Model Context Protocol
The Model Context Protocol and the servers and clients that expose tools and data to models through it.
- All items
- 295
- Last 90 days
- 133
- Change
- +53%vs 87 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 2 |
| Jun 2025 | 4 |
| Jul 2025 | 4 |
| Aug 2025 | 7 |
| Sep 2025 | 3 |
| Oct 2025 | 3 |
| Nov 2025 | 2 |
| Dec 2025 | 4 |
| Jan 2026 | 4 |
| Feb 2026 | 12 |
| Mar 2026 | 22 |
| Apr 2026 | 27 |
| May 2026 | 31 |
| Jun 2026 | 25 |
| Jul 2026 | 43 |
| Aug 2026 | 45 |
| Sep 2026 | 40 |
| Oct 2026 | 16 |
295 items
CVE-2026-58195: Agentic-Flow MCP server tools command execution through shell interpolation
Jul 17, 2026HighVulnerabilitySecurityCVE-2026-58195Agentic-Flow, an AI agent orchestration platform, is affected in versions prior to 2.0.14. Several MCP server tool files interpolate attacker-influenceable parameters such as agent, task, name, language and agentdb directly into shell command strings passed to execSync(). This allows arbitrary OS command execution with the privileges of the MCP server user.
Fix: This issue is fixed in version 2.0.14.
NVD/CVE DatabaseNew NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens
Jul 17, 2026MediumNewsSecurityIndustryA Go botnet called NadMesh targets exposed AI services such as ComfyUI, Ollama, n8n, Open WebUI, Langflow and Gradio, and its operator's dashboard claims 3,811 unique AWS keys. XLab, the QiAnXin research group, published a report on the malware and noted that its figures are internally inconsistent. Per the source, the bots mainly harvest cloud keys, Kubernetes service account tokens and config files, with MCP tool calls such as execute_command ranked high in the controller's exploitation priorities.
The Hacker NewsCVE-2026-9810: AI Copilot WordPress plugin accepts OAuth tokens not bound to a user
Jul 17, 2026CriticalVulnerabilitySecurityCVE-2026-9810CVE-2026-9810 affects the AI Copilot WordPress plugin before 1.5.4. The plugin does not bind OAuth access tokens to a WordPress user and accepts any valid token as an administrator session. Unauthenticated attackers who complete the public OAuth flow can run privileged MCP tools as an administrator, including arbitrary user creation and role escalation.
NVD/CVE DatabaseGHSA-vj7q-gjh5-988w: MCP Python SDK: WebSocket server transport does not support Host/Origin validation
Jul 16, 2026HighVulnerabilitySecurityCVE-2026-59950The deprecated WebSocket server transport, mcp.server.websocket.websocket_server, in the MCP Python SDK accepted WebSocket handshakes without validating the Host or Origin headers, because TransportSecuritySettings was never wired into it. A malicious web page can open a connection to an exposed server on this transport, complete initialize, and invoke its tools and read its resources, and the transport requires no token or prior session. Only applications that wire this transport into their own ASGI server are affected.
Fix: Upgrade to version 1.28.1 or later, which adds the optional security_settings: TransportSecuritySettings argument and validates Host and Origin headers, rejecting failed requests with HTTP 403 and ValueError("Request validation failed"). The parameter defaults to None, which leaves validation disabled, so pass a TransportSecuritySettings with enable_dns_rebinding_protection=True and appropriate allowed_hosts / allowed_origins. The recommended path is to migrate to Streamable HTTP, where FastMCP enables this protection automatically for localhost binds. The WebSocket transport has been removed entirely in v2.
GitHub Advisory DatabaseGHSA-jpw9-pfvf-9f58: MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal
Jul 16, 2026HighVulnerabilitySecurityCVE-2026-52869Affected versions of the MCP Python SDK route requests on the SSE and Streamable HTTP transports to an existing session using only the session identifier, without checking that the request carries the same authenticated principal that created the session. Anyone who learns or guesses a session ID, such as the `session_id` query parameter or `Mcp-Session-Id` header, can send JSON-RPC messages into that session regardless of their bearer token. Only servers that use an HTTP transport and built-in bearer-token authentication are affected; stdio, stateless Streamable HTTP, and unauthenticated servers are not.
Fix: Upgrade to version 1.27.2 or later, which records the authenticated principal that created each session and returns a 404 to requests presenting a different principal. Deployments where many end users share one OAuth client should ensure the token verifier populates `AccessToken.subject`, for example from the `sub` claim, so sessions are isolated per user. Deployments using a custom authentication backend other than `BearerAuthBackend` should enforce an equivalent check themselves.
GitHub Advisory DatabaseGHSA-hvrp-rf83-w775: MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks
Jul 16, 2026HighVulnerabilitySecurityCVE-2026-52870The MCP Python SDK's experimental task handlers, enabled through `server.experimental.enable_tasks()`, did not check which session created a task before acting on it. On a multi-client server, any connected client could list, read, cancel, and consume queued messages such as elicitation requests belonging to other clients' tasks.
Fix: Upgrade to version 1.27.2 or later, in which task IDs generated by `run_task()` embed an opaque per-session marker and the default handlers restrict each session to its own tasks. Alternatively, leave the experimental tasks feature disabled, or register task handlers that validate session ownership.
GitHub Advisory DatabaseCVE-2026-30623: LiteLLM remote code execution through MCP server creation configuration
Jul 15, 2026CriticalVulnerabilitySecurityCVE-2026-30623CVE-2026-30623 affects LiteLLM 1.18.10 in its MCP server creation functionality. Users can add MCP servers through a JSON configuration that sets arbitrary command and args values, which LiteLLM executes on the host without validation, allowing an attacker to run arbitrary operating system commands. Successful exploitation may result in remote code execution with the privileges of the LiteLLM process.
NVD/CVE DatabaseGHSA-3pvh-63gf-j9mw: LangBot: Authenticated RCE Via MCP Configuration
Jul 15, 2026HighVulnerabilitySecurityCVE-2026-54449Any authenticated LangBot user can execute arbitrary OS commands on the server by adding an STDIO MCP server with a chosen command in the MCP configuration. The flaw is in src/langbot/pkg/provider/tools/loaders/mcp.py, where StdioServerParameters from the mcp package spawns a subprocess with the supplied command. The advisory rates this as authenticated remote code execution (CWE-78) affecting publicly reachable instances and, from the same network, local instances.
GitHub Advisory DatabaseSASE Has An AI Blind Spot. Inspecting Packets Is No Longer Enough.
Jul 15, 2026InfoNewsIndustrySecurityThe article argues that traditional SASE, which backhauls traffic to cloud proxies for decryption and inspection, cannot see data interactions in browsers and AI workflows, such as employees pasting intellectual property into public LLMs or agents using model context protocol (MCP) tool calls. It says TLS 1.3, HTTP/3 and certificate pinning cause traditional proxy inspection to fail, forcing teams to write bypass exceptions. The piece proposes enforcing policy at the point of interaction on the device, using the "Perfect Packet" architecture, which evaluates context at the endpoint before routing.
Fix: Enforce policy at the point of interaction on the device (browser and endpoint), inspecting copy, paste and prompt content locally before data leaves the device, and steer traffic to the closest edge infrastructure, invoking cloud inspection only when a session requires additional verification (the "Perfect Packet" architecture).
The Hacker NewsGHSA-2cf7-hpwf-47h9: n8n-MCP: Incorrect authorization can expose default-scope workflow version backups in multi-tenant HTTP mode
Jul 14, 2026MediumVulnerabilitySecurityPrivacyCVE-2026-55608n8n-MCP versions up to and including 2.57.3, when run in multi-tenant HTTP mode (ENABLE_MULTI_TENANT=true), let an authenticated tenant reach the local default-scope workflow_versions backups instead of being confined to its own tenant scope. An attacker with tenant access can read or delete these backups, which may contain sensitive workflow configuration; single-tenant and stdio deployments are not affected.
Fix: Upgrade to n8n-mcp 2.57.4 or later. Workarounds: restrict network access to the HTTP endpoint (firewall, reverse proxy or VPN), run in stdio mode, or remove default-scope backups from a prior single-tenant deployment if they are not needed.
GitHub Advisory DatabaseCVE-2026-15643 - AWS HealthLake MCP Server SSRF via Unvalidated Pagination URL
Jul 14, 2026HighVulnerabilitySecurityCVE-2026-15643 is a server-side request forgery in the pagination handling of the awslabs.healthlake-mcp-server (AWS HealthLake MCP Server) before 0.0.14, on all platforms. A remote authenticated user can craft a next_token parameter so that the server does not validate the pagination URL against the expected HealthLake endpoint, redirecting requests to an actor-controlled server and exfiltrating AWS temporary security credentials.
AWS Security BulletinsGHSA-j6r7-6fhx-77wx: n8n-MCP: Cross-tenant access to workflow version backups in multi-tenant HTTP deployments
Jul 14, 2026CriticalVulnerabilitySecurityCVE-2026-54052In multi-tenant HTTP deployments of n8n-mcp (ENABLE_MULTI_TENANT=true), the locally stored workflow version history was not isolated per tenant. An authenticated tenant could read other tenants' workflow version snapshots, which can include node credential references and authorization headers, and could delete their backups. Affected versions are <= 2.56.0; stdio and single-tenant HTTP deployments are not affected.
Fix: Fixed in 2.56.1, which isolates the stored version history per instance; upgrading runs a one-time migration that isolates existing history and clears previously stored, un-scoped backups. Workarounds: set DISABLED_TOOLS=n8n_workflow_versions in the server environment, run each tenant on a separate instance with its own database, or restrict network access to the HTTP endpoint to trusted operators.
GitHub Advisory DatabaseHow Pentera Turns AI Security Workflows into Validation Engines
Jul 14, 2026InfoNewsSecurityIndustryPentera describes how AI security workflows that rely on scanner output, severity scores and other disconnected risk signals cannot tell whether findings form a real attack path. The source argues that security validation, which emulates attacker techniques against production environments to produce evidence of exploitable exposures, should ground these workflows. Pentera introduced an MCP (Model Context Protocol) Server to make its validation data available to MCP-compatible AI assistants.
The Hacker NewsGHSA-g5r6-gv6m-f5jv: mcp-atlassian: Arbitrary file read via missing path validation in confluence_upload_attachment
Jul 10, 2026HighVulnerabilitySecurityThe mcp-atlassian server's confluence_upload_attachment tool passes a caller-supplied file_path directly to open() in _upload_attachment_direct() in src/mcp_atlassian/confluence/attachments.py, without the validate_safe_path() check that download_attachment() applies. Any authenticated MCP client, or an AI agent steered by prompt injection, can read files the server process can access and upload them to Confluence as attachments. The source reports this was confirmed against v0.21.1 and that /proc/self/environ, which can expose API tokens and other secrets on a Linux deployment, was exfiltrated.
Fix: Add validate_safe_path(file_path) before the open() call in _upload_attachment_direct(), as the source proposes.
GitHub Advisory DatabaseIntroducing OAuth Support for AWS MCP Server
Jul 9, 2026InfoNewsIndustrySecurityAWS has added OAuth sign-in to its AWS MCP Server, letting agents connect using the same credentials used for the AWS Management Console or AWS CLI. The release adds global condition keys for OAuth, token introspection and revocation, dynamic client registration, new AWS CloudTrail elements, and a headless OAuth API, all compatible with existing IAM configuration. The source notes that authorizing an agent grants access on the user's behalf but does not grant additional AWS permissions.
AWS Security BlogCVE-2026-59207: n8n AI Agents MCP tool ignores credential HTTP domain restriction
Jul 9, 2026HighVulnerabilitySecurityCVE-2026-59207CVE-2026-59207 is a vulnerability in n8n, an open source workflow automation platform, affecting versions before 2.27.4 and 2.28.1. The AI Agents feature did not enforce the Allowed HTTP Request Domains restriction configured on credentials when an MCP tool was pointed at an arbitrary URL. A member-level user with use-only access to a shared credential could send its secret to an external server they control.
Fix: This issue is fixed in versions 2.27.4 and 2.28.1.
NVD/CVE DatabaseGHSA-52vm-mxx8-f227: Phantom: Arbitrary file write and decode-bomb DoS via unconfined MCP tool paths
Jul 9, 2026HighVulnerabilitySecurityIn Phantom 1.3.0 and earlier, the MCP tools accepted arbitrary absolute output paths when PHANTOM_OUTPUT_DIR was unset, the default. Any caller able to send tool calls, such as an AI agent, could write or overwrite files the process user can write, including shell startup files. Separately, the stem-separation and render paths decoded input audio without a size or duration cap, so a small compressed FLAC or OGG file could expand to multi-gigabyte PCM and exhaust memory.
Fix: Fixed in 1.3.1: file writes are confined to PHANTOM_OUTPUT_DIR (default ~/.phantom/output), with symlinks resolved and re-verified on the final path; decode, duration and size guards were added to the separation and render paths, plus ffmpeg -max_alloc/-t/-fs; output creation uses atomic O_CREAT|O_EXCL. Workaround: set PHANTOM_OUTPUT_DIR (and optionally PHANTOM_AUDIO_DIR) to dedicated directories before starting the server.
GitHub Advisory DatabaseCVE-2026-59822: LiteLLM authentication bypass through MCP Streamable HTTP endpoint
Jul 8, 2026HighVulnerabilitySecurityCVE-2026-59822Actively ExploitedCVE-2026-59822 affects LiteLLM versions prior to 1.84.0. An unauthenticated attacker could send a fabricated Authorization header to the MCP Streamable HTTP endpoint, triggering an OAuth2 passthrough fallback that replaces failed key validation with an empty UserAPIKeyAuth() object. This lets requests reach MCP tooling without a valid LiteLLM key. The GitHub-assigned CVSS 4.0 base score is 8.8 (HIGH), and CWE-287 and CWE-306 are listed.
Fix: Fixed in 1.84.0.
NVD/CVE DatabaseGHSA-wqxv-w64v-5wh6: Suspended Coder users retain access to AI Bridge LLM proxy endpoints
Jul 6, 2026MediumVulnerabilitySecurityCVE-2026-55435Coder's AI Bridge authorization logic, implemented in `Server.IsAuthorized` in `coderd/aibridgedserver`, does not check whether a user account is suspended, so a suspended user's unexpired API key keeps working against AI Bridge LLM proxy endpoints. The flaw affects AI Bridge from v2.30.0 onward, and the v2.29 ESR line is not affected. An attacker holding such a token can consume paid provider resources billed to the deployment and, if injected MCP tools are enabled, invoke those tools until the token expires.
Fix: Fixed in v2.34.2 (2.34 line), v2.33.8 (2.33 line) and v2.32.7 (2.32 line). Workaround: on suspension, delete the user's API keys via `DELETE /api/v2/users/{user}/keys`.
GitHub Advisory DatabaseCVE-2026-13341: Kong Konnect MCP server indirect prompt injection flaw
Jul 3, 2026HighVulnerabilitySecurityCVE-2026-13341A vulnerability in the Kong Konnect Model Context Protocol (MCP) server prior to version 1.0.0 could allow a remote attacker to perform an indirect prompt injection attack and execute unintended API requests. The weakness is classified as CWE-20, Improper Input Validation, and NVD has not yet provided an assessment.
NVD/CVE Database
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.