Model Context Protocol
The Model Context Protocol and the servers and clients that expose tools and data to models through it.
- All items
- 295
- Last 90 days
- 133
- Change
- +53%vs 87 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 2 |
| Jun 2025 | 4 |
| Jul 2025 | 4 |
| Aug 2025 | 7 |
| Sep 2025 | 3 |
| Oct 2025 | 3 |
| Nov 2025 | 2 |
| Dec 2025 | 4 |
| Jan 2026 | 4 |
| Feb 2026 | 12 |
| Mar 2026 | 22 |
| Apr 2026 | 27 |
| May 2026 | 31 |
| Jun 2026 | 25 |
| Jul 2026 | 43 |
| Aug 2026 | 45 |
| Sep 2026 | 40 |
| Oct 2026 | 16 |
198 items
CVE-2026-59207: n8n AI Agents MCP tool ignores credential HTTP domain restriction
Jul 9, 2026HighVulnerabilitySecurityCVE-2026-59207CVE-2026-59207 is a vulnerability in n8n, an open source workflow automation platform, affecting versions before 2.27.4 and 2.28.1. The AI Agents feature did not enforce the Allowed HTTP Request Domains restriction configured on credentials when an MCP tool was pointed at an arbitrary URL. A member-level user with use-only access to a shared credential could send its secret to an external server they control.
Fix: This issue is fixed in versions 2.27.4 and 2.28.1.
NVD/CVE DatabaseGHSA-52vm-mxx8-f227: Phantom: Arbitrary file write and decode-bomb DoS via unconfined MCP tool paths
Jul 9, 2026HighVulnerabilitySecurityIn Phantom 1.3.0 and earlier, the MCP tools accepted arbitrary absolute output paths when PHANTOM_OUTPUT_DIR was unset, the default. Any caller able to send tool calls, such as an AI agent, could write or overwrite files the process user can write, including shell startup files. Separately, the stem-separation and render paths decoded input audio without a size or duration cap, so a small compressed FLAC or OGG file could expand to multi-gigabyte PCM and exhaust memory.
Fix: Fixed in 1.3.1: file writes are confined to PHANTOM_OUTPUT_DIR (default ~/.phantom/output), with symlinks resolved and re-verified on the final path; decode, duration and size guards were added to the separation and render paths, plus ffmpeg -max_alloc/-t/-fs; output creation uses atomic O_CREAT|O_EXCL. Workaround: set PHANTOM_OUTPUT_DIR (and optionally PHANTOM_AUDIO_DIR) to dedicated directories before starting the server.
GitHub Advisory DatabaseCVE-2026-59822: LiteLLM authentication bypass through MCP Streamable HTTP endpoint
Jul 8, 2026HighVulnerabilitySecurityCVE-2026-59822Actively ExploitedCVE-2026-59822 affects LiteLLM versions prior to 1.84.0. An unauthenticated attacker could send a fabricated Authorization header to the MCP Streamable HTTP endpoint, triggering an OAuth2 passthrough fallback that replaces failed key validation with an empty UserAPIKeyAuth() object. This lets requests reach MCP tooling without a valid LiteLLM key. The GitHub-assigned CVSS 4.0 base score is 8.8 (HIGH), and CWE-287 and CWE-306 are listed.
Fix: Fixed in 1.84.0.
NVD/CVE DatabaseGHSA-wqxv-w64v-5wh6: Suspended Coder users retain access to AI Bridge LLM proxy endpoints
Jul 6, 2026MediumVulnerabilitySecurityCVE-2026-55435Coder's AI Bridge authorization logic, implemented in `Server.IsAuthorized` in `coderd/aibridgedserver`, does not check whether a user account is suspended, so a suspended user's unexpired API key keeps working against AI Bridge LLM proxy endpoints. The flaw affects AI Bridge from v2.30.0 onward, and the v2.29 ESR line is not affected. An attacker holding such a token can consume paid provider resources billed to the deployment and, if injected MCP tools are enabled, invoke those tools until the token expires.
Fix: Fixed in v2.34.2 (2.34 line), v2.33.8 (2.33 line) and v2.32.7 (2.32 line). Workaround: on suspension, delete the user's API keys via `DELETE /api/v2/users/{user}/keys`.
GitHub Advisory DatabaseCVE-2026-13341: Kong Konnect MCP server indirect prompt injection flaw
Jul 3, 2026HighVulnerabilitySecurityCVE-2026-13341A vulnerability in the Kong Konnect Model Context Protocol (MCP) server prior to version 1.0.0 could allow a remote attacker to perform an indirect prompt injection attack and execute unintended API requests. The weakness is classified as CWE-20, Improper Input Validation, and NVD has not yet provided an assessment.
NVD/CVE DatabaseGHSA-f9ff-5x35-7gfw: Grackle: Fail-open authorization in the MCP tool layer lets scoped agents perform cross-task and cross-session mutations (IDOR)
Jul 2, 2026HighVulnerabilitySecurityGrackle's MCP server, `@grackle-ai/mcp` with `@grackle-ai/plugin-core` and `@grackle-ai/auth`, is affected through version 0.132.1 and earlier. Authorization for scoped agent callers is enforced inline per tool and omitted in several mutating tools, such as `task_update`, `task_delete`, `task_resume`, `session_kill` and `session_resume`, so a scoped agent can act on sibling, parent or cross-workspace tasks and sessions. Backend gRPC handlers perform no caller-based authorization, making the MCP tool layer the sole boundary.
GitHub Advisory DatabaseCVE-2026-7663: IBM Langflow OSS unauthenticated access to MCP project resources
Jun 30, 2026CriticalVulnerabilitySecurityCVE-2026-7663CVE-2026-7663 affects IBM Langflow OSS versions 1.0.0 through 1.9.6. The flaw is improper authorization enforcement in the Streamable MCP transport endpoint, which allows unauthenticated attackers to access protected MCP project resources and execute MCP operations. The weakness is classified as CWE-285 (Improper Authorization), and NVD had not yet provided an assessment at the time of publication.
NVD/CVE DatabaseCVE-2026-54030: LibreChat MCP OAuth token theft through unvalidated resource parameter
Jun 25, 2026HighVulnerabilitySecurityCVE-2026-54030CVE-2026-54030 affects LibreChat before 0.8.5. Its MCP OAuth implementation does not check that the resource parameter from OAuth Protected Resource metadata (RFC 9728) matches the configured MCP server URL. A malicious MCP server can therefore steal access tokens meant for a legitimate server.
Fix: Fixed in 0.8.5.
NVD/CVE DatabaseGHSA-c693-x898-5g4h: BerriAI litellm has SSRF via Unvalidated spec_path URL in MCP OpenAPI Spec Loader
Jun 21, 2026LowVulnerabilitySecurityCVE-2026-12798A weakness in BerriAI litellm up to 1.82.2 lies in the load_openapi_spec_async function of litellm/proxy/_experimental/mcp_server/openapi_to_mcp_generator.py, within the MCP OpenAPI Spec Loader component. Manipulating the spec_path argument causes server-side request forgery, and it can be exploited remotely. A public exploit exists, and the vendor was contacted early about the disclosure.
GitHub Advisory DatabaseGHSA-4jcj-7x88-m979: LiteLLM: MCP Proxy Has Improper Authentication
Jun 21, 2026MediumVulnerabilitySecurityCVE-2026-12773A weakness in BerriAI litellm up to 1.59.8 affects the function UserAPIKeyAuth in litellm/proxy/_experimental/mcp_server/auth/user_api_key_auth_mcp.py, part of the MCP Proxy component. Manipulating this component can lead to improper authentication, and the attack can be launched remotely. A public exploit exists, and the vendor was contacted early about the disclosure.
GitHub Advisory DatabaseGHSA-mrvx-jmjw-vggc: SearXNG MCP Server: DNS-resolved Private Hostname SSRF in `web_url_read`
Jun 19, 2026HighVulnerabilitySecurityThe `web_url_read` tool in `mcp-searxng` is vulnerable to SSRF via DNS rebinding. The `assertUrlAllowed()` function in `src/url-reader.ts` checks only the hostname string against a private address blocklist and performs no DNS resolution, so a domain that resolves to a private or loopback IP bypasses the check. In default HTTP mode, where `requireAuth` is `false`, an attacker can read arbitrary internal HTTP services reachable from the server host without authentication.
Fix: The source recommends resolving the hostname with `node:dns/promises` inside `assertUrlAllowed()` before the fetch is issued, rejecting non-http(s) protocols, and checking the resolved addresses against the private IPv4 and IPv6 checks, with `assertUrlAllowed()` made async and awaited at both call sites.
GitHub Advisory DatabaseGHSA-xcqx-9jf5-w339: SearXNG MCP Server: Unbounded Response Body Read Bypasses URL Size Limit in `web_url_read`
Jun 19, 2026HighVulnerabilitySecurityThe `web_url_read` tool in mcp-searxng enforces its 5 MiB response limit only by checking the `Content-Length` header from a preliminary HEAD request. When a server omits that header, `checkContentLength()` returns `null`, the guard evaluates to `false`, and `response.text()` reads the full body with no byte cap. An unauthenticated attacker who controls or can redirect to an HTTP endpoint can force unbounded memory and CPU use, causing a Denial of Service.
Fix: Replace both `response.text()` calls with a streaming reader that aborts once the byte counter exceeds `maxContentLengthBytes`.
GitHub Advisory DatabaseGHSA-vcv2-r9jh-99m5: Agentic-Flow: OS Command Injection in agentic-flow MCP server tools via unsanitized tool-parameter interpolation into execSync
Jun 19, 2026HighVulnerabilitySecurityagentic-flow versions <= 2.0.13 interpolated MCP tool parameters such as agent, task, name, language and agentdb arguments directly into shell command strings passed to execSync(). A malicious value can break out of the double-quoted argument and run arbitrary OS commands with the privileges of the user running the MCP server. The HTTP/SSE transports expose the same sinks without authentication or Origin/Host validation.
Fix: Fixed in agentic-flow@2.0.14, which rewrites every affected call site to use execFileSync(file, argv, { shell: false }). Upgrade to agentic-flow >= 2.0.14. There is no in-product configuration that mitigates this without upgrading.
GitHub Advisory DatabaseGHSA-r78r-rwrf-rjwp: Network-AI: CVE-2026-46701 fix incomplete — empty default secret still authorizes all requests
Jun 19, 2026CriticalVulnerabilitySecurityCVE-2026-48814The fix for CVE-2026-46701 in Network-AI, npm package network-ai, is incomplete on the latest v5.7.1. The 5.4.5 release restricted Access-Control-Allow-Origin to localhost origins, but the SSE MCP server still defaults to an empty secret, and _isAuthorized() returns true when the secret is empty. Any non-browser caller can therefore invoke all 22 MCP tools without credentials, including config_set, agent_spawn, blackboard_write and token_* tools.
Fix: Implement the advisory's remediation #1: refuse to start SSE mode with an empty secret (unless --stdio), and/or make _isAuthorized fail closed so an empty configured secret denies requests. The CORS allowlist alone does not authenticate non-browser callers.
GitHub Advisory DatabaseGHSA-qrx8-25qr-5r7v: n8n: MCP Browser HTTP Transport Exposes Unauthenticated Browser-Control Sessions
Jun 16, 2026HighVulnerabilitySecurityCVE-2026-54309When @n8n/mcp-browser runs in HTTP transport mode (--transport http), its MCP endpoint accepts session initialization and tool calls with no authentication. Any network-reachable client, or any website the user visits, can open an MCP session and invoke browser-control tools. Where the n8n AI Browser Bridge extension is installed and a browser connection is active, the attacker gets navigation, JavaScript evaluation, and cookie and storage access against the user's real browser profile. The default stdio transport is not affected.
Fix: The issue has been fixed in n8n versions 2.25.7 and 2.26.2; upgrade to one of these or later. Temporary workarounds: avoid HTTP transport and use the default stdio transport instead, or if HTTP is required, restrict network access to the listening port to trusted clients using host-based firewall rules. The source states these workarounds do not fully remediate the risk and are short-term measures only.
GitHub Advisory DatabaseGHSA-8q5r-mmjf-575q: Claude Code Action: Malicious MCP Server Configuration in PRs Enables Remote Code Execution and Secret Exfiltration
Jun 10, 2026MediumVulnerabilitySecurityCVE-2026-47751A flaw in claude-code-action combined checking out attacker-controlled PR head branches, reading `.mcp.json` from the working directory through default setting sources, and unconditionally enabling all project MCP servers via `enableAllProjectMcpServers`. An attacker who opens a PR containing a malicious `.mcp.json` can achieve arbitrary code execution on the GitHub Actions runner. This can expose workflow secrets such as API keys and tokens when a privileged user or automatic trigger runs the action on that PR.
Fix: Users pinned to a vulnerable version of claude-code-action are advised to update to the latest version. Users referencing anthropics/claude-code-action@v1, anthropics/claude-code-action@beta, anthropics/claude-code-action@main, or other non-pinned tags have already received the fix.
GitHub Advisory DatabaseGHSA-6mx4-4h42-r8vh: MCP Server Kubernetes: kubectl-generic flag injection enables Kubernetes bearer token exfiltration
Jun 5, 2026MediumVulnerabilitySecurityCVE-2026-47250The kubectl_generic tool in mcp-server-kubernetes passes user-supplied flags and args straight to kubectl with no allowlist. An attacker with limited access can plant a JSON log line that an AI agent follows, causing kubectl to send the operator's Authorization: Bearer token to an attacker endpoint via --server and --insecure-skip-tls-verify=true. The captured token can then be replayed against the real Kubernetes API server, granting the operator's service account RBAC permissions.
GitHub Advisory DatabaseCVE-2026-44653: LibreChat exposes decrypted MCP server secrets to users with view access
Jun 2, 2026MediumVulnerabilitySecurityCVE-2026-44653In LibreChat versions up to and including 0.8.3, users with only VIEW access to an MCP server can retrieve the server's decrypted admin-managed secrets through GET /api/mcp/servers and GET /api/mcp/servers/:serverName. The returned config includes plaintext apiKey.key and oauth.client_secret values, letting viewers of a shared MCP server exfiltrate the underlying provider credentials.
Fix: Version 0.8..4 contains a patch. Other remediations include: never returning decrypted admin-managed secrets to non-owners; redacting apiKey.key and oauth.client_secret from all API responses, considering returning only boolean presence indicators for secrets, similar to the auth-values route pattern; and, if owners need to edit configs without re-entering secrets, preserving secrets server-side and returning placeholders instead of plaintext.
NVD/CVE DatabaseCVE-2026-32625: LibreChat MCP server integration leaks secrets via user-supplied URLs
Jun 2, 2026CriticalVulnerabilitySecurityIndustryCVE-2026-32625LibreChat versions up to and including 0.8.3 resolve ${VAR} placeholders against the server's process.env during Zod schema validation of user-supplied MCP server URLs. An authenticated user can submit an MCP server configuration pointing to an attacker-controlled domain, causing the server to transmit secrets such as CREDS_KEY, CREDS_IV, JWT_SECRET and MONGO_URI in the request URL, without administrative privileges.
Fix: Fixed in 0.8.4-rc1.
NVD/CVE DatabaseGHSA-9cr9-25q5-8prj: PraisonAI vulnerable to unauthenticated arbitrary file read via MCP workflow.show, workflow.validate, deploy.validate
May 29, 2026HighVulnerabilitySecurityCVE-2026-47394The fix for GHSA-9mqq-jqxf-grvw / CVE-2026-44336 is incomplete. Commit 68cc9427 added _resolve_rule_path() to rules.create, rules.show and rules.delete in mcp_server/adapters/cli_tools.py, but praisonai.workflow.show, praisonai.workflow.validate and praisonai.deploy.validate remain unchanged. A single unauthenticated MCP tools/call to praisonai.workflow.show can return any file the host user can read, and the dispatcher in server.py, which passes unvalidated arguments as **kwargs, is also unchanged.
GitHub Advisory Database
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.