Tag
mcp-shell Insecure Configuration and Allowlist Bypass
2 TTPsmcp-shell versions prior to 0.6.0 suffer from default-disabled security settings and insecure allowlists, enabling unauthenticated arbitrary command execution via connected LLM agents.
Contentful MCP Tools SSRF via LLM-Controlled Parameters
2 TTPsThe Contentful MCP tools 'export_space' and 'import_space' are vulnerable to Server-Side Request Forgery (SSRF) due to the unsafe passing of LLM-controlled 'host' and 'proxy' arguments directly to the Contentful Management API client, enabling credential exfiltration.
Automated LLM-Based User Account Compromise Triage
3 TTPsAn automated detection framework that uses Large Language Models to correlate disparate security alerts and assess potential account compromise based on behavioral indicators.
Server-Side Request Forgery in mcp-webresearch (CVE-2026-65056)
4 TTPs 1 CVEA server-side request forgery (SSRF) vulnerability in mcp-webresearch version 0.1.7 allows attackers to bypass URL protocol validation by supplying private IP addresses, enabling them to leverage prompt injection to steer an LLM-controlled URL, forcing the server's Playwright browser to access internal network services and cloud instance metadata, which leads to the exfiltration of sensitive internal content, including credentials, into the model's context.
LiteLLM Vulnerability Allows Remote Code Execution with Service Privileges
2 TTPsA remote, authenticated attacker can exploit a vulnerability in LiteLLM to execute arbitrary program code with the privileges of the service.