{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/mcp-router/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-81094"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["mcp-router"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"threat","_cs_vendors":[],"content_html":"\u003cp\u003eThe mcp-router CLI tool contains a significant configuration vulnerability (CVE-2026-81094) in how it handles the 'serve' command. In versions prior to 0.6.3, the aggregator service defaults to binding to all network interfaces (0.0.0.0) on a fixed port rather than the local loopback interface. Furthermore, the application does not enforce authentication tokens by default. If an operator starts the tool using default settings, the MCP aggregator and all downstream MCP servers it orchestrates are exposed to any party with network reachability to the host. This effectively allows unauthorized actors to interface with, query, or potentially influence data processed by the MCP aggregator. The vulnerability was remediated in release 0.6.3, which forces a loopback bind by default and enforces token-based authentication when non-loopback addresses are specified.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an unauthenticated attacker to interact with the mcp-router CLI, enabling unauthorized access to sensitive MCP-managed resources. Organizations using versions earlier than 0.6.3 in production environments are at risk of lateral movement or information disclosure if the host is reachable from untrusted network segments.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade mcp-router to version 0.6.3 or higher immediately to enforce secure network binding and mandatory authentication.\u003c/li\u003e\n\u003cli\u003eAudit existing deployments of mcp-router to identify instances bound to non-loopback interfaces.\u003c/li\u003e\n\u003cli\u003eImplement network access control lists (ACLs) to restrict access to the mcp-router listening port to authorized management hosts only.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-27T19:08:54Z","date_published":"2026-08-27T19:08:54Z","id":"https://feed.craftedsignal.io/briefs/2026-08-mcp-router-insecure-default/","summary":"The mcp-router CLI versions prior to 0.6.3 default to binding the MCP aggregator service to all network interfaces without mandatory authentication, exposing fronted MCP servers to unauthorized remote access.","title":"Unauthenticated Remote Access Vulnerability in mcp-router CLI","url":"https://feed.craftedsignal.io/briefs/2026-08-mcp-router-insecure-default/"}],"language":"en","title":"CraftedSignal Threat Feed - Mcp-Router","version":"https://jsonfeed.org/version/1.1"}