Skip to content
Threat Feed

Tag

Mcp

26 briefs RSS
high threat

Arbitrary File Read Vulnerability in mcp-atlassian

The mcp-atlassian package contains a path traversal vulnerability allowing an authenticated MCP caller to exfiltrate arbitrary server-local files to Jira or Confluence via attachment upload tools.

exploited mcp-atlassian path-traversal data-exfiltration mcp cve-2026-77253
1t 1c
high advisory

SSRF Protection Bypass in mcp-atlassian

The mcp-atlassian library is vulnerable to an SSRF bypass (CVE-2026-77274) due to a URL parsing discrepancy between the security validator and the HTTP client, allowing attackers to access internal or loopback services.

mcp-atlassian ssrf application-vulnerability lfd mcp atlassian confluence jira cve-2026-77257
1r 2t 1c
critical advisory

Authentication Bypass in mcp-atlassian HTTP Transport

The mcp-atlassian package contains an authentication bypass vulnerability (CVE-2026-77244) that allows unauthenticated network-adjacent attackers to execute tools using the operator's Jira and Confluence credentials.

mcp-atlassian +1 authentication-bypass api-security atlassian mcp path-traversal ai-security exfiltration vulnerability +9
1r 8t 2c
high threat

ToolHive Containerized MCP Servers Vulnerable to Host Pivot and Lateral Movement

ToolHive versions prior to 0.30.1 enable insecure container network defaults that allow MCP servers to reach host services via host.docker.internal, enabling unauthenticated lateral movement and host API exploitation.

exploited ToolHive container-security mcp lateral-movement cve-2026-58197
3t 1c
high advisory

SSRF Vulnerability in Obot via Remote MCP Server URLs

Obot versions 0.22.1 and earlier are vulnerable to server-side request forgery (SSRF) allowing authenticated privileged users to probe internal network resources and cloud instance metadata services.

Obot +1 ssrf cloud-security vulnerability oauth authentication-bypass token-theft mcp
5t
high advisory

Multiple Safety-Control Bypasses in @zereight/mcp-gitlab

Multiple vulnerabilities in the @zereight/mcp-gitlab package allow attackers to bypass read-only mode, exfiltrate data, perform unauthorized GitLab operations, and trigger a denial-of-service via unauthenticated session exhaustion.

@zereight/mcp-gitlab mcp gitlab llm-security supply-chain
4t
critical advisory

SSRF Vulnerability in mcp-gitlab Enables GitLab Credential Theft

The mcp-gitlab server is vulnerable to Server-Side Request Forgery (SSRF) when ENABLE_DYNAMIC_API_URL is enabled, allowing attackers to force the server to forward victim GitLab tokens to an arbitrary host.

mcp-gitlab +2 dns-rebinding mcp gitlab cve-2026-61568 vulnerability rce exfiltration
1r 6t 1c updated
critical advisory

Unauthenticated SQL Execution and RCE in MySQL MCP Server via SSE Transport

The mysql_mcp_server package (v < 0.4.2) fails to implement security protections in SSE transport mode, enabling unauthenticated attackers to perform arbitrary SQL execution, data exfiltration, and potential remote code execution.

mysql_mcp_server vulnerability rce sql-injection mcp
2t
high advisory

Remote Code Execution in functype-mcp-server via Unsanitized MCP Tool Input

The set_functype_version MCP tool in functype-mcp-server allows unauthenticated attackers to execute arbitrary code by passing a malicious package alias to pnpm, which the server subsequently executes via dynamic import.

functype-mcp-server remote-code-execution mcp nodejs
1r 1t
critical advisory

CVE-2026-86542 Path Traversal in knowns Application

An unauthenticated path traversal vulnerability in knowns versions prior to 0.30.0 allows attackers to overwrite arbitrary files on the server by supplying malicious traversal sequences in the import route name parameter.

knowns +1 remote-code-execution cve vulnerability path-traversal mcp
2r 6t 1c updated
high advisory

Unauthenticated SSRF in Chainlit MCP Component

Chainlit versions 2.4.0rc0 through 2.11.1 contain an unauthenticated SSRF vulnerability (CVE-2026-45019) in the Model Context Protocol (MCP) component, allowing attackers to perform internal network reconnaissance and interact with internal APIs using attacker-controlled HTTP headers.

Chainlit ssrf mcp cve-2026-45019
1r 1t 1c
high advisory

DNS Rebinding Vulnerability in GenieACS MCP Streamable HTTP Transport

The genieacs-mcp package fails to validate Host and Origin headers on loopback listeners, allowing unauthorized web pages to perform DNS rebinding and invoke administrative GenieACS tools via an unauthenticated MCP interface.

genieacs-mcp dns-rebinding mcp genieacs remote-code-execution
1t 1c
high advisory

MCP-Shell Secure Mode Allowlist Bypass via Shell Interpreter

The mcp-shell tool contains a security bypass where improper validation of command-line arguments allows an attacker to execute arbitrary commands by leveraging a default-allowed shell interpreter.

mcp-shell command-injection mcp container-security
1t
high advisory

mcp-shell Insecure Configuration and Allowlist Bypass

mcp-shell versions prior to 0.6.0 suffer from default-disabled security settings and insecure allowlists, enabling unauthenticated arbitrary command execution via connected LLM agents.

PoC mcp-shell vulnerability rce mcp llm-security
2t
high advisory

Path Traversal Vulnerability in grok-faf-mcp

The grok-faf-mcp MCP server contains an arbitrary file read vulnerability via inadequate path validation, allowing attackers to access sensitive host files by injecting path traversal sequences into tool arguments.

grok-faf-mcp mcp path-traversal information-disclosure
2t
high advisory

Arbitrary Local File Read and Write in claude-faf-mcp

The claude-faf-mcp MCP server exposes arbitrary file read and write primitives through unconfined path parameters, allowing LLM-based prompt injection to access sensitive local files or modify system files.

claude-faf-mcp vulnerability mcp path-traversal arbitrary-file-read arbitrary-file-write
2t
high advisory

Contentful MCP Tools SSRF via LLM-Controlled Parameters

The Contentful MCP tools 'export_space' and 'import_space' are vulnerable to Server-Side Request Forgery (SSRF) due to the unsafe passing of LLM-controlled 'host' and 'proxy' arguments directly to the Contentful Management API client, enabling credential exfiltration.

Contentful MCP Tools +1 ssrf llm-security credential-theft mcp
2t
medium advisory

Unbounded Memory Growth in MCP PHP SDK SSE Client

The MCP PHP SDK's HTTP transport fails to bound the in-memory buffer used for Server-Sent-Events, allowing a malicious server to trigger a denial-of-service via memory exhaustion.

sdk denial-of-service sse mcp memory-exhaustion
1t
critical advisory

Unauthenticated Remote Execution in dynatrace-mcp-server HTTP Transport

The dynatrace-mcp-server package v1.8.5 contains a critical authentication bypass vulnerability in its HTTP transport mode that allows unauthenticated, network-reachable attackers to invoke sensitive Model Context Protocol tools.

dynatrace-mcp-server authentication-bypass mcp dynatrace web-vulnerability
1r
high advisory

Session Poisoning Vulnerability in Ruby MCP SDK

The Ruby SDK for the Model Context Protocol (MCP) lacks session ownership validation, allowing attackers to perform unauthorized tool executions within a victim's active session.

Ruby SDK cve-2026-67431 mcp session-hijacking ruby sse
1c
medium advisory

MKP Pod Log Read Vulnerability Leads to Memory Exhaustion and Denial of Service

An unauthenticated remote attacker can exploit a vulnerability in the MKP (Model Context Protocol for Kubernetes) server to exhaust its memory and cause a denial of service by sending a crafted `tools/call` request that manipulates `limitBytes` or `tailLines` parameters, leading to unbounded Kubernetes pod log reads into memory.

MKP server kubernetes denial-of-service memory-exhaustion unauthenticated mcp cloud
2t
critical advisory

MCPHub User Impersonation Vulnerability via Unauthenticated SSE Endpoint

MCPHub is vulnerable to user identity spoofing on the MCP transport layer; an unauthenticated network user can impersonate any user, including administrators, on SSE/MCP endpoints by providing the target username in the URL path, which allows execution of MCP tool calls under a spoofed user's identity, access to user-scoped resources and data, and poisoning of audit logs.

@samanhappy/mcphub identity-spoofing sse mcp unauthenticated-access
2r 3t
critical advisory

Obot Authorization Bypass in /mcp-connect/{id} Endpoint

Obot version 0.21.0 has an authorization bypass vulnerability in the `/mcp-connect/{id}` endpoint allowing any authenticated user to connect to any registered MCP server, regardless of permissions, leading to unauthorized access and actions on upstream services.

obot authorization bypass privilege escalation mcp cloud
2r 2t
critical advisory

PraisonAI MCP Path Traversal to RCE via .pth Injection

PraisonAI's MCP server is vulnerable to path traversal leading to arbitrary code execution by writing a Python `.pth` file into the user's site-packages directory, triggered via poisoned LLM contexts or unauthenticated HTTP-stream transports due to unvalidated kwargs in the dispatcher and lack of containment checks in file-handling tools.

MCP path-traversal code-execution prompt-injection
3r 3t
critical advisory

Unsecured Model Context Protocol (MCP) Server Deployments Expose AI Integrations

Unsecured Model Context Protocol (MCP) servers, used to connect AI agents to enterprise tools, lack authentication and audit trails, leading to data exfiltration, private repo leaks, cross-tenant exposure, and remote code execution due to AI agents using valid user credentials to make API calls based on potentially poisoned context.

Claude +4 ai mcp zero-trust data-exfiltration rce
2r 8t 1i
high advisory

Java-SDK DNS Rebinding Vulnerability in MCP Server

A DNS rebinding vulnerability exists in java-sdk versions prior to 1.0.0, allowing an attacker to access a locally or network-private java-sdk MCP server via a victim's browser, potentially enabling unauthorized tool calls to the server.

Java SDK +1 dns-rebinding java-sdk mcp cve-2026-35568
2r 2t