-control steering files to prevent silent tampering. For R002, use security requirements in a steering document plus policy-as-code scanning (Checkov, cfn-nag) in the IDE and pipeline. For R003, use branch protection rules requiring PR approval, pre-commit hooks for security checks, and sandboxed agent runs that prevent direct pushes to protected branches.
AWS Security BlogCVE-2026-12940: IBM Langflow OSS unauthenticated code execution via MCP stdio launcher
Jul 30, 2026CriticalVulnerabilitySecurityCVE-2026-12940CVE-2026-12940 affects IBM Langflow OSS versions 1.0.0 through 1.10.1. The flaw is in the MCP (Model Context Protocol) stdio launcher, in src/lfx/src/lfx/base/mcp/util.py, where the DANGEROUS_ENV_VARS blocklist omits SHELLOPTS, BASHOPTS, and PS4. Per the source, this allows unauthenticated remote code execution through environment variable injection and is classified as CWE-78, OS Command Injection. NVD had not yet provided an assessment at publication on 07/30/2026.
NVD/CVE DatabaseCritical Ruflo flaw lets attackers hijack AI agents through exposed MCP bridge
Jul 30, 2026MediumNewsSecurityIndustryNoma Security reported CVE-2026-59726, dubbed RufRoot, a critical flaw (CVSS 10.0) in Ruflo versions prior to 3.16.3. An unauthenticated MCP Bridge, exposed by default, accepts tool invocations at its /mcp endpoint, letting attackers run commands, steal LLM API keys, read user conversations and poison AgentDB memory with a single HTTP request. The researchers validated the attack chain against a default Ruflo deployment on AWS EC2.
Fix: Patch addresses attack chain
CSO OnlineRuflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory
Jul 29, 2026MediumNewsSecurityIndustryResearchers at Noma Labs disclosed CVE-2026-59726 (CVSS 10.0), dubbed RufRoot, in Ruflo, an open-source agent meta-harness for Claude Code and Codex, affecting all versions before 3.16.3. The default docker-compose.yml binds port 3001 to 0.0.0.0, exposing an unauthenticated MCP bridge that exposes 233 tools, including terminal_execute. A single unauthenticated POST to /mcp allows remote code execution, enabling theft of LLM provider API keys, reading of stored conversations, and poisoning of AgentDB memory.
Fix: Fixed in version 3.16.3. The patch binds the MCP bridge to the loopback interface by default, gates terminal_execute behind server-side executeTool controls, and enables MongoDB authentication. Operators with exposed instances are advised to close firewall ports 3001 and 27017, rotate all LLM API keys, audit the AgentDB pattern store for injected agentdb_pattern-store entries, and check MongoDB for tampering.
The Hacker NewsAdding a custom MCP server to Claude and ChatGPT
Jul 28, 2026InfoNewsIndustrySimon Willison writes a short TIL post on July 29, 2026, about adding a custom MCP server to the Claude and ChatGPT web chat interfaces. He says the setup is possible but takes quite a few steps and is not obvious.
Simon Willison's Weblog2026-07-28
Jul 28, 2026InfoResearchIndustryIndustryThe Model Context Protocol has published a stable release of its 2026-07-28 revision. The specification is available on the official Model Context Protocol website, and a changelog describes the changes in detail.
MCP Specification ReleasesThe risk hiding behind exposed MCP servers
Jul 28, 2026MediumNewsSecurityIndustryWiz Research examined MCP servers left reachable from the Internet, often without authentication, and found several run by Fortune 500 companies. These exposed employee PII, internal business records, write and delete operations, and in some cases code execution and cloud credentials. Roughly 1 in 6 cloud environments where MCP was found exposed at least one server.
Wiz Research BlogGHSA-29w2-fq35-v728: AWS API MCP Server Security Policy Bypass via Startup Initialization Failure
Jul 24, 2026HighVulnerabilitySecurityCVE-2026-16584The AWS API MCP Server, an open source Model Context Protocol server for running AWS CLI commands, skips its per-request security policy check for the lifetime of the process if the policy enforcement data fails to load at startup. Deny and gate rules are then not consulted, so restricted AWS API operations execute, though IAM permissions on the configured credentials still apply. Affected versions are >= 0.2.13 and < 1.3.47.
Fix: Fixed in awslabs.aws-api-mcp-server version 1.3.47. Until upgrading, use least-privilege IAM credentials (for example, a ReadOnlyAccess role) scoped to the task, or restart the server once connectivity is restored if it started during degraded connectivity.
GitHub Advisory DatabaseCVE-2026-66005: Jan local API server CORS misconfiguration allows trusted host bypass
Jul 24, 2026MediumVulnerabilitySecurityCVE-2026-66005CVE-2026-66005 affects Jan through 0.8.4 and is fixed in commit 3e1c1e7. The local API server has a CORS misconfiguration: it replaces user-configured trusted hosts with a wildcard that reflects arbitrary origins with credentials. Network-adjacent attackers, or attackers using DNS rebinding, can reach the unauthenticated OpenAI-compatible API to run inference, enumerate models, invoke MCP tools, and read cross-origin responses.
Fix: Fixed in commit 3e1c1e7.
NVD/CVE DatabaseCVE-2026-16584 - AWS API MCP Server Security Policy Bypass via Startup Failure
Jul 23, 2026HighVulnerabilitySecurityCVE-2026-16584 affects the AWS API MCP Server (awslabs.aws-api-mcp-server) for versions >= 0.2.13 and < 1.3.47. If the server fails to load its optional user-configured security policy at startup, it keeps running with the per-request policy check skipped, so AWS API operations the policy was set to deny or gate can execute without enforcement, provided fail-closed modes are not enabled. IAM permissions on the configured credentials remain in effect.
AWS Security BulletinsGHSA-q5xf-xhwf-cwqf: n8n: Member-Level Users Can Execute Other Users' MCP Server Trigger Workflows via Missing OAuth Authorization Check
Jul 22, 2026MediumVulnerabilitySecurityCVE-2026-65594GHSA-q5xf-xhwf-cwqf affects n8n instances running 2.27.0 or later with an active workflow using an MCP Server Trigger node configured with `n8n OAuth2` authentication. The OAuth 2.1 consent and token-issuance flow does not check whether the authenticated user can access the referenced workflow, so a member-level user can self-approve consent for another user's workflow and obtain a valid token. The workflow then runs in the owner's project context with the owner's stored credentials, letting the attacker set inputs and read outputs, which may include data from the owner's connected integrations.
Fix: Fixed in n8n 2.29.8 and 2.30.1; upgrade to one of these versions or later. If upgrading is not immediately possible, restrict instance access to fully trusted users only and audit active MCP Server Trigger workflows using `n8n OAuth2`, switching their authentication method or deactivating them until the patch is applied. These workarounds do not fully remediate the risk and are short-term measures only.
GitHub Advisory DatabaseGHSA-vhf8-cg2h-cg3p: n8n: SSRF Protection Bypass via MCP Client Node
Jul 22, 2026MediumVulnerabilitySecurityThe MCP Client node in n8n sent requests to user-supplied endpoints without routing them through SSRF protection or pinning the resolved address. An authenticated user who could create or edit a workflow could make the server connect to internal or blocked hosts and read the responses back through the workflow. The issue affects instances with SSRF protection enabled.
Fix: Fixed in n8n versions 2.31.5 and 2.32.1; upgrade to one of these or later. If upgrading is not immediately possible, temporary mitigations include restricting instance access to fully trusted users only, disabling the MCP Client node by adding it to the `NODES_EXCLUDE` environment variable, and restricting network egress from the n8n host to block internal and link-local address ranges. These workarounds do not fully remediate the risk and should only be short-term measures.
GitHub Advisory DatabaseCVE-2026-44192: Ansible Lightspeed MCP server path traversal via indirect prompt injection
Jul 22, 2026MediumVulnerabilitySecurityCVE-2026-44192CVE-2026-44192 is a path traversal flaw in the Ansible Lightspeed Model Context Protocol (MCP) server, classified as CWE-22. An attacker can use indirect prompt injection to manipulate an AI agent, causing the server to write files to unauthorized locations on the user's system. The source says this can expose sensitive host information and enable execution of malicious commands, potentially leading to full system compromise.
NVD/CVE DatabaseMicrosoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents
Jul 22, 2026MediumNewsSecurityIndustryA hidden HTML comment in an Azure DevOps pull request description can hijack a reviewer's AI coding agent through Microsoft's official Azure DevOps MCP server. The repo_get_pull_request_by_id tool returns descriptions without the spotlighting guardrail that other tools in the server already apply, which Manifold Security says is the gap. In a proof of concept run on a local build of v2.7.0, the injected instructions led the agent to trigger a pipeline in another project, read a confidential wiki page, and post it back to the PR.
The Hacker NewsFakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware
Jul 20, 2026MediumNewsSecurityIndustryCybersecurity researchers found nearly 7,600 malicious GitHub repositories created by about 6,600 profiles, more than 800 of which pose as AI skills or Model Context Protocol (MCP) servers to deliver SmartLoader malware in a campaign called FakeGit. The campaign then pushes secondary payloads such as StealC, an information stealer. Island's tests found Anthropic Claude Code, Google Gemini and OpenAI ChatGPT susceptible to surfacing these repositories, a technique it calls AgentBaiting.
Fix: To counter the threat, it's advised to build a catalog of reviewed Skills, MCP servers, and agent plugins, evaluate new agent capabilities in a sandboxed environment first before broader rollout, verify both the publisher and the project to ensure credibility.
The Hacker NewsCVE-2026-46555: WhatsApp MCP Server bridge API unauthenticated local and DNS rebinding access
Jul 20, 2026HighVulnerabilitySecurityCVE-2026-46555WhatsApp MCP Server, prior to version 0.2.1, exposes its `whatsapp-bridge` HTTP API on `127.0.0.1:8080` without authentication or Host header validation, and the `/api/send` endpoint accepts an absolute `media_path` without confinement to a safe directory. A local process running as the same user, or a remote attacker via DNS rebinding from a visited webpage, can send messages from the paired account, read arbitrary user-readable files such as SSH keys, and exfiltrate them as WhatsApp attachments.
Fix: Fixed in whatsapp-mcp v0.2.1 and corresponding Docker images and release artifacts, which add bearer token authentication, host header allow-list validation, and confinement of `media_path` to a configured directory. This is a breaking change for bridge API clients. Users who cannot upgrade immediately should stop the bridge or block loopback access to port 8080 when unused, avoid running it alongside untrusted MCP servers or local processes, avoid browsing untrusted sites while it runs, and/or run it under a dedicated user account or in a sandbox/container without access to sensitive files.
NVD/CVE DatabaseCVE-2026-7755: IBM Langflow OSS remote code execution via MCP server configuration files
Jul 17, 2026HighVulnerabilitySecurityCVE-2026-7755CVE-2026-7755 affects IBM Langflow OSS versions 1.0.0 through 1.10.0. The flaw is incomplete validation enforcement on MCP server configuration files, which could allow remote code execution. NIST has not yet provided an NVD assessment.
NVD/CVE DatabaseGHSA-f7wf-v2vw-mpcx: mcp-memory-keeper: Arbitrary local file read in context_import via unvalidated filePath
Jul 17, 2026MediumVulnerabilitySecurityCVE-2026-54561GHSA-f7wf-v2vw-mpcx affects mcp-memory-keeper, where the context_import tool passed the caller-supplied filePath directly to fs.readFileSync without path confinement. A malicious MCP client, or an LLM agent prompt-injected into calling the tool, could read any file the server process can access. Valid JSON files are imported in full and retrievable through context_get or context_export, while other files leak their leading bytes through the JSON.parse SyntaxError message.
Fix: Fixed in 0.13.0 (PR #36). Upgrade to >= 0.13.0. There is no configuration-only workaround for affected versions.
GitHub Advisory Database
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.