Model Context Protocol
The Model Context Protocol and the servers and clients that expose tools and data to models through it.
- All items
- 295
- Last 90 days
- 133
- Change
- +55%vs 86 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 2 |
| Jun 2025 | 4 |
| Jul 2025 | 4 |
| Aug 2025 | 7 |
| Sep 2025 | 3 |
| Oct 2025 | 3 |
| Nov 2025 | 2 |
| Dec 2025 | 4 |
| Jan 2026 | 4 |
| Feb 2026 | 12 |
| Mar 2026 | 22 |
| Apr 2026 | 27 |
| May 2026 | 31 |
| Jun 2026 | 25 |
| Jul 2026 | 43 |
| Aug 2026 | 45 |
| Sep 2026 | 40 |
| Oct 2026 | 16 |
198 items
GHSA-89xv-2j6f-qhc8: Cross-Site Tool Execution for HTTP Servers without Authorizatrion in github.com/modelcontextprotocol/go-sdk
Mar 19, 2026HighVulnerabilitySecurityCVE-2026-33252The Go SDK for MCP (github.com/modelcontextprotocol/go-sdk) had a flaw in its Streamable HTTP transport. It accepted browser-generated cross-site POST requests without validating the Origin header or requiring Content-Type: application/json. Without Authorization configured, especially in stateless or sessionless setups, any website could send MCP requests to a local server and potentially trigger tool execution. Cross-site POSTs with Content-Type: text/plain could reach message handling without a CORS preflight barrier.
Fix: Fixed in v1.4.1, which adds Content-Type header validation for POST requests and a configurable origin verification protection (commit a433a83). Note: v1.4.1 requires Go 1.25 or later.
GitHub Advisory DatabaseGHSA-q382-vc8q-7jhj: Improper handling of null Unicode character when parsing JSON in github.com/modelcontextprotocol/go-sdk
Mar 19, 2026HighVulnerabilitySecurityThe Go SDK for the Model Context Protocol moved to the segmentio/encoding library for JSON parsing in version 1.3.1. The new parser matched keys that had null Unicode characters appended to their base names, so combined with duplicate keys, a "last key wins" resolution could override the intended MCP message. This could let messages evade proxies or policy layers that match exact field names, and other MCP SDKs in TypeScript and Python would reject the same messages.
Fix: The segmentio/encoding package was patched and released as v0.5.4, and the SDK switched to the patched dependency in 724dd47aa. Users are advised to update to v1.4.1.
GitHub Advisory DatabaseGHSA-3xm7-qw7j-qc8v: SSRF in @aborruso/ckan-mcp-server via base_url allows access to internal networks
Mar 18, 2026MediumVulnerabilitySecurityCVE-2026-33060The @aborruso/ckan-mcp-server MCP server accepts a base_url parameter in tools such as ckan_package_search and sparql_query and sends HTTP requests to it without restriction. Exploitation needs prompt injection through malicious content while the assistant has this server connected, and a proof of concept sent 9 requests to a canary endpoint. An attacker could scan internal networks, steal cloud metadata credentials via 169.254.169.254, and attempt SQL or SPARQL injection.
Fix: Recommended fix: 1. Validate base_url against a configurable allowlist of permitted CKAN portals. 2. Block private IP ranges (RFC 1918, link-local). 3. Block cloud metadata endpoints (169.254.169.254). 4. Sanitize SQL input for datastore queries. 5. Apply a SPARQL endpoint allowlist.
GitHub Advisory DatabaseGHSA-2cpp-j2fc-qhp7: AWS API MCP File Access Restriction Bypass
Mar 17, 2026MediumVulnerabilitySecurityCVE-2026-4270The AWS API MCP Server, an open source Model Context Protocol server that lets AI assistants run AWS CLI commands, contains an Improper Protection of Alternate Path flaw in its no-access and workdir file access features. Versions >= 0.2.14 and < 1.3.9, on all platforms, can bypass the intended file restriction and expose arbitrary local file contents in the MCP client application context.
Fix: Upgrade to version 1.3.9.
GitHub Advisory DatabaseCVE-2026-4270 - AWS API MCP File Access Restriction Bypass
Mar 16, 2026HighVulnerabilitySecurityCVE-2026-4270 is an Improper Protection of Alternate Path flaw in the no-access and workdir file access features of the AWS API MCP Server, affecting awslabs.aws-api-mcp-server versions >= 0.2.14 and < 1.3.9 on all platforms. The flaw may allow an attacker to bypass the intended file access restriction and expose arbitrary local file contents in the MCP client application context.
AWS Security BulletinsGHSA-5h2m-4q8j-pqpj: FastMCP OAuth Proxy token reuse across MCP servers
Mar 16, 2026HighVulnerabilitySecurityCVE-2025-69196The FastMCP OAuth Proxy ignores the client-supplied `resource` parameter in authorization and token requests and issues tokens for the `base_url` set at initialization instead. Because the tokens carry no resource information, a benign MCP server cannot verify that a token was issued for it. An attacker can run a malicious MCP server that advertises the benign proxy as its authorization server, capture the token from a victim's OAuth flow, and replay it against other MCP servers that share that authorization server.
Fix: To mitigate this vulnerability, it is recommended to issue tokens specifically for the MCP server submitted in the authorization URL's `resource` GET parameter. In this way, the receiving MCP server will be able to properly verify that the token was indeed issued for it, allowing it to reject tokens stolen by an attack like the one demonstrated above.
GitHub Advisory DatabaseCVE-2026-31944: LibreChat MCP OAuth callback stores tokens for the wrong user
Mar 13, 2026HighVulnerabilitySecurityCVE-2026-31944LibreChat versions 0.8.2 through 0.8.2-rc3 have a flaw in the MCP (Model Context Protocol) OAuth callback endpoint. It stores OAuth tokens for the user who started the flow without checking that the browser completing the redirect is logged in or belongs to that same user. An attacker can send a victim the authorization URL, and the victim's tokens for linked services such as Atlassian and Outlook end up on the attacker's account, enabling account takeover.
Fix: Fixed in 0.8.3-rc1.
NVD/CVE DatabaseGHSA-xjgw-4wvw-rgm4: MCP Atlassian has an arbitrary file write leading to arbitrary code execution via unconstrained download_path in confluence_download_attachment
Mar 10, 2026CriticalVulnerabilitySecurityCVE-2026-27825GHSA-xjgw-4wvw-rgm4 affects MCP Atlassian. The confluence_download_attachment tool accepts a download_path parameter that is written to without any directory boundary enforcement, so an attacker who controls an attachment's content can write it to any path the server process can write, such as /etc/cron.d/, leading to arbitrary code execution. The MCP HTTP transport carries no authentication by default and binds to 0.0.0.0, so the issue is reachable from the local network.
GitHub Advisory DatabaseGHSA-7r34-79r5-rcc9: MCP Atlassian has SSRF via unvalidated X-Atlassian-Jira-Url / X-Atlassian-Confluence-Url headers
Mar 10, 2026HighVulnerabilitySecurityCVE-2026-27826mcp-atlassian's HTTP middleware and dependency layer accept an unvalidated X-Atlassian-Jira-Url (and the Confluence equivalent) from unauthenticated requests when no Authorization header is present. The server then issues an outbound GET to {header_url}/rest/api/2/myself, enabling server-side request forgery, which the advisory says can expose IAM credentials via 169.254.169.254 in cloud deployments and enable internal network reconnaissance and injection of attacker-controlled content into LLM tool results.
GitHub Advisory DatabaseGHSA-67q9-58vj-32qx: WeKnora Vulnerable to Tool Execution Hijacking via Ambigous Naming Convention In MCP client and Indirect Prompt Injection
Mar 6, 2026MediumVulnerabilitySecurityCVE-2026-30856WeKnora's MCP client builds internal tool names as `mcp_{service}_{tool}` after sanitizing each part, and its registry (`internal/agent/tools/registry.go`) silently overwrites existing entries. A malicious remote MCP server can register a tool such as `tavily_extract` that replaces the legitimate one, and the client also feeds MCP tool descriptions and results into the LLM context without sanitization. The source states that this lets an attacker redirect LLM execution, exfiltrate system prompts and context, and potentially run other tools with the user's privileges, with a precondition that the user registers the malicious service before the legitimate one.
GitHub Advisory DatabaseCVE-2026-29791: Agentgateway input validation flaw in MCP tools/call to OpenAPI conversion
Mar 6, 2026MediumVulnerabilitySecurityCVE-2026-29791CVE-2026-29791 affects Agentgateway, an open source data plane for agentic AI connectivity, prior to version 0.12.0. When converting an MCP tools/call request to an OpenAPI request, input path, query, and header values are not sanitized, which is classified as CWE-20 Improper Input Validation. The NVD assessment has not yet been provided.
Fix: This issue has been patched in version 0.12.0.
NVD/CVE DatabaseGHSA-g8r9-g2v8-jv6f: GitHub Copilot CLI Dangerous Shell Expansion Patterns Enable Arbitrary Code Execution
Mar 6, 2026HighVulnerabilitySecurityCVE-2026-29783GitHub Copilot CLI's shell tool contains a vulnerability in which crafted bash parameter expansion patterns (such as ${var@P}, assignment forms like ${var=value}, indirect ${!var}, and nested $(cmd) inside ${...}) can hide command execution inside commands the safety assessment classifies as read-only. An attacker who can influence the commands the agent runs, for example through prompt injection in repository files, MCP server responses, or user instructions, could achieve arbitrary code execution on the user's workstation, even in modes that require approval for write operations. The issue affects versions prior to 0.0.423.
Fix: Fixed in 0.0.423. The fix adds parse-time detection that downgrades commands containing dangerous ${...} expansion operators or nested command/process substitutions from read-only to write-capable, and unconditionally blocks such commands at the tool execution layer regardless of permission mode, including --yolo / autopilot.
GitHub Advisory DatabaseGHSA-wvj2-96wp-fq3f: MCP Go SDK Vulnerable to Improper Handling of Case Sensitivity
Feb 26, 2026HighVulnerabilitySecurityCVE-2026-27896The Go MCP SDK parsed JSON-RPC and MCP messages with Go's standard encoding/json.Unmarshal, which matches keys case-insensitively and folds Unicode characters such as ſ (U+017F) and K (U+212A) to ASCII. A malicious MCP peer could send non-standard field casing, such as "Method" instead of "method", that the SDK silently accepted. This could let such messages bypass intermediary proxies or policy layers that match exact field names, and it made the Go SDK inconsistent with the case-sensitive TypeScript and Python SDKs.
Fix: Fixed in v1.3.1. The SDK replaced Go's standard JSON unmarshaling with a case-sensitive decoder (github.com/segmentio/encoding) in commit 7b8d81c. Users are advised to update to v1.3.1.
GitHub Advisory DatabaseGHSA-w5cr-2qhr-jqc5: Cloudflare Agents has a Reflected Cross-Site Scripting (XSS) vulnerability in AI Playground site
Feb 13, 2026MediumVulnerabilitySecurityCloudflare Agents' AI Playground OAuth callback handler in site/ai-playground/src/server.ts inserted the error_description query parameter into an inline script tag without escaping. A crafted link lets an attacker run JavaScript in a victim's session, exposing chat history, LLM interactions and connected MCP servers, and enabling actions on the victim's behalf.
Fix: Agents-sdk users should upgrade to agents@0.3.10 (fix in PR https://github.com/cloudflare/agents/pull/841). Developers using configureOAuthCallback with custom error handling should escape all user-controlled input before interpolation.
GitHub Advisory DatabaseCVE-2026-1721: AI Playground reflected XSS through OAuth callback error parameter
Feb 12, 2026MediumVulnerabilitySecurityCVE-2026-1721A reflected XSS flaw in the AI Playground's OAuth callback handler (`site/ai-playground/src/server.ts`) interpolates the `error_description` query parameter into an inline `<script>` tag without escaping. A victim who clicks a crafted link lets an attacker run arbitrary JavaScript in their session, exposing stored LLM chat history and allowing actions on any MCP servers connected to that session, public or authenticated.
Fix: Agents-sdk users should upgrade to agents@0.3.10. Developers using configureOAuthCallback with custom error handling should escape all user-controlled input before interpolation. The source also links PR https://github.com/cloudflare/agents/pull/841.
NVD/CVE DatabaseCVE-2026-26029: sf-mcp-server command injection through Salesforce CLI commands
Feb 11, 2026HighVulnerabilitySecurityCVE-2026-26029CVE-2026-26029 affects sf-mcp-server, an implementation of the Salesforce MCP server for Claude for Desktop. The flaw is an OS command injection (CWE-78) caused by unsafe use of child_process.exec when building Salesforce CLI commands from user-controlled input. Successful exploitation lets an attacker run arbitrary shell commands with the privileges of the MCP server process.
Fix: The source links a commit (99fba0171b8c22b5ee3c0405053ccfd2910a066d) and a GitHub security advisory (GHSA-h4w9-g9c5-vfwq), but does not state a fixed version, configuration change or workaround in the text provided.
NVD/CVE DatabaseCVE-2026-25904: Pydantic-AI MCP Run Python tool SSRF via Deno sandbox localhost access
Feb 9, 2026MediumVulnerabilitySecurityCVE-2026-25904CVE-2026-25904 affects the Pydantic-AI MCP Run Python tool, which configures its Deno sandbox too permissively. Python code run through the tool can reach the host's localhost interface and perform server-side request forgery (CWE-918). The project mcp-run-python is archived and unlikely to receive a fix. NVD published the entry on 02/09/2026, citing JFrog as the source.
NVD/CVE DatabaseCVE-2025-15063: Ollama MCP Server execAsync command injection leading to remote code execution
Jan 23, 2026HighVulnerabilitySecurityCVE-2025-15063CVE-2025-15063 is a command injection flaw in the execAsync method of the Ollama MCP Server. It stems from the lack of proper validation of a user-supplied string before the string is used in a system call. Remote attackers can exploit it without authentication to execute code in the context of the service account.
NVD/CVE DatabaseCVE-2026-0757: MCP Manager for Claude Desktop command injection sandbox escape
Jan 22, 2026HighVulnerabilitySecurityCVE-2026-0757MCP Manager for Claude Desktop contains a command injection sandbox escape flaw tracked as CVE-2026-0757, reported as ZDI-CAN-27810. The flaw lies in processing of MCP config objects, where a user-supplied string is used in a system call without proper validation. A remote attacker who gets a target to visit a malicious page or open a malicious file can escape the sandbox and run arbitrary code at medium integrity.
NVD/CVE DatabaseCVE-2026-22252: LibreChat MCP stdio transport accepts arbitrary commands without validation
Jan 12, 2026CriticalVulnerabilitySecurityCVE-2026-22252CVE-2026-22252 affects LibreChat before v0.8.2-rc2. Its MCP stdio transport accepts arbitrary commands without validation, so any authenticated user can run shell commands as root inside the container with a single API request. The weakness is classified as CWE-285, Improper Authorization.
Fix: Fixed in v0.8.2-rc2.
NVD/CVE Database
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.