Model Context Protocol
The Model Context Protocol and the servers and clients that expose tools and data to models through it.
- All items
- 295
- Last 90 days
- 133
- Change
- +53%vs 87 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 2 |
| Jun 2025 | 4 |
| Jul 2025 | 4 |
| Aug 2025 | 7 |
| Sep 2025 | 3 |
| Oct 2025 | 3 |
| Nov 2025 | 2 |
| Dec 2025 | 4 |
| Jan 2026 | 4 |
| Feb 2026 | 12 |
| Mar 2026 | 22 |
| Apr 2026 | 27 |
| May 2026 | 31 |
| Jun 2026 | 25 |
| Jul 2026 | 43 |
| Aug 2026 | 45 |
| Sep 2026 | 40 |
| Oct 2026 | 16 |
198 items
CVE-2026-44895: GitLab MCP Server HTTP transport accepts unauthenticated requests
May 26, 2026CriticalVulnerabilitySecurityCVE-2026-44895CVE-2026-44895 affects the GitLab MCP Server before 0.6.0. Its HTTP transport in src/transport.ts has no authentication and sends a wildcard Access-Control-Allow-Origin: * header, while exposing a mutation-capable RPC endpoint backed by GITLAB_PERSONAL_ACCESS_TOKEN. Because httpServer.listen(port) at line 97 passes no host, the server binds to 0.0.0.0 and exposes this surface on every interface.
Fix: Fixed in 0.6.0.
NVD/CVE DatabaseGHSA-j3vx-cx2r-pvg8: Network-AI: Unauthenticated Cross-Origin MCP Tool Invocation via Empty Default Secret
May 21, 2026HighVulnerabilitySecurityCVE-2026-46701Network-AI v5.4.4 defaults the MCP SSE server secret to an empty string (`process.env['NETWORK_AI_MCP_SECRET'] ?? ''` in `bin/mcp-server.ts`), so `_isAuthorized` in `lib/mcp-transport-sse.ts` returns true for every request with no Authorization header. The server also sends `Access-Control-Allow-Origin: *` on every response, letting a cross-origin browser script read results. An attacker who lures a user to a malicious web page can invoke all 22 exposed MCP tools, including `config_set`, `agent_spawn` and `blackboard_write`, against a default-configured localhost server.
GitHub Advisory DatabaseGHSA-cr22-wjx7-2w6m: MCP Server Kubernetes: Tool Access Control Bypass via Presentation-Layer Filtering Without Execution-Layer Enforcement
May 21, 2026HighVulnerabilitySecurityCVE-2026-46519The mcp-server-kubernetes package exposes ALLOW_ONLY_READONLY_TOOLS, ALLOW_ONLY_NON_DESTRUCTIVE_TOOLS and ALLOWED_TOOLS as access controls, but they are enforced only at tools/list and not at tools/call. Any client that knows a tool name can invoke it directly, so kubectl_delete, exec_in_pod, kubectl_generic and node_management run regardless of the configured restriction, which the advisory says is equivalent to full cluster compromise when the service account has cluster-admin.
Fix: Fixed in v3.6.0. The fix applies the same filtering logic from ListToolsRequestSchema at the start of the CallToolRequestSchema handler, returning an error for any tool call outside the active allowed set.
GitHub Advisory DatabaseGHSA-22qr-rp27-j9wm: PenPot MCP REPL server binds to 0.0.0.0 with unauthenticated /execute endpoint — RCE
May 19, 2026HighVulnerabilitySecurityCVE-2026-45805The PenPot MCP module's ReplServer binds to 0.0.0.0:4403 and exposes an unauthenticated /execute endpoint that runs arbitrary JavaScript posted in a JSON code field. The earlier fix for the similar binding issue in #8683 covered PenpotMcpServer.ts but missed ReplServer.ts, which still calls listen(this.port) with no host argument. The reporter demonstrated file reads, command execution and environment variable dumps from another container on the same Docker network.
Fix: Add a host argument to the listen call in ReplServer.ts:89, changing it to this.app.listen(this.port, 'localhost', ...) (the source's own suggested fix), and add authentication to the /execute endpoint, with the source noting even a shared secret from an environment variable would be better than nothing.
GitHub Advisory DatabaseGHSA-fhh6-4qxv-rpqj: 9router: Unauthenticated Remote Code Execution via unprotected MCP custom plugin routes
May 19, 2026CriticalVulnerabilitySecurityCVE-2026-463399router exposes unauthenticated endpoints under /api/cli-tools/* and /api/mcp/*, which fall outside the authentication matcher in src/proxy.js. An attacker can POST a custom plugin with an arbitrary command and args to /api/cli-tools/cowork-settings, then GET /api/mcp/[plugin]/sse to trigger spawn() with that command, executing arbitrary OS commands as the user running 9router with no credentials required.
GitHub Advisory DatabaseGHSA-jwp7-wg77-3w9v: Apify Model Context Protocol (MCP) server: Domain Allowlist Bypass in fetch-apify-docs via String Prefix Matching
May 19, 2026MediumVulnerabilitySecurityCVE-2026-46341The fetch-apify-docs tool in the Apify Model Context Protocol (MCP) server checks URLs against a domain allowlist with String.startsWith() instead of comparing hostnames. An attacker can use a URL such as https://docs.apify.com.evil.com/ to pass the check and have the tool return attacker-controlled page content to the LLM. The advisory notes this enables prompt injection and can direct the LLM to use a victim's _meta.apifyToken in call-actor invocations.
GitHub Advisory DatabaseGHSA-4gph-2hhr-5mwg: Envoy AI Proxy - MCP Message Smuggling Vulnerability
May 19, 2026MediumVulnerabilitySecurityEnvoy AI Gateway's MCP proxy parses JSON-RPC 2.0 messages case-insensitively, contrary to the MCP-mandated case-sensitive matching, via `jsonrpc.DecodeMessage` in `github.com/modelcontextprotocol/go-sdk` and the `internal/json` wrapper around `github.com/bytedance/sonic`. An attacker can send a message with a case-variant `Name` field alongside `name`, and the gateway re-serializes it with the injected value, so the upstream backend receives a different tool call (e.g. `backend__secretTool` instead of `backend__greet`), potentially bypassing authorization checks applied earlier.
GitHub Advisory DatabaseGHSA-hv85-774v-26fg: auth-fetch-mcp: SSRF and disk exfiltration via unvalidated auth_fetch and download_media URLs
May 19, 2026HighVulnerabilitySecurityThe download_media and auth_fetch tools in ymw0407/auth-fetch-mcp accept arbitrary URLs and request them from the MCP server process without validating the destination. An MCP client can therefore reach loopback, link-local and private-range hosts, and download_media additionally writes the response body to a user-controlled output directory.
GitHub Advisory DatabaseGHSA-jxx9-px88-pj69: n8n-MCP: Multi-tenant MCP requests fall back to process-level n8n credentials when tenant headers are absent or incomplete
May 18, 2026HighVulnerabilitySecurityCVE-2026-45707When ENABLE_MULTI_TENANT=true, n8n-mcp's HTTP transport selects the target n8n instance from the x-n8n-url and x-n8n-key headers, but requests missing one or both headers silently fell back to the operator's process-level N8N_API_URL and N8N_API_KEY. An authenticated MCP tenant could therefore run n8n management calls against the operator's own instance, with possible escalation to remote code execution where Code-node execution reaches OS-level modules. Single-tenant deployments are not affected.
Fix: Fixed in n8n-mcp 2.51.2, which rejects header-less multi-tenant requests with HTTP 400 / JSON-RPC -32602 and refuses to construct an env-credential n8n API client when ENABLE_MULTI_TENANT=true. Upgrade with `npx n8n-mcp@latest` or `docker pull ghcr.io/czlonkowski/n8n-mcp:latest`. Workarounds: set ENABLE_MULTI_TENANT=false and run a separate instance per tenant with its own credentials; require both x-n8n-url and x-n8n-key at a proxy (partial mitigation only); or scope the operator's N8N_API_KEY to the minimum required permissions.
GitHub Advisory DatabaseGHSA-m99r-2hxc-cp3q: Flowise has an MCP Security Bypass that Enables RCE
May 14, 2026HighVulnerabilitySecurityFlowise's MCP feature contains a security bypass chain that lets an attacker run arbitrary commands on the host. The validateCommandFlags blocklist in packages/components/nodes/tools/MCP/core.ts omits docker build, so a Custom MCP Server configured as docker build <remote-URL> pulls and runs a remote Dockerfile. A second bypass uses the long alias --yes, which is not blocked for npx, letting npx install and execute an attacker-supplied npm package. The attacker needs a Flowise account of any role or an API key with view and update permissions for chatflows, and the server must have the docker or npx command available.
GitHub Advisory DatabaseCVE-2026-43992: JunoClaw MCP write tools expose BIP-39 mnemonic in LLM tool-call parameters
May 12, 2026CriticalVulnerabilitySecurityPrivacyCVE-2026-43992CVE-2026-43992 affects JunoClaw, an agentic AI platform built on Juno Network, prior to 0.x.y-security-1. Every MCP write tool, including send_tokens, execute_contract, instantiate_contract, upload_wasm and ibc_transfer, accepted 'mnemonic: string' as an explicit tool-call parameter. As a result, the BIP-39 seed was embedded in the LLM tool-call JSON and exposed to any transport, log or telemetry surface between the LLM provider and the MCP process.
Fix: This vulnerability is fixed in 0.x.y-security-1.
NVD/CVE DatabaseCVE-2026-43989: JunoClaw upload_wasm MCP tool accepts unvalidated filesystem paths
May 12, 2026HighVulnerabilitySecurityCVE-2026-43989CVE-2026-43989 affects JunoClaw, an agentic AI platform built on Juno Network, prior to 0.x.y-security-1. The upload_wasm MCP tool accepted a filesystem path from the agent and uploaded whatever bytes that path resolved to, without validating location, symlink target, file size, or file format. The flaw is classified as CWE-20, CWE-22, CWE-59 and CWE-73.
Fix: Fixed in 0.x.y-security-1.
NVD/CVE DatabaseCVE-2026-44284: FastGPT SSRF through stored internal MCP tool server URLs
May 8, 2026MediumVulnerabilitySecurityCVE-2026-44284FastGPT, an AI Agent building platform, prior to version 4.14.17, let authenticated users who can create or manage MCP toolsets save an internal MCP server URL, such as http://localhost:3000/mcp, through the MCP tool create and update endpoints. The direct MCP preview and run endpoints already rejected internal or private network URLs, so the protection was inconsistent. Later workflow execution used the stored URL without revalidating the destination, letting the FastGPT backend workflow runner connect to that internal destination.
Fix: Fixed in 4.14.17.
NVD/CVE DatabaseGHSA-8g7g-hmwm-6rv2: n8n-mcp affected by path traversal, redirect-following SSRF, and telemetry payload exposure
May 8, 2026HighVulnerabilitySecurityn8n-mcp versions before 2.50.1 contain three independently reported issues in deployments that use the n8n API integration. An authenticated MCP caller can supply crafted identifiers that the n8n API client uses as URL path segments, sending the configured n8n API key to other same-origin endpoints and bypassing handler-level controls including DISABLED_TOOLS. Validated webhook, form and chat trigger URLs also follow redirects, returning the response body to the caller, and default opt-in telemetry uploads unredacted operation payloads that can contain bearer tokens, API keys and webhook secrets. CVSS 8.3 (HIGH); exploitation requires an authenticated MCP caller and a configured n8n API key.
Fix: Upgrade to n8n-mcp >= 2.50.1. Workarounds: for the first two issues, restrict network access to the HTTP transport (firewall, reverse-proxy ACL or VPN) or switch to stdio mode; for the telemetry issue, set N8N_MCP_TELEMETRY_DISABLED=true before starting the server or run `npx n8n-mcp telemetry disable` once.
GitHub Advisory DatabaseGHSA-cmrh-wvq6-wm9r: n8n-mcp webhook and API client paths has an authenticated SSRF
May 8, 2026HighVulnerabilitySecurityIndustryCVE-2026-44694Authenticated server-side request forgery in n8n-mcp affects the webhook trigger tools, the n8n API client via N8N_API_URL, and per-request URLs supplied in the x-n8n-url header in multi-tenant HTTP mode. A caller with an MCP session can make the n8n-mcp host send requests to internal services and cloud metadata endpoints, and the response body is returned to the caller. Fixed in n8n-mcp@2.50.2.
Fix: Fixed in `n8n-mcp@2.50.2`. Operators whose N8N_API_URL points at localhost or a private address should set WEBHOOK_SECURITY_MODE to moderate (allows localhost, still blocks RFC1918 and cloud metadata) or permissive (also allows RFC1918, only safe on a trusted private network); the default strict applies where n8n is on a public hostname. Workarounds for deployments that cannot upgrade: restrict network egress from the host and deny cloud metadata IPs (169.254.169.254, 169.254.170.2, 100.100.100.200, 192.0.0.192, and the GCP metadata.google.internal resolved IP) and RFC1918 networks; run in stdio mode instead of HTTP; or set DISABLED_TOOLS=n8n_trigger_webhook_workflow,n8n_create_workflow,n8n_test_workflow.
GitHub Advisory DatabaseCVE-2026-42271: LiteLLM command execution through MCP test endpoints
May 8, 2026CriticalVulnerabilitySecurityCVE-2026-42271EPSS: 92.6%Actively ExploitedLiteLLM versions from 1.74.2 up to, but not including, 1.83.7 expose two endpoints, POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list, that accept a full MCP server configuration including the stdio transport's command, args and env fields. Any holder of a valid proxy API key, including low-privilege internal-user keys, can make these endpoints spawn an arbitrary command as a subprocess on the proxy host with the proxy process's privileges, because no role check gates them.
Fix: Fixed in 1.83.7.
NVD/CVE DatabaseGHSA-89vp-x53w-74fx: rmcp Streamable HTTP server transport has a DNS rebinding vulnerability
May 6, 2026HighVulnerabilitySecurityCVE-2026-42559Prior to version 1.4.0, the rmcp crate's Streamable HTTP server transport did not validate the incoming Host header, so a malicious public website using a DNS rebinding attack could send authenticated requests to a local or private-network MCP server. An attacker could enumerate and invoke exposed tools and read resources, and because MCP servers often run with the user's privileges, the impact can extend to arbitrary code execution on the victim's machine.
Fix: Fixed in rmcp 1.4.0 (PR #764, commit 8e22aa2): StreamableHttpServerConfig::allowed_hosts now defaults to a loopback-only allowlist, and requests whose Host header is not on the allowlist receive HTTP 403. Upgrade to rmcp >= 1.4.0. If upgrade is not possible, place the MCP server behind a reverse proxy configured to reject requests whose Host header is not an expected hostname, and do not bind the server to 0.0.0.0 without such a proxy.
GitHub Advisory DatabaseGHSA-fj4g-2p96-q6m3: Network-AI missing authentication on MCP HTTP endpoint, which allows unauthenticated privileged tool calls
May 5, 2026HighVulnerabilitySecurityCVE-2026-42856Network-AI version 5.1.2 (commit c344f2053eb0d49395988f803bf92f2a86b2a0d0) accepts JSON-RPC tools/call requests on its MCP HTTP transport with no authentication, session, origin or token check, dispatching them straight to the orchestrator's tool registry. The default bind address is 0.0.0.0, so any party with network reachability can list and invoke privileged tools such as config_get and config_set, agent_spawn, token_create and budget_set_ceiling. The advisory is rated High (CWE-306) and was validated on 2026-04-21 with a proof of concept that changed a live configuration value without credentials.
GitHub Advisory DatabaseGHSA-537j-gqpc-p7fq: n8n Vulnerable to XSS via MCP OAuth client
Apr 29, 2026HighVulnerabilitySecurityCVE-2026-42235An unauthenticated attacker can register a malicious MCP OAuth client with a crafted client_name. When a second user revokes access after a victim authorized the OAuth consent dialog, a toast notification renders the injected script. Clicking the link runs arbitrary JavaScript in the victim's authenticated n8n browser session, enabling credential and session token theft, workflow manipulation, or privilege escalation.
Fix: Fixed in n8n version 2.14.2; users should upgrade to this version or later. Until then, administrators should consider restricting access to the n8n instance and the MCP OAuth registration endpoint to trusted users only, and disabling MCP server functionality if it is not actively required. The source states these workarounds do not fully remediate the risk and are only short-term measures.
GitHub Advisory DatabaseGHSA-49m9-pgww-9vq6: n8n Vulnerable to Unauthenticated Denial of Service via MCP Client Registration
Apr 29, 2026HighVulnerabilitySecurityCVE-2026-42236The MCP OAuth client registration endpoint in n8n accepted unauthenticated requests and stored client data without adequate resource controls. A remote attacker can exhaust server memory with large registration payloads, making the instance unavailable, and the endpoint remains reachable even when MCP is disabled.
Fix: Fixed in n8n 1.123.32, 2.17.4, and 2.18.1; upgrade to one of these versions or later. If upgrading is not immediately possible, restrict network access to the n8n instance to untrusted sources and lower the N8N_PAYLOAD_SIZE_MAX environment variable from its default value. These workarounds do not fully remediate the risk and are short-term measures only.
GitHub Advisory Database
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.