Skip to content
Threat Feed
high threat exploited

Unauthenticated Remote Access Vulnerability in mcp-router CLI

The mcp-router CLI versions prior to 0.6.3 default to binding the MCP aggregator service to all network interfaces without mandatory authentication, exposing fronted MCP servers to unauthorized remote access.

CVE search metadata

CVE search record: CVE-2026-81094. Severity: critical. CVSS: 9.1. KEV: no. Product: mcp-router. Brief: Unauthenticated Remote Access Vulnerability in mcp-router CLI. Brief link: https://feed.craftedsignal.io/briefs/2026-08-mcp-router-insecure-default/

The mcp-router CLI tool contains a significant configuration vulnerability (CVE-2026-81094) in how it handles the 'serve' command. In versions prior to 0.6.3, the aggregator service defaults to binding to all network interfaces (0.0.0.0) on a fixed port rather than the local loopback interface. Furthermore, the application does not enforce authentication tokens by default. If an operator starts the tool using default settings, the MCP aggregator and all downstream MCP servers it orchestrates are exposed to any party with network reachability to the host. This effectively allows unauthorized actors to interface with, query, or potentially influence data processed by the MCP aggregator. The vulnerability was remediated in release 0.6.3, which forces a loopback bind by default and enforces token-based authentication when non-loopback addresses are specified.

Impact

Successful exploitation allows an unauthenticated attacker to interact with the mcp-router CLI, enabling unauthorized access to sensitive MCP-managed resources. Organizations using versions earlier than 0.6.3 in production environments are at risk of lateral movement or information disclosure if the host is reachable from untrusted network segments.

Recommendation

  • Upgrade mcp-router to version 0.6.3 or higher immediately to enforce secure network binding and mandatory authentication.
  • Audit existing deployments of mcp-router to identify instances bound to non-loopback interfaces.
  • Implement network access control lists (ACLs) to restrict access to the mcp-router listening port to authorized management hosts only.

Immediate actions

Upgrade mcp-router to 0.6.3 or higher.

IT Operations 48h

Mitigations

Restrict network access to mcp-router ports.

immediate IT Operations

CVE-2026-81094