Model Context Protocol
The Model Context Protocol and the servers and clients that expose tools and data to models through it.
- All items
- 295
- Last 90 days
- 133
- Change
- +53%vs 87 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 2 |
| Jun 2025 | 4 |
| Jul 2025 | 4 |
| Aug 2025 | 7 |
| Sep 2025 | 3 |
| Oct 2025 | 3 |
| Nov 2025 | 2 |
| Dec 2025 | 4 |
| Jan 2026 | 4 |
| Feb 2026 | 12 |
| Mar 2026 | 22 |
| Apr 2026 | 27 |
| May 2026 | 31 |
| Jun 2026 | 25 |
| Jul 2026 | 43 |
| Aug 2026 | 45 |
| Sep 2026 | 40 |
| Oct 2026 | 16 |
198 items
GHSA-hc5v-gxvj-58wh: PraisonAI: MCP HTTP-stream transport is unauthenticated by default, exposing tool enumeration and an unvalidated tool-call surface
Oct 8, 2026HighVulnerabilitySecurityCVE-2026-61427PraisonAI 4.6.63's MCP HTTP-stream server applies authentication only when an API key is set, and the CLI defaults `--api-key` to `None`, so `praisonai mcp serve --transport http-stream` exposes the full MCP surface without authentication. An unauthenticated client can call `initialize` and `tools/list` (about 50 tools), and the dispatcher in `mcp_server/server.py` forwards tool-call arguments to handlers without validating them against the advertised `inputSchema`. The source states this is not an RCE or file read in 4.6.63, because `workflow.run` and `workflow.run_file` fail at runtime.
GitHub Advisory DatabaseGHSA-6qxp-vccf-f47h: MCP TypeScript SDK: OAuth client could send credentials to an authorization server chosen by the MCP server
Oct 6, 2026HighVulnerabilitySecurityCVE-2026-104850GitHub Advisory DatabaseCVE-2026-105741: Langflow IP spoofing bypasses local-only restriction on MCP install endpoint
Oct 5, 2026HighVulnerabilitySecurityCVE-2026-105741Langflow versions 1.5.0 through 1.10.3 contain an IP spoofing flaw in the MCP configuration installation endpoint, POST /api/v1/mcp/project/{project_id}/install. An authenticated remote attacker can send a spoofed X-Forwarded-For: 127.0.0.1 header, making the server treat the request as local and bypass the "local-only" restriction. This lets the attacker write or overwrite an MCP client configuration file on the server's filesystem.
Fix: Fixed in 1.10.3.
NVD/CVE DatabaseCVE-2026-105740: Langflow remote code execution through MCP server stdio command field
Oct 5, 2026CriticalVulnerabilitySecurityCVE-2026-105740CVE-2026-105740 affects Langflow versions prior to 1.9.0. Any authenticated user can add an MCP server with the "Stdio" transport, and the user-supplied command field is passed directly to bash -c "exec {command}" with no validation, allowlisting, or sandboxing, so the command runs on the server as soon as the server list is fetched. The env field also permits arbitrary environment variable injection, such as LD_PRELOAD or a PATH override.
Fix: Fixed in 1.9.0.
NVD/CVE DatabaseCVE-2026-105699: Langflow MCP resource read exposes other users' flow files
Oct 5, 2026HighVulnerabilitySecurityCVE-2026-105699Langflow versions from 1.6.8 through 1.9.1 fail to authorize the resource URI passed to resources/read on project-scoped MCP connections. An authenticated user with access to any project-scoped MCP endpoint can read another user's flow-backed files, including uploaded documents, structured data, prompts and other private flow artifacts. Global handle_list_resources and handle_list_tools behavior can also disclose the flow and file identifiers needed to target them. Victim files and stored flows are not modified.
Fix: Fixed in 1.9.1.
NVD/CVE DatabaseCVE-2026-105697: Langflow arbitrary command execution through MCP stdio server configuration
Oct 5, 2026CriticalVulnerabilitySecurityCVE-2026-105697CVE-2026-105697 affects Langflow before 1.10.3, where the MCP stdio transport ran whatever command and args a user placed in an MCP server configuration, with no allowlist and, before 1.10.3, wrapped in bash -c "exec {command} ...". Any user who can reach the MCP server settings (POST/PATCH /api/v2/mcp/servers/{server_name}) or build a flow with the MCP Tools component can run an arbitrary OS command on the Langflow host as the Langflow process user, when Langflow connects to the server, even if the UI then reports a startup failure. With the default LANGFLOW_AUTO_LOGIN=true, GET /api/v1/auto_login issues a token without credentials, so the flaw is reachable without an account on an exposed default instance; with AUTO_LOGIN disabled, any authenticated non-admin user can exploit it.
Fix: Fixed in Langflow 1.10.3, langflow-base 0.10.3, and lfx 1.10.3.
NVD/CVE DatabaseGHSA-p23f-cm6q-2qp8: SiYuan MCP asset.upload Reads Arbitrary Absolute File Paths (Workspace Boundary Bypass)
Oct 2, 2026MediumVulnerabilitySecuritySiYuan's MCP tool `asset.upload` accepts a comma-separated `files` list of absolute paths and performs no workspace boundary or sensitive-path check before `model.InsertLocalAssets` opens each file and copies it into the workspace `assets/` directory. An attacker who can steer the AI Agent through prompt injection could make it upload files such as `~/.ssh/id_rsa` into the workspace, where they become reachable. Affected versions are `<= 3.8.0`, and the issue is a residual gap from the remediation of CVE-2026-66012.
Fix: Fixed in 3.8.1.
GitHub Advisory DatabaseGHSA-c9xm-49cp-xcr9: rmcp OAuth client fetches server-controlled resource_metadata URLs
Oct 2, 2026MediumVulnerabilitySecurityThe rmcp OAuth client in modelcontextprotocol/rust-sdk takes a resource_metadata URL from the server-controlled WWW-Authenticate header and fetches it without same-origin or private-network checks. A malicious or compromised MCP server can point the client at localhost, RFC 1918 addresses or cloud metadata endpoints, making the victim application send outbound GET requests from its own network context.
GitHub Advisory DatabaseCVE-2025-71427: Office-PowerPoint-MCP-Server path traversal in file read and write
Oct 1, 2026MediumVulnerabilitySecurityCVE-2025-71427CVE-2025-71427 affects Office-PowerPoint-MCP-Server through 2.0.7. A path traversal flaw lets MCP callers read and write files outside the working directory by supplying absolute paths or ../ sequences. An attacker can steer an AI agent via prompt injection to abuse save_presentation, open_presentation, or manage_image output_path to overwrite any server-writable file or load external files.
NVD/CVE DatabaseCVE-2026-97662 - Argument injection in AWS security-agent-mcp-server diff scan
Oct 1, 2026HighVulnerabilitySecurityCVE-2026-97662 is an argument injection flaw in the diff scan operation of security-agent-mcp-server, an open-source MCP server published by AWS in the awslabs/mcp repository. Affected versions are 0.1.1 up to but not including 0.2.0. A crafted reference value is parsed as a command-line option instead of a revision, letting a context-dependent actor create, overwrite, or truncate arbitrary files on the host outside the workspace directory and bypass the server's workspace-confinement control.
AWS Security BulletinsCVE-2026-96561: AI Engine WordPress plugin stored cross-site scripting via chat REST endpoint
Oct 1, 2026HighVulnerabilitySecurityCVE-2026-96561The AI Engine plugin for WordPress, up to and including 3.8.0, contains a stored cross-site scripting flaw. An unauthenticated attacker can send crafted input to the /mwai-ui/v1/chats/submit REST endpoint, which writes an attacker-controlled string into the PHP error log as a forged line. The plugin's Advisor feature then passes that content into an AI prompt and stores the result unescaped, so the injected script runs when an administrator opens the WordPress dashboard.
NVD/CVE DatabaseCVE-2026-55157: Token Optimizer MCP OS command injection through smart_user username argument
Sep 28, 2026HighVulnerabilitySecurityCVE-2026-55157Prior to version 5.1.0, token-optimizer-mcp is vulnerable to OS command injection in the smart_user tool. Any MCP client that can call smart_user can run arbitrary shell commands through the username argument of the get-user-info operation, with the privileges of the user running the server.
Fix: This issue has been patched in version 5.1.0.
NVD/CVE DatabaseCVE-2026-55156: Token Optimizer MCP dashboard path traversal via sessionId in session endpoints
Sep 28, 2026MediumVulnerabilitySecurityCVE-2026-55156Token Optimizer MCP versions before 5.1.0 run a dashboard HTTP server whose /api/session-summary and /api/session-events endpoints have no authentication middleware. Both handlers join the caller-supplied sessionId query parameter into a filesystem path with path.join, and Node.js normalizes .. segments, so an unauthenticated network client can read any .jsonl file the server can access.
Fix: This issue has been patched in version 5.1.0.
NVD/CVE DatabaseCVE-2026-101065: Obot Docker quickstart exposes admin access without authentication
Sep 27, 2026CriticalVulnerabilitySecurityCVE-2026-101065Obot, an open-source AI agent and MCP platform, documents a Docker quickstart that starts the container on 0.0.0.0:8080 with authentication disabled by default in all versions up to and including commit d7e6970 (CVE-2026-101065). Unauthenticated users who can reach the port receive a synthetic "nobody" user holding the Owner and Admin roles, which grants full control of the Obot API and UI, including registering and launching attacker-controlled MCP servers. The quickstart also mounts /var/run/docker.sock, giving the MCP runtime backend access to the host's Docker control surface.
Fix: The fix is documentation-only: the quickstart now enables authentication. Operators who followed the previous instructions should set OBOT_SERVER_ENABLE_AUTHENTICATION=true before exposing the host to any untrusted network.
NVD/CVE DatabaseCVE-2026-97228: Rapid7 Bulk Export MCP GraphQL query injection in export-status component
Sep 25, 2026LowVulnerabilitySecurityCVE-2026-97228Rapid7 Bulk Export MCP versions 0.2.5 through 0.6.1 contain a GraphQL query injection in `get_export_status` in `src/export_manager.py`. The unvalidated `export_id` argument, passed via the `check_rapid7_export_status` and `download_rapid7_export` tools, is interpolated directly into the query string, so a crafted value can append attacker-chosen root-level selections such as schema introspection. The injected query runs under the operator's own API key and cannot cross a tenant or account boundary, so the realistic exposure is a compromised or careless upstream MCP client or indirect prompt injection.
Fix: Fixed in version 0.6.2, which passes `export_id` as a parameterized GraphQL variable (`$exportId: ID!`).
NVD/CVE DatabaseGHSA-3cj3-hqcr-g934: Cline: Cross-Origin WebSocket Hijacking in Cline Hub Dashboard (`/browser` endpoint)
Sep 24, 2026HighVulnerabilitySecurityCVE-2026-59723The Cline Hub dashboard server (`@cline/cline-hub`), launched with the `cline dashboard` CLI command, accepts WebSocket connections on `/browser` without validating the HTTP `Origin` header. When `ROOM_SECRET` is unset, which is the default for `127.0.0.1` binds, `isAuthorizedBrowserRequest()` returns `true`, so any website a developer visits can open a cross-origin WebSocket to `ws://127.0.0.1:8787/browser`. Dashboard sessions default to `autoApprove: true` for all tools, and the source reports that an injected `upsert_mcp_server` frame wrote a malicious `stdio` MCP server entry into the victim's Cline settings file.
GitHub Advisory DatabaseGHSA-fm8p-53ww-hf6w: DBHub HTTP transport DNS rebinding allows unauthenticated browser-origin SQL execution
Sep 24, 2026CriticalVulnerabilitySecurityCVE-2026-61742DBHub 0.21.2 exposes an unauthenticated HTTP MCP endpoint at /mcp when run with --transport http. Its origin check only compares Origin and Host hostnames for equality, so a DNS rebinding attack lets a malicious website invoke DBHub MCP tools from a victim's browser without prompt injection or model involvement. With a real configured database, this can read, enumerate, and potentially write database contents depending on configured tool permissions and credentials.
Fix: Suggested remediation: bind HTTP transport to 127.0.0.1 by default and require explicit opt-in for 0.0.0.0 or non-loopback hosts. Add an explicit allowed-hosts policy instead of accepting arbitrary hosts (the source text is truncated at this point).
GitHub Advisory DatabaseCVE-2026-93529: Contributor Broken Access Control in WSP MCP – AI Agents Connector <= 2.7.0 versions.
Sep 23, 2026MediumVulnerabilitySecurityCVE-2026-93529CVE-2026-93529 is a Contributor Broken Access Control flaw in WSP MCP – AI Agents Connector, affecting versions up to and including 2.7.0. The source text provides no further detail on how the flaw is reached or what an attacker gains.
NVD/CVE DatabaseCVE-2026-18875: IBM FTM for RedHat OpenShift RAG poisoning via unauthenticated upsert
Sep 23, 2026HighVulnerabilitySecurityCVE-2026-18875IBM Financial Transaction Manager (FTM) for RedHat OpenShift is affected by CVE-2026-18875, a RAG poisoning flaw (CWE-74) caused by an unauthenticated runbook upsert in the FTM AI agent server at api.vectordb.runbooks.js:51. An unauthenticated attacker can insert malicious runbook content into the agent's vector database. This can steer AI-driven MCP tool calls, potentially triggering unauthorized payment actions or exfiltrating payment data.
NVD/CVE DatabaseGHSA-93xw-j965-9mx3: MCP Atlassian: Arbitrary file read/exfiltration via upload_attachment missing validate_safe_path()
Sep 22, 2026HighVulnerabilitySecurityCVE-2026-77258The upload_attachment method in confluence/attachments.py of mcp-atlassian reads and uploads arbitrary local files to Confluence without calling validate_safe_path(), although the download methods do call it. An MCP-connected AI agent, or an attacker influencing it through prompt injection, can read any file the server process can access, such as SSH keys, AWS credentials or .env files, and exfiltrate it as a Confluence page attachment. The issue was reproduced with mcp-atlassian 0.21.1 on Python 3.11.
Fix: Add validate_safe_path(file_path) before the os.path.exists() check in upload_attachment, matching the existing pattern in the download methods. The function is already imported in that file.
GitHub Advisory Database
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.