Model Context Protocol
The Model Context Protocol and the servers and clients that expose tools and data to models through it.
- All items
- 295
- Last 90 days
- 133
- Change
- +53%vs 87 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 2 |
| Jun 2025 | 4 |
| Jul 2025 | 4 |
| Aug 2025 | 7 |
| Sep 2025 | 3 |
| Oct 2025 | 3 |
| Nov 2025 | 2 |
| Dec 2025 | 4 |
| Jan 2026 | 4 |
| Feb 2026 | 12 |
| Mar 2026 | 22 |
| Apr 2026 | 27 |
| May 2026 | 31 |
| Jun 2026 | 25 |
| Jul 2026 | 43 |
| Aug 2026 | 45 |
| Sep 2026 | 40 |
| Oct 2026 | 16 |
295 items
GHSA-qrx8-25qr-5r7v: n8n: MCP Browser HTTP Transport Exposes Unauthenticated Browser-Control Sessions
Jun 16, 2026HighVulnerabilitySecurityCVE-2026-54309When @n8n/mcp-browser runs in HTTP transport mode (--transport http), its MCP endpoint accepts session initialization and tool calls with no authentication. Any network-reachable client, or any website the user visits, can open an MCP session and invoke browser-control tools. Where the n8n AI Browser Bridge extension is installed and a browser connection is active, the attacker gets navigation, JavaScript evaluation, and cookie and storage access against the user's real browser profile. The default stdio transport is not affected.
Fix: The issue has been fixed in n8n versions 2.25.7 and 2.26.2; upgrade to one of these or later. Temporary workarounds: avoid HTTP transport and use the default stdio transport instead, or if HTTP is required, restrict network access to the listening port to trusted clients using host-based firewall rules. The source states these workarounds do not fully remediate the risk and are short-term measures only.
GitHub Advisory DatabaseGHSA-8q5r-mmjf-575q: Claude Code Action: Malicious MCP Server Configuration in PRs Enables Remote Code Execution and Secret Exfiltration
Jun 10, 2026MediumVulnerabilitySecurityCVE-2026-47751A flaw in claude-code-action combined checking out attacker-controlled PR head branches, reading `.mcp.json` from the working directory through default setting sources, and unconditionally enabling all project MCP servers via `enableAllProjectMcpServers`. An attacker who opens a PR containing a malicious `.mcp.json` can achieve arbitrary code execution on the GitHub Actions runner. This can expose workflow secrets such as API keys and tokens when a privileged user or automatic trigger runs the action on that PR.
Fix: Users pinned to a vulnerable version of claude-code-action are advised to update to the latest version. Users referencing anthropics/claude-code-action@v1, anthropics/claude-code-action@beta, anthropics/claude-code-action@main, or other non-pinned tags have already received the fix.
GitHub Advisory DatabaseNew Platform Uses Cryptographic Invisibility to Protect AI-Built Applications
Jun 9, 2026InfoNewsSecurityIndustryAtsign has launched AI Architect, a product that adds security to AI-assisted coding by having developers specify an app's purpose and generating precise prompts that direct coding agents to produce secure, relevant code. It is delivered as a custom MCP server called AAIA, which gives each resource a unique cryptographic identity with policies controlling its privileges. The source claims that AI-built apps are otherwise likely to contain unknown vulnerabilities.
SecurityWeekMicrosoft identifies seven new ways AI agents can be hacked
Jun 5, 2026InfoNewsSecurityResearchMicrosoft has identified seven new failure modes in agentic AI systems, extending the first Taxonomy of Failure Modes in Agentic AI Systems it published last year. The new modes include Goal Hijacking, Inter-Agent Trust Escalation, Computer Use Agent (CUA) Visual Attack, and MCP / Plugin Abuse. Microsoft attributes the expanding list to rapid mainstream adoption, the maturing Model Context Protocol (MCP) ecosystem, the rise of computer-use agents, and more empirical findings from real-world research.
Fix: Microsoft advises security teams to inventory their supply chain and generate a software bill of materials (SBOM) for every deployed agent. It also recommends verifying agent identity cryptographically rather than positionally, by issuing attestable credentials at provisioning. Teams should add the seven new failure modes to their red-team coverage matrix and audit the human-in-the-loop user experience as a security control.
CSO OnlineGHSA-6mx4-4h42-r8vh: MCP Server Kubernetes: kubectl-generic flag injection enables Kubernetes bearer token exfiltration
Jun 5, 2026MediumVulnerabilitySecurityCVE-2026-47250The kubectl_generic tool in mcp-server-kubernetes passes user-supplied flags and args straight to kubectl with no allowlist. An attacker with limited access can plant a JSON log line that an AI agent follows, causing kubectl to send the operator's Authorization: Bearer token to an attacker endpoint via --server and --insecure-skip-tls-verify=true. The captured token can then be replayed against the real Kubernetes API server, granting the operator's service account RBAC permissions.
GitHub Advisory DatabaseClaude Code has an MCP security problem — and your developers are already using it
Jun 5, 2026MediumNewsSecurityIndustryResearchers at Mitiga Labs published an attack chain in which a malicious npm package's post-install hook rewrites ~/.claude.json, redirecting Claude Code's MCP traffic to attacker-controlled infrastructure and intercepting the OAuth bearer tokens stored there in plaintext. Mitiga reported the issue to Anthropic on April 10, and Anthropic replied on April 12 that it was out of scope; the article states no patch exists as of writing. It also recalls two earlier Claude Code flaws, CVE-2025-59536 and CVE-2026-21852, disclosed by Check Point Research in February 2026 and patched by Anthropic.
CSO OnlineCVE-2026-44653: LibreChat exposes decrypted MCP server secrets to users with view access
Jun 2, 2026MediumVulnerabilitySecurityCVE-2026-44653In LibreChat versions up to and including 0.8.3, users with only VIEW access to an MCP server can retrieve the server's decrypted admin-managed secrets through GET /api/mcp/servers and GET /api/mcp/servers/:serverName. The returned config includes plaintext apiKey.key and oauth.client_secret values, letting viewers of a shared MCP server exfiltrate the underlying provider credentials.
Fix: Version 0.8..4 contains a patch. Other remediations include: never returning decrypted admin-managed secrets to non-owners; redacting apiKey.key and oauth.client_secret from all API responses, considering returning only boolean presence indicators for secrets, similar to the auth-values route pattern; and, if owners need to edit configs without re-entering secrets, preserving secrets server-side and returning placeholders instead of plaintext.
NVD/CVE DatabaseCVE-2026-32625: LibreChat MCP server integration leaks secrets via user-supplied URLs
Jun 2, 2026CriticalVulnerabilitySecurityIndustryCVE-2026-32625LibreChat versions up to and including 0.8.3 resolve ${VAR} placeholders against the server's process.env during Zod schema validation of user-supplied MCP server URLs. An authenticated user can submit an MCP server configuration pointing to an attacker-controlled domain, causing the server to transmit secrets such as CREDS_KEY, CREDS_IV, JWT_SECRET and MONGO_URI in the request URL, without administrative privileges.
Fix: Fixed in 0.8.4-rc1.
NVD/CVE DatabaseFlowise’s MCP implementation can run ghost commands
Jun 1, 2026MediumNewsSecurityResearchers at Obsidian Security disclosed CVE-2026-40933, a one-click remote code execution flaw in self-hosted Flowise deployments through its implementation of MCP stdio servers. Flowise lets users configure stdio servers with arbitrary commands, which the operating system then runs with the Flowise process's privileges, and a malicious chatflow import can trigger this before any save or run. The flaw is rated 9.9 CVSS, and Flowise Cloud is not affected because stdio MCP is disabled there.
Fix: The only complete mitigation recommended by the researchers is turning off MCP stdio by setting "CUSTOM_MCP_PROTOCOL=sse". For those who cannot do so without obstructing operations, pinning trusted packages where possible and reviewing imported chatflows from untrusted sources might help.
CSO OnlineGHSA-9cr9-25q5-8prj: PraisonAI vulnerable to unauthenticated arbitrary file read via MCP workflow.show, workflow.validate, deploy.validate
May 29, 2026HighVulnerabilitySecurityCVE-2026-47394The fix for GHSA-9mqq-jqxf-grvw / CVE-2026-44336 is incomplete. Commit 68cc9427 added _resolve_rule_path() to rules.create, rules.show and rules.delete in mcp_server/adapters/cli_tools.py, but praisonai.workflow.show, praisonai.workflow.validate and praisonai.deploy.validate remain unchanged. A single unauthenticated MCP tools/call to praisonai.workflow.show can return any file the host user can read, and the dispatcher in server.py, which passes unvalidated arguments as **kwargs, is also unchanged.
GitHub Advisory DatabaseChatGPhish Vulnerability Turns ChatGPT Web Summaries Into a Phishing Surface
May 29, 2026MediumNewsSecuritySafetyPermiso Security disclosed ChatGPhish, a technique in which a web page that a user asks ChatGPT to summarize can cause the chatgpt.com response renderer to display attacker-controlled Markdown links, image URLs, fake security alerts and QR codes as live elements in the assistant's UI. The renderer auto-fetches attacker-hosted images, which can leak the victim's IP, User-Agent and Referer. Separately, Adversa AI documented SymJack and TrustFall, which target AI coding agents and can lead to code execution through malicious repositories and MCP servers.
The Hacker NewsDNS-AID will make AI agents easier to discover, says Linux Foundation
May 29, 2026InfoNewsIndustrySecurityThe Linux Foundation is inviting contributions to DNS-AID, a proposed standard that lets AI agents and MCP servers discover, verify and communicate with one another using existing DNS infrastructure. The proposal suggests domain owners publish a well-known address, _index._agents.{domain}, as a starting point for agent discovery. DNS-AID was initially developed at Infoblox, with contributions from Deutsche Telekom and Amazon in the latest internet draft.
CSO OnlineFastAPI-based AI tools exposed to authentication bypass by flaw in Starlette framework
May 27, 2026MediumNewsSecurityIndustryA single malformed character in the Host header lets an unauthenticated attacker bypass host-validation protections in Starlette, the Python framework underlying FastAPI, tracked as CVE-2026-48710. Starlette rebuilds the request URL by joining the Host header to the path, and a slash, question mark or hash in the Host header shifts where the path begins, so middleware reads a different path than the one routed. Researchers at X41 D-Sec rated the flaw 7.0 (High), while Starlette's maintainer rated it 6.5 (Moderate), and they said downstream applications built on FastAPI, including AI model-serving tools, gateways and MCP servers, can be affected.
Fix: Starlette's maintainer released a patch through an official GitHub security advisory. The source does not specify a fixed version number.
CSO Online‘SymJack’ Attack Turns AI Coding Agents Into Supply Chain Attack Delivery Systems
May 27, 2026MediumNewsSecurityIndustryAdversa AI describes SymJack, an attack that uses a malicious repository to turn AI coding agents into delivery mechanisms for supply chain attacks. A malicious symlink, renamed to look innocuous, is used with a cp command to plant a payload in the agent's configuration, registering a malicious MCP server whose startup command runs attacker code as the user on the next restart. Adversa reports the method worked in all five coding agents it tested, including Claude Code, Gemini CLI, Cursor Agent CLI, Grok Build CLI and GitHub's Copilot CLI.
Fix: Anthropic quietly hardened Claude Code, which now resolves symlinks before asking for approval and shows the real destination path in the prompt. The article calls this a good start and suggests other coding agents could implement similar prompts.
SecurityWeekCVE-2026-44895: GitLab MCP Server HTTP transport accepts unauthenticated requests
May 26, 2026CriticalVulnerabilitySecurityCVE-2026-44895CVE-2026-44895 affects the GitLab MCP Server before 0.6.0. Its HTTP transport in src/transport.ts has no authentication and sends a wildcard Access-Control-Allow-Origin: * header, while exposing a mutation-capable RPC endpoint backed by GITLAB_PERSONAL_ACCESS_TOKEN. Because httpServer.listen(port) at line 97 passes no host, the server binds to 0.0.0.0 and exposes this surface on every interface.
Fix: Fixed in 0.6.0.
NVD/CVE DatabaseGHSA-j3vx-cx2r-pvg8: Network-AI: Unauthenticated Cross-Origin MCP Tool Invocation via Empty Default Secret
May 21, 2026HighVulnerabilitySecurityCVE-2026-46701Network-AI v5.4.4 defaults the MCP SSE server secret to an empty string (`process.env['NETWORK_AI_MCP_SECRET'] ?? ''` in `bin/mcp-server.ts`), so `_isAuthorized` in `lib/mcp-transport-sse.ts` returns true for every request with no Authorization header. The server also sends `Access-Control-Allow-Origin: *` on every response, letting a cross-origin browser script read results. An attacker who lures a user to a malicious web page can invoke all 22 exposed MCP tools, including `config_set`, `agent_spawn` and `blackboard_write`, against a default-configured localhost server.
GitHub Advisory DatabaseGHSA-cr22-wjx7-2w6m: MCP Server Kubernetes: Tool Access Control Bypass via Presentation-Layer Filtering Without Execution-Layer Enforcement
May 21, 2026HighVulnerabilitySecurityCVE-2026-46519The mcp-server-kubernetes package exposes ALLOW_ONLY_READONLY_TOOLS, ALLOW_ONLY_NON_DESTRUCTIVE_TOOLS and ALLOWED_TOOLS as access controls, but they are enforced only at tools/list and not at tools/call. Any client that knows a tool name can invoke it directly, so kubectl_delete, exec_in_pod, kubectl_generic and node_management run regardless of the configured restriction, which the advisory says is equivalent to full cluster compromise when the service account has cluster-admin.
Fix: Fixed in v3.6.0. The fix applies the same filtering logic from ListToolsRequestSchema at the start of the CallToolRequestSchema handler, returning an error for any tool call outside the active allowed set.
GitHub Advisory Database1Password Teams With OpenAI to Stop AI Coding Agents From Leaking Credentials
May 20, 2026InfoNewsSecurityIndustry1Password has partnered with OpenAI to give Codex access to credentials during development without exposing them in prompts, code, repositories, terminals or the model's context window. The integration uses an Environments MCP Server for Codex, which issues just-in-time, task-scoped credentials and injects them into the application process at runtime.
Fix: 1Password has introduced an Environments MCP Server for Codex that keeps secrets out of prompts, code and model context, with user authentication required at the moment of access.
SecurityWeekGHSA-22qr-rp27-j9wm: PenPot MCP REPL server binds to 0.0.0.0 with unauthenticated /execute endpoint — RCE
May 19, 2026HighVulnerabilitySecurityCVE-2026-45805The PenPot MCP module's ReplServer binds to 0.0.0.0:4403 and exposes an unauthenticated /execute endpoint that runs arbitrary JavaScript posted in a JSON code field. The earlier fix for the similar binding issue in #8683 covered PenpotMcpServer.ts but missed ReplServer.ts, which still calls listen(this.port) with no host argument. The reporter demonstrated file reads, command execution and environment variable dumps from another container on the same Docker network.
Fix: Add a host argument to the listen call in ReplServer.ts:89, changing it to this.app.listen(this.port, 'localhost', ...) (the source's own suggested fix), and add authentication to the /execute endpoint, with the source noting even a shared secret from an environment variable would be better than nothing.
GitHub Advisory DatabaseGHSA-fhh6-4qxv-rpqj: 9router: Unauthenticated Remote Code Execution via unprotected MCP custom plugin routes
May 19, 2026CriticalVulnerabilitySecurityCVE-2026-463399router exposes unauthenticated endpoints under /api/cli-tools/* and /api/mcp/*, which fall outside the authentication matcher in src/proxy.js. An attacker can POST a custom plugin with an arbitrary command and args to /api/cli-tools/cowork-settings, then GET /api/mcp/[plugin]/sse to trigger spawn() with that command, executing arbitrary OS commands as the user running 9router with no credentials required.
GitHub Advisory Database
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.