Model Context Protocol
The Model Context Protocol and the servers and clients that expose tools and data to models through it.
- All items
- 295
- Last 90 days
- 133
- Change
- +53%vs 87 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 2 |
| Jun 2025 | 4 |
| Jul 2025 | 4 |
| Aug 2025 | 7 |
| Sep 2025 | 3 |
| Oct 2025 | 3 |
| Nov 2025 | 2 |
| Dec 2025 | 4 |
| Jan 2026 | 4 |
| Feb 2026 | 12 |
| Mar 2026 | 22 |
| Apr 2026 | 27 |
| May 2026 | 31 |
| Jun 2026 | 25 |
| Jul 2026 | 43 |
| Aug 2026 | 45 |
| Sep 2026 | 40 |
| Oct 2026 | 16 |
198 items
GHSA-f6x8-65q6-j9m9: n8n has Open Redirect in MCP OAuth Consent Flow
Apr 29, 2026MediumVulnerabilitySecurityCVE-2026-42230n8n's `/mcp-oauth/register` endpoint accepts OAuth client registrations without authentication, so arbitrary `redirect_uri` values can be registered. When a user clicks Deny on the MCP OAuth consent dialog, the `handleDeny` handler redirects them to that registered URI without validation, creating an open redirect. An attacker can send a phishing link that silently sends a victim to an external site after they deny consent.
Fix: Fixed in n8n 1.123.32, 2.17.4, and 2.18.1. Upgrade to one of these versions or later. If upgrading is not immediately possible, restrict network access to the n8n instance so untrusted users cannot reach the MCP OAuth endpoints, and limit access to fully trusted users only. The source states these workarounds do not fully remediate the risk and are short-term measures only.
GitHub Advisory DatabaseGHSA-wg4g-395p-mqv3: n8n-MCP: Sensitive MCP tool-call arguments logged on authenticated requests in HTTP mode
Apr 25, 2026MediumVulnerabilitySecurityPrivacyIn HTTP transport mode, n8n-mcp versions v2.47.12 and earlier wrote full MCP tools/call arguments and JSON-RPC params to server logs for authenticated requests, before redaction. When a call carried credentials, such as through n8n_manage_credentials.data, the raw values could be persisted in logs, exposing bearer tokens, OAuth credentials, API keys and webhook auth headers to anyone with access to collected or forwarded logs. The issue requires a valid AUTH_TOKEN, and the stdio transport is not affected in practice.
Fix: Fixed in v2.47.13 (npm: npx n8n-mcp@latest or >= 2.47.13; Docker: ghcr.io/czlonkowski/n8n-mcp:latest). Interim workarounds: restrict access to the HTTP port, restrict access to server logs, or switch to stdio transport (MCP_MODE=stdio).
GitHub Advisory DatabaseGHSA-v4p8-mg3p-g94g: LiteLLM: Authenticated command execution via MCP stdio test endpoints
Apr 25, 2026HighVulnerabilitySecurityLiteLLM's two MCP preview endpoints, POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list, accepted full server configurations including command, args and env for the stdio transport. Calling them with a stdio configuration spawned the supplied command as a subprocess on the proxy host with the proxy process's privileges. Because the endpoints checked only for a valid proxy API key and no role, any authenticated user, including low-privilege internal-user keys, could run arbitrary commands on the host.
Fix: Fixed in 1.83.7. Both test endpoints now require the PROXY_ADMIN role. If upgrading is not immediately possible, block POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list at the reverse proxy or API gateway.
GitHub Advisory DatabaseGHSA-pfm2-2mhg-8wpx: n8n-MCP Logs Sensitive Request Data on Unauthorized /mcp Requests
Apr 23, 2026MediumVulnerabilitySecurityCVE-2026-41495Versions 2.47.10 and earlier of n8n-mcp, when run in HTTP transport mode, wrote request metadata for incoming POST /mcp requests to server logs even when authentication failed. Sensitive values from those rejected requests, including bearer tokens from the Authorization header, per-tenant x-n8n-key API keys, and JSON-RPC payloads, could therefore be persisted and exposed to anyone with access to collected logs. Access control itself was not bypassed, since unauthenticated requests received 401 Unauthorized, and the stdio transport is not affected.
Fix: Fixed in v2.47.11 (npm: npx n8n-mcp@latest or >= 2.47.11; Docker: ghcr.io/czlonkowski/n8n-mcp:latest). Workarounds: restrict network access to the HTTP port with a firewall, reverse proxy, or VPN, or switch to stdio transport (MCP_MODE=stdio).
GitHub Advisory DatabaseCVE-2026-40933: Flowise command execution through Custom MCP stdio server configuration
Apr 21, 2026CriticalVulnerabilitySecurityCVE-2026-40933Flowise versions prior to 3.1.0 contain a flaw in the MCP adapter's serialization of stdio commands. An authenticated user can add an MCP stdio server through the "Custom MCP" configuration with an arbitrary command, bypassing validateCommandInjection and validateArgsForLocalFileAccess by pairing an allowed command such as "npx" with code execution arguments like "-c touch /tmp/pwn", which achieves command execution on the underlying OS.
Fix: Fixed in 3.1.0.
NVD/CVE DatabaseGHSA-cvrr-qhgw-2mm6: Flowise: Parameter Override Bypass Remote Command Execution
Apr 16, 2026HighVulnerabilitySecurityFlowise is vulnerable to unauthenticated remote command execution through a parameter override bypass. The FILE-STORAGE:: check in replaceInputsWithConfig in packages/server/src/utils/index.ts uses .includes() rather than .startsWith(), so an attacker can embed the keyword in a string and skip the isParameterEnabled() check. This lets the attacker set NODE_OPTIONS through the Custom MCP node, which does not block it, and run arbitrary code with root privileges in the container. The attack requires a single HTTP request, plus API Override enabled and a public chatflow containing an MCP tool node.
GitHub Advisory DatabaseCVE-2026-30617: LangChain-ChatChat remote code execution through MCP STDIO server configuration
Apr 15, 2026CriticalVulnerabilitySecurityCVE-2026-30617LangChain-ChatChat 0.3.1 contains a remote code execution flaw in its MCP STDIO server configuration and execution handling. A remote attacker who can reach the publicly exposed MCP management interface can configure an MCP STDIO server with attacker-controlled commands and arguments, and once the server starts with MCP enabled for agent execution, arbitrary commands run within the context of the LangChain-ChatChat service.
NVD/CVE DatabaseCVE-2026-30615: Windsurf prompt injection allows arbitrary command execution via HTML content
Apr 15, 2026CriticalVulnerabilitySecurityCVE-2026-30615A prompt injection flaw in Windsurf 1.9544.26 lets remote attackers run arbitrary commands on a victim system. When Windsurf processes attacker-controlled HTML, injected instructions can modify the local MCP configuration and automatically register a malicious MCP STDIO server, with no further user interaction. Successful exploitation can execute commands as the user, persist the malicious configuration, and expose sensitive information accessible through the application.
NVD/CVE DatabaseCVE-2026-39884: mcp-server-kubernetes argument injection in port_forward tool
Apr 15, 2026HighVulnerabilitySecurityCVE-2026-39884mcp-server-kubernetes, a Model Context Protocol server for Kubernetes cluster management, versions 3.4.0 and prior, contains an argument injection flaw (CVE-2026-39884) in the port_forward tool in src/tools/port_forward.ts. The tool builds a kubectl command by string concatenation and splits it on spaces before calling spawn(), so spaces in namespace, resourceType, resourceName, localPort and targetPort become argument boundaries. An attacker can inject arbitrary kubectl flags, such as --address=0.0.0.0 to expose internal Kubernetes services to the network or additional -n flags to target other namespaces, including through prompt injection against connected AI agents.
Fix: Fixed in 3.5.0.
NVD/CVE DatabaseCVE-2025-61260: OpenAI Codex CLI code execution through malicious MCP configuration files
Apr 14, 2026HighVulnerabilitySecurityCVE-2025-61260CVE-2025-61260 affects OpenAI Codex CLI v0.23.0 and earlier. A malicious or compromised repository can trigger code execution when a user runs the codex command inside it, because Codex automatically loads project-local .env and .codex/config.toml files, including malicious MCP (Model Context Protocol) configuration, without user confirmation. Attackers can embed arbitrary commands that execute immediately.
NVD/CVE DatabaseGHSA-8jxr-pr72-r468: Java-SDK has a DNS Rebinding Vulnerability
Apr 7, 2026HighVulnerabilitySecurityCVE-2026-35568The java-sdk MCP server contained a DNS rebinding vulnerability because it performed no Origin header validation before version 1.0.0, contrary to the MCP specification. An attacker can use a malicious website opened in a victim's browser to make arbitrary tool calls to a locally or privately networked MCP server, acting as a locally connected AI agent. Servers built on frameworks with built-in Origin validation, such as Spring AI, are not affected.
Fix: Fixed in 1.0.0 (Origin validation was absent prior to that release). Workarounds: run the MCP server behind a reverse proxy such as Nginx or HAProxy configured to strictly validate the Host and Origin headers, or use a framework that enforces strict CORS and Origin validation, such as Spring AI.
GitHub Advisory DatabaseGHSA-5qhv-x9j4-c3vm: @mobilenext/mobile-mcp: Arbitrary Android Intent Execution via mobile_open_url
Apr 4, 2026HighVulnerabilitySecurityCVE-2026-35394The mobile_open_url tool in @mobilenext/mobile-mcp passes user-supplied URLs straight to Android's intent system through adb shell am start without scheme validation. Because MCP servers are driven by AI agents that can be manipulated through prompt injection, a malicious document or website could make the agent open tel:, sms:, mailto:, content:// or market:// URLs, enabling USSD codes, calls, SMS drafts, content provider access and app installation prompts.
Fix: Upgrade to version 0.0.50 or later, which restricts mobile_open_url to http:// and https:// schemes by default. Users who need other URL schemes can opt in by setting MOBILEMCP_ALLOW_UNSAFE_URLS=1.
GitHub Advisory DatabaseCVE-2025-64340: FastMCP command injection through server names in install commands on Windows
Apr 3, 2026MediumVulnerabilitySecurityCVE-2025-64340CVE-2025-64340 affects FastMCP, a framework for building MCP applications, before version 3.2.0. On Windows, server names containing shell metacharacters such as & can trigger command injection when passed to fastmcp install claude-code or fastmcp install gemini-cli. The install paths call subprocess.run() with a list argument, but target CLIs that resolve to .cmd wrappers run through cmd.exe, which interprets the metacharacters in the flattened command string.
Fix: Fixed in 3.2.0.
NVD/CVE DatabaseGHSA-xw59-hvm2-8pj6: DNS Rebinding Protection Disabled by Default in Model Context Protocol Go SDK for Servers Running on Localhost
Apr 1, 2026HighVulnerabilitySecurityCVE-2026-34742The Model Context Protocol (MCP) Go SDK does not enable DNS rebinding protection by default for HTTP-based servers. A malicious website could use DNS rebinding to bypass same-origin restrictions and send requests to an HTTP-based MCP server running on localhost without authentication, using `StreamableHTTPHandler` or `SSEHandler`. This could let an attacker invoke tools or access resources on the user's behalf, and servers using stdio transport are not affected.
Fix: Fixed in 1.4.0: servers created via `StreamableHTTPHandler` or `SSEHandler` now have DNS rebinding protection enabled by default when binding to `localhost`. Users are advised to update to version 1.4.0.
GitHub Advisory DatabaseGHSA-vv7q-7jx5-f767: FastMCP OpenAPI Provider has an SSRF & Path Traversal Vulnerability
Mar 31, 2026CriticalVulnerabilitySecurityCVE-2026-32871GHSA-vv7q-7jx5-f767 affects the OpenAPIProvider in FastMCP, which parses OpenAPI specifications to expose internal APIs to MCP clients. The _build_url() method in fastmcp/utilities/openapi/director.py substitutes path parameter values into URL templates without URL-encoding, and urljoin() then resolves ../ sequences, letting an attacker reach arbitrary backend endpoints. Because requests carry the MCP provider's configured authorization headers, the flaw results in authenticated SSRF.
GitHub Advisory DatabaseGHSA-rww4-4w9c-7733: FastMCP: Missing Consent Verification in OAuth Proxy Callback Facilitates Confused Deputy Vulnerabilities
Mar 31, 2026HighVulnerabilitySecurityCVE-2026-27124The FastMCP OAuthProxy does not verify user consent when it receives an authorization code from the identity provider, in its _handle_idp_callback function. Because GitHub skips the consent page for previously authorized clients, an attacker can capture a GitHub authorization URL after consenting and lure a logged-in victim to open it. The victim's browser then redirects to the malicious client's callback with a valid authorization code, which the attacker can exchange for an access token to the benign MCP server tied to the victim's GitHub account. The issue was verified only for GitHubProvider, but the flaw affects any OAuth integration whose identity provider skips consent.
GitHub Advisory DatabaseCVE-2026-34163: FastGPT MCP tools endpoints server-side request forgery via user-supplied URL
Mar 31, 2026HighVulnerabilitySecurityCVE-2026-34163FastGPT, an AI Agent building platform, has an SSRF flaw in its MCP tools endpoints, /api/core/app/mcpTools/getTools and /api/core/app/mcpTools/runTool, before version 4.14.9.5. These endpoints accept a user-supplied URL and send server-side HTTP requests to it without checking for internal or private network addresses. The application's isInternalAddress() function exists but these endpoints do not call it. An authenticated attacker can scan internal networks, reach cloud metadata services, and interact with internal services such as MongoDB and Redis.
Fix: Fixed in 4.14.9.5.
NVD/CVE DatabaseCVE-2026-31951: LibreChat OAuth token exfiltration through user-created MCP server headers
Mar 27, 2026MediumVulnerabilitySecurityCVE-2026-31951CVE-2026-31951 affects LibreChat versions 0.8.2-rc1 through 0.8.3-rc1. User-created MCP (Model Context Protocol) servers can set arbitrary HTTP headers that undergo credential placeholder substitution, so a malicious server using `{{LIBRECHAT_OPENID_ACCESS_TOKEN}}` in its headers can exfiltrate the OAuth tokens of users who call tools on that server. The weakness is classified as CWE-200, Exposure of Sensitive Information to an Unauthorized Actor.
Fix: Fixed in 0.8.3-rc2.
NVD/CVE DatabaseGHSA-vphc-468g-8rfp: Azure Data Explorer MCP Server: KQL Injection in multiple tools allows MCP client to execute arbitrary Kusto queries
Mar 27, 2026HighVulnerabilitySecurityCVE-2026-33980adx-mcp-server, at latest and commit 48b2933, contains KQL injection in three MCP tool handlers: get_table_schema, sample_table_data and get_table_details. The table_name parameter is interpolated into KQL via f-strings with no validation, so a caller or a prompt-injected agent can run arbitrary KQL against the Azure Data Explorer cluster, including reading other tables and issuing management commands such as .drop table. The flaw bypasses client trust boundaries because these tools are presented as safe metadata tools.
GitHub Advisory DatabaseGHSA-647h-p824-99w7: @grackle-ai/mcp has a workspace authorization bypass in its knowledge_search MCP tool
Mar 25, 2026HighVulnerabilitySecurityThe knowledge_search and knowledge_get_node MCP tools in @grackle-ai/mcp are listed in SCOPED_TOOLS, so scoped agents can call them, but their handlers do not receive authContext or enforce workspace scoping. A scoped agent in Workspace A can pass an arbitrary workspaceId to read knowledge graph data from Workspace B, bypassing workspace isolation (CWE-284).
Fix: Fix: Add an authContext parameter to the knowledge_search and knowledge_get_node handlers and enforce workspace scoping, matching knowledge_create_node, using resolvedWorkspaceId = authContext?.type === "scoped" ? authContext.workspaceId ?? "" : workspaceId ?? "". Workarounds: do not use scoped agent tokens in multi-workspace deployments until patched, or remove knowledge_search and knowledge_get_node from the SCOPED_TOOLS set in tool-scoping.ts.
GitHub Advisory Database
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.