Product
Context7 versions 2.1.2 and earlier are vulnerable to a prompt injection flaw in the MCP server's Custom AI Instructions feature, enabling credential exfiltration and unauthorized file operations.