Command Palette

Search for a command to run...

UnylyUnyly
Browse all

Cve Project

FreeNot checked

The Project shares all information on MCP related CVE's published

GitHubEmbed

About

The Project shares all information on MCP related CVE's published

README

This repository is a curated index of publicly disclosed Common Vulnerabilities and Exposures (CVEs) that touch the Model Context Protocol (MCP) ecosystem: official and third-party servers, SDKs, gateways, clients, and integrations where MCP is part of the attack surface or fix scope. Each linked note under [cves/](cves/) summarizes the affected component, weakness class, and pointers for defenders and maintainers.

Coverage: 570 indexed CVEs (indexed below, newest first by disclosure-related date).

Maintained and curated by Vandana Verma Sehgal.

OWASP MCP Top 10 (2025) mapping

Indexed CVEs are mapped to the primary category in the OWASP MCP Top 10 (2025). Mappings use NVD/CWE and index summaries where available. A CVE may relate to more than one MCP risk; only the primary mapping is shown in the tables below.

ID Category Count
MCP01 Token Mismanagement & Secret Exposure 92
MCP02 Privilege Escalation via Scope Creep 75
MCP03 Tool Poisoning 2
MCP04 Software Supply Chain Attacks & Dependency Tampering 37
MCP05 Command Injection & Execution 210
MCP06 Prompt Injection via Contextual Payloads 13
MCP07 Insufficient Authentication & Authorization 112
MCP08 Lack of Audit and Telemetry 4
MCP09 Shadow MCP Servers 22
MCP10 Context Injection & Over-Sharing 5

CVE Breakdown

2026

S.No Date CVE OWASP MCP Top 10 (2025) Affected product
1 2026‑09‑04 CVE‑2026‑77822 MCP07 — Insufficient Authentication & Authorization IBM ContextForge MCP Gateway (mcp-contextforge-gateway): A2A invoke DNS rebinding SSRF
2 2026‑09‑04 CVE‑2026‑18905 MCP07 — Insufficient Authentication & Authorization IBM ContextForge MCP Gateway (mcp-contextforge-gateway): tool-invocation DNS rebinding
3 2026‑08‑31 CVE‑2026‑79748 MCP07 — Insufficient Authentication & Authorization MCPHub (samanhappy/mcphub): STDIO MCP server create/update authorization gap
4 2026‑08‑31 CVE‑2026‑81315 MCP07 — Insufficient Authentication & Authorization ash_ai MCP HTTP transport DNS rebinding / X-Forwarded-Proto origin bypass
5 2026‑08‑27 CVE‑2026‑81092 MCP07 — Insufficient Authentication & Authorization mcp-go (mark3labs/mcp-go): StreamableHTTP / SSE DNS rebinding via missing Host validation
6 2026‑08‑27 CVE‑2026‑37006 MCP05 — Command Injection & Execution GPT Researcher WebSocket endpoint malicious MCP configuration RCE
7 2026‑08‑26 CVE‑2026‑75062 MCP05 — Command Injection & Execution Google langfun (langfun): default lf.query eval injection
8 2026‑08‑25 CVE‑2026‑45018 MCP05 — Command Injection & Execution Chainlit (chainlit): MCP stdio command injection via POST /mcp
9 2026‑08‑25 CVE‑2026‑45019 MCP05 — Command Injection & Execution Chainlit (chainlit): MCP SSE / streamable-http SSRF via POST /mcp
10 2026‑08‑25 CVE‑2026‑55637 MCP07 — Insufficient Authentication & Authorization genieacs-mcp: Streamable HTTP DNS rebinding on localhost listener
11 2026‑05‑15 CVE‑2026‑45350 MCP02 — Privilege Escalation via Scope Creep Open WebUI chat completion API MCP tool restriction bypass
12 2026‑04‑23 CVE‑2026‑41268 MCP05 — Command Injection & Execution Flowise Custom MCP mcpServerConfig parameter override / NODE_OPTIONS injection RCE
13 2026‑04‑14 CVE‑2026‑39417 MCP05 — Command Injection & Execution MaxKB workflow MCP node STDIO RCE (incomplete fix for CVE-2025-53928)
14 2026‑03‑18 GHSA‑q382‑vc8q‑7jhj MCP04 — Software Supply Chain Attacks & Dependency Tampering MCP Go SDK (modelcontextprotocol/go-sdk): null-Unicode JSON key override (no CVE assigned)
15 2026‑03‑18 CVE‑2026‑32632 MCP07 — Insufficient Authentication & Authorization Glances REST/WebUI MCP DNS rebinding / missing Host validation
16 2026‑02‑03 CVE‑2026‑24052 MCP06 — Prompt Injection via Contextual Payloads Claude Code (@anthropic-ai/claude-code): WebFetch trusted-domain validation bypass
17 2026‑08‑19 CVE‑2026‑53965 MCP07 — Insufficient Authentication & Authorization MCP PHP SDK (modelcontextprotocol/php-sdk): HttpTransport unbounded SSE buffer DoS
18 2026‑08‑12 CVE‑2026‑73498 MCP02 — Privilege Escalation via Scope Creep MCP Atlassian (mcp-atlassian): confluence_upload_attachment path traversal / arbitrary file read
19 2026‑07‑30 CVE‑2026‑67430 MCP07 — Insufficient Authentication & Authorization MCP Ruby SDK (modelcontextprotocol/ruby-sdk): Streamable HTTP unbounded session retention DoS
20 2026‑07‑30 CVE‑2026‑67431 MCP07 — Insufficient Authentication & Authorization MCP Ruby SDK (modelcontextprotocol/ruby-sdk): Streamable HTTP session poisoning / missing session owner binding
21 2026‑07‑30 CVE‑2026‑67432 MCP07 — Insufficient Authentication & Authorization MCP Ruby SDK (modelcontextprotocol/ruby-sdk): Streamable HTTP unbounded JSON-RPC body DoS
22 2026‑07‑16 CVE‑2026‑44968 MCP05 — Command Injection & Execution dbt-mcp: dbt CLI argument injection via node_selection / resource_type
23 2026‑07‑16 CVE‑2026‑44969 MCP01 — Token Mismanagement & Secret Exposure dbt-mcp: plaintext SQL/credentials in tool argument logs when file logging enabled
24 2026‑07‑16 CVE‑2026‑44970 MCP01 — Token Mismanagement & Secret Exposure dbt-mcp: unredacted MCP tool arguments sent to dbt Labs telemetry by default
25 2026‑07‑17 CVE‑2026‑50143 MCP01 — Token Mismanagement & Secret Exposure @apify/actors-mcp-server Actor webServerMcpPath authority injection / Apify token leak
26 2026‑07‑15 CVE‑2026‑59950 MCP07 — Insufficient Authentication & Authorization MCP Python SDK (mcp): deprecated WebSocket transport Host/Origin validation gap
27 2026‑07‑10 CVE‑2026‑61459 MCP02 — Privilege Escalation via Scope Creep mcp-server-kubernetes structured tools --server argument injection / bearer token exfiltration
28 2026‑07‑08 CVE‑2026‑63118 MCP07 — Insufficient Authentication & Authorization MCP Ruby SDK (modelcontextprotocol/ruby-sdk): Streamable HTTP DNS rebinding
29 2026‑07‑08 CVE‑2026‑63119 MCP07 — Insufficient Authentication & Authorization MCP Ruby SDK (modelcontextprotocol/ruby-sdk): stdio unbounded line buffer DoS
30 2026‑07‑03 CVE‑2026‑13341 MCP06 — Prompt Injection via Contextual Payloads Kong Konnect MCP server (mcp-konnect) indirect prompt injection
31 2026‑06‑30 CVE‑2026‑7663 MCP07 — Insufficient Authentication & Authorization IBM Langflow Streamable MCP authorization bypass
32 2026‑06‑30 CVE‑2026‑58446 MCP07 — Insufficient Authentication & Authorization Presenton bundled MCP server unauthenticated /mcp access
33 2026‑06‑30 CVE‑2026‑58171 MCP02 — Privilege Escalation via Scope Creep Vibe-Trading path traversal affecting MCP/agent workflow storage
34 2026‑06‑30 CVE‑2026‑58168 MCP07 — Insufficient Authentication & Authorization DeepTutor MCP tool authorization bypass
35 2026‑06‑29 CVE‑2026‑13524 MCP07 — Insufficient Authentication & Authorization Cherry Studio MCP OAuth local callback issue
36 2026‑06‑28 CVE‑2026‑58057 MCP05 — Command Injection & Execution Flowise Custom MCP Windows env-var denylist bypass
37 2026‑06‑28 CVE‑2026‑13489 MCP07 — Insufficient Authentication & Authorization xiaozhi-esp32 MCP response handler validation issue
38 2026‑06‑26 CVE‑2026‑57922 MCP01 — Token Mismanagement & Secret Exposure JetBrains YouTrack project settings disclosure via MCP
39 2026‑06‑26 CVE‑2026‑48529 MCP02 — Privilege Escalation via Scope Creep GitHub MCP Server HTTP lockdown-mode repo access cache issue
40 2026‑06‑26 CVE‑2026‑4339 MCP05 — Command Injection & Execution Mattermost Agents plugin MCP server internal/private IP validation issue
41 2026‑06‑25 CVE‑2026‑54842 MCP07 — Insufficient Authentication & Authorization Royal MCP missing authorization
42 2026‑06‑25 CVE‑2026‑54030 MCP07 — Insufficient Authentication & Authorization LibreChat MCP OAuth resource validation issue
43 2026‑06‑24 CVE‑2026‑57300 MCP07 — Insufficient Authentication & Authorization Jenkins MCP Server Plugin missing permission check
44 2026‑06‑24 CVE‑2026‑53766 MCP02 — Privilege Escalation via Scope Creep chrome-devtools-mcp workspace path validation issue
45 2026‑06‑24 CVE‑2026‑12958 MCP02 — Privilege Escalation via Scope Creep Amazon Q Developer / Language Servers for AWS (symlink write outside workspace trust boundary)
46 2026‑06‑24 CVE‑2026‑12957 MCP09 — Shadow MCP Servers Amazon Q Developer / Language Servers for AWS (.amazonq/mcp.json auto-execution)
47 2026‑06‑24 CVE‑2026‑12537 MCP09 — Shadow MCP Servers Google Gemini CLI / run-gemini-cli GitHub Action
48 2026‑06‑23 CVE‑2026‑56274 MCP05 — Command Injection & Execution Flowise Custom MCP Server command injection
49 2026‑06‑23 CVE‑2026‑54309 MCP07 — Insufficient Authentication & Authorization @n8n/mcp-browser unauthenticated HTTP transport
50 2026‑06‑23 CVE‑2026‑47388 MCP02 — Privilege Escalation via Scope Creep NocoDB MCP token attachment ownership bypass / file read
51 2026‑06‑23 CVE‑2026‑46549 MCP02 — Privilege Escalation via Scope Creep NocoDB MCP OAuth token scope bypass
52 2026‑06‑23 CVE‑2026‑12112 MCP07 — Insufficient Authentication & Authorization foreman-mcp-server session hijack via non-secret session IDs
53 2026‑06‑22 CVE‑2026‑7664 MCP07 — Insufficient Authentication & Authorization IBM Langflow Streamable MCP authorization bypass
54 2026‑06‑22 CVE‑2026‑10789 MCP05 — Command Injection & Execution Autodesk Fusion Desktop MCP extension arbitrary code execution
55 2026‑06‑21 CVE‑2026‑12798 MCP05 — Command Injection & Execution LiteLLM OpenAPI-to-MCP generator SSRF
56 2026‑06‑21 CVE‑2026‑12774 MCP05 — Command Injection & Execution LiteLLM MCP connection testing SSRF
57 2026‑06‑21 CVE‑2026‑12773 MCP07 — Insufficient Authentication & Authorization LiteLLM MCP Proxy improper authentication
58 2026‑06‑19 CVE‑2026‑49357 MCP07 — Insufficient Authentication & Authorization line-desktop-mcp unauthenticated HTTP mode chat access
59 2026‑06‑19 CVE‑2026‑49291 MCP02 — Privilege Escalation via Scope Creep mcp-memory-service OAuth read-scope tools/call bypass
60 2026‑06‑19 CVE‑2026‑48787 MCP05 — Command Injection & Execution gin-vue-admin MCP management code-generation command injection
61 2026‑06‑19 CVE‑2026‑48774 MCP02 — Privilege Escalation via Scope Creep ProxySQL GenAI/MCP run_sql_readonly multi-statement bypass
62 2026‑06‑18 CVE‑2026‑55887 MCP05 — Command Injection & Execution Docker MCP Gateway (github.com/docker/mcp-gateway)
63 2026‑06‑18 CVE‑2026‑49257 MCP07 — Insufficient Authentication & Authorization mcp-pinot unauthenticated 0.0.0.0 HTTP MCP server
64 2026‑06‑18 CVE‑2026‑11719 MCP02 — Privilege Escalation via Scope Creep MCP Toolbox for Databases protocol-version scope bypass
65 2026‑06‑17 CVE‑2026‑48989 MCP07 — Insufficient Authentication & Authorization Windows-MCP unauthenticated HTTP control plane / PowerShell execution
66 2026‑06‑17 CVE‑2026‑48814 MCP07 — Insufficient Authentication & Authorization Network-AI MCP SSE unauthenticated tool invocation
67 2026‑06‑16 CVE‑2026‑53840 MCP01 — Token Mismanagement & Secret Exposure OpenClaw Streamable HTTP MCP custom-header leak on redirects
68 2026‑06‑15 CVE‑2026‑40775 MCP07 — Insufficient Authentication & Authorization Royal MCP unauthenticated broken access control
69 2026‑06‑13 CVE‑2026‑11624 MCP07 — Insufficient Authentication & Authorization MCP Origin/Host validation gap for DNS rebinding controls
70 2026‑06‑12 CVE‑2026‑53820 MCP05 — Command Injection & Execution OpenClaw bundled MCP exec denylist bypass
71 2026‑06‑12 CVE‑2026‑50287 MCP07 — Insufficient Authentication & Authorization @agenticmail/mcp unauthenticated Streamable HTTP endpoint
72 2026‑06‑11 CVE‑2026‑53818 MCP07 — Insufficient Authentication & Authorization OpenClaw MCP loopback owner-only policy bypass
73 2026‑06‑11 CVE‑2026‑53814 MCP02 — Privilege Escalation via Scope Creep OpenClaw hook-triggered MCP loopback privilege escalation
74 2026‑06‑11 CVE‑2026‑47250 MCP02 — Privilege Escalation via Scope Creep mcp-server-kubernetes kubectl_generic unsafe flags / token exfiltration
75 2026‑06‑05 CVE‑2026‑52869 MCP07 — Insufficient Authentication & Authorization MCP Python SDK (mcp): HTTP session auth bypass (SseServerTransport / Streamable HTTP)
76 2026‑06‑05 CVE‑2026‑52870 MCP07 — Insufficient Authentication & Authorization MCP Python SDK (mcp): experimental task handlers cross-client access
77 2026‑06‑04 CVE‑2026‑54449 MCP09 — Shadow MCP Servers LangBot
78 2026‑06‑02 CVE‑2026‑44653 MCP07 — Insufficient Authentication & Authorization LibreChat — GET /api/mcp/servers returns plaintext apiKey.key and oauth.client_secret to VIEW-only users
79 2026‑06‑02 CVE‑2026‑42073 MCP07 — Insufficient Authentication & Authorization OpenClaude MCP OAuth callback CSRF state bypass / DoS
80 2026‑06‑02 CVE‑2026‑32625 MCP01 — Token Mismanagement & Secret Exposure LibreChat — MCP server URL ${VAR} interpolation exfiltrates JWT_SECRET, CREDS_KEY, CREDS_IV, MONGO_URI
81 2026‑06‑01 CVE‑2026‑10280 MCP05 — Command Injection & Execution mcpilot MCP API call endpoint SSRF via serverBaseUrl
82 2026‑06‑01 CVE‑2026‑10277 MCP02 — Privilege Escalation via Scope Creep mcp-google-workspace Gmail saveToDisk improper access controls
83 2026‑05‑29 CVE‑2026‑47751 MCP04 — Software Supply Chain Attacks & Dependency Tampering Anthropic Claude Code Action (claude-code-action)
84 2026‑05‑29 CVE‑2026‑45707 MCP07 — Insufficient Authentication & Authorization n8n-mcp multi-tenant HTTP transport authentication gap
85 2026‑05‑29 CVE‑2026‑45609 MCP05 — Command Injection & Execution Spring AI mcp-security missing MCP-spec SSRF mitigations
86 2026‑05‑29 CVE‑2026‑45582 MCP01 — Token Mismanagement & Secret Exposure n8n-MCP (czlonkowski/n8n-mcp)
87 2026‑05‑29 CVE‑2026‑45555 MCP05 — Command Injection & Execution Roslyn CodeLens MCP Server arbitrary DiagnosticAnalyzer load
88 2026‑05‑26 CVE‑2026‑48710 MCP07 — Insufficient Authentication & Authorization Starlette / FastAPI-based MCP and AI gateways
89 2026‑05‑19 CVE‑2026‑46341 MCP02 — Privilege Escalation via Scope Creep @apify/actors-mcp-server
90 2026‑05‑19 CVE‑2026‑46339 MCP07 — Insufficient Authentication & Authorization 9router MCP routes
91 2026‑05‑19 CVE‑2026‑45805 MCP07 — Insufficient Authentication & Authorization @penpot/mcp
92 2026‑05‑18 CVE‑2026‑46519 MCP02 — Privilege Escalation via Scope Creep mcp-server-kubernetes
93 2026‑05‑15 CVE‑2026‑44717 MCP05 — Command Injection & Execution MCP Calculate Server
94 2026‑05‑14 CVE‑2026‑44895 MCP07 — Insufficient Authentication & Authorization GitLab MCP Server (HTTP transport without authentication)
95 2026‑05‑14 CVE‑2026‑44830 MCP07 — Insufficient Authentication & Authorization Nocturne Memory MCP server (missing auth when token unset)
96 2026‑05‑14 CVE‑2026‑44284 MCP05 — Command Injection & Execution FastGPT (MCP tool URL SSRF gap)
97 2026‑05‑14 CVE‑2026‑42559 MCP07 — Insufficient Authentication & Authorization MCP Rust SDK (rmcp crate): Streamable HTTP server transport DNS rebinding
98 2026‑05‑14 CVE‑2026‑34163 MCP07 — Insufficient Authentication & Authorization FastGPT (MCP tools endpoint auth gap)
99 2026‑05‑12 CVE‑2026‑5029 MCP07 — Insufficient Authentication & Authorization Code Runner MCP Server
100 2026‑05‑12 CVE‑2026‑45781 MCP02 — Privilege Escalation via Scope Creep MCP Registry
101 2026‑05‑12 CVE‑2026‑43992 MCP01 — Token Mismanagement & Secret Exposure JunoClaw
102 2026‑05‑12 CVE‑2026‑42260 MCP05 — Command Injection & Execution Open-WebSearch MCP server
103 2026‑05‑11 CVE‑2026‑45001 MCP04 — Software Supply Chain Attacks & Dependency Tampering OpenClaw
104 2026‑05‑11 CVE‑2026‑44998 MCP03 — Tool Poisoning OpenClaw
105 2026‑05‑11 CVE‑2026‑44995 MCP05 — Command Injection & Execution OpenClaw
106 2026‑05‑11 CVE‑2026‑44450 MCP05 — Command Injection & Execution Lumiverse (MCP server command allowlist bypass)
107 2026‑05‑11 CVE‑2026‑44430 MCP05 — Command Injection & Execution MCP Registry
108 2026‑05‑11 CVE‑2026‑44429 MCP05 — Command Injection & Execution MCP Registry
109 2026‑05‑11 CVE‑2026‑44428 MCP07 — Insufficient Authentication & Authorization MCP Registry
110 2026‑05‑11 CVE‑2026‑44427 MCP07 — Insufficient Authentication & Authorization MCP Registry
111 2026‑05‑11 CVE‑2026‑43901 MCP02 — Privilege Escalation via Scope Creep Wireshark MCP (wireshark-mcp)
112 2026‑05‑10 CVE‑2026‑7738 MCP02 — Privilege Escalation via Scope Creep doc-tools-mcp
113 2026‑05‑09 CVE‑2026‑7729 MCP05 — Command Injection & Execution directus-mcp
114 2026‑05‑09 CVE‑2026‑7728 MCP02 — Privilege Escalation via Scope Creep mcp-rtfm
115 2026‑05‑09 CVE‑2026‑7715 MCP02 — Privilege Escalation via Scope Creep mcp-server-arangodb
116 2026‑05‑08 CVE‑2026‑7653 MCP05 — Command Injection & Execution mcp-server-rijksmuseum
117 2026‑05‑08 CVE‑2026‑7628 MCP05 — Command Injection & Execution mcp-code-review-server
118 2026‑05‑08 CVE‑2026‑7627 MCP02 — Privilege Escalation via Scope Creep metatrader-4-mcp
119 2026‑05‑08 CVE‑2026‑44694 MCP05 — Command Injection & Execution n8n-mcp
120 2026‑05‑08 CVE‑2026‑44336 MCP05 — Command Injection & Execution PraisonAI MCP tools/call path traversal to RCE via .pth injection
121 2026‑05‑08 CVE‑2026‑42282 MCP08 — Lack of Audit and Telemetry n8n-mcp
122 2026‑05‑08 CVE‑2026‑42271 MCP05 — Command Injection & Execution LiteLLM MCP server preview endpoints
123 2026‑05‑08 CVE‑2026‑41495 MCP08 — Lack of Audit and Telemetry n8n-mcp
124 2026‑05‑07 CVE‑2026‑7600 MCP05 — Command Injection & Execution mcp-server-yii2
125 2026‑05‑07 CVE‑2026‑7599 MCP05 — Command Injection & Execution terminalcraft
126 2026‑05‑07 CVE‑2026‑7594 MCP02 — Privilege Escalation via Scope Creep DungeonMind-MCP
127 2026‑05‑07 CVE‑2026‑7593 MCP05 — Command Injection & Execution command-executor-mcp-server
128 2026‑05‑07 CVE‑2026‑42449 MCP05 — Command Injection & Execution n8n-mcp
129 2026‑05‑06 CVE‑2026‑7446 MCP05 — Command Injection & Execution mcp-server-semgrep
130 2026‑05‑06 CVE‑2026‑7443 MCP05 — Command Injection & Execution mcp-dnstwist
131 2026‑05‑06 CVE‑2026‑44118 MCP07 — Insufficient Authentication & Authorization OpenClaw (loopback MCP owner-context spoofing)
132 2026‑05‑05 CVE‑2026‑7386 MCP05 — Command Injection & Execution mail-mcp-bridge
133 2026‑05‑05 CVE‑2026‑35228 MCP05 — Command Injection & Execution Oracle MCP Server Helper Tool (SQL injection)
134 2026‑05‑04 CVE‑2026‑7730 MCP05 — Command Injection & Execution privsim/mcp-test-runner
135 2026‑05‑04 CVE‑2026‑42236 MCP07 — Insufficient Authentication & Authorization n8n (MCP OAuth client registration DoS)
136 2026‑05‑04 CVE‑2026‑42230 MCP07 — Insufficient Authentication & Authorization n8n (MCP OAuth open redirect)
137 2026‑05‑02 CVE‑2026‑7272 MCP02 — Privilege Escalation via Scope Creep matlab-mcp-server
138 2026‑05‑01 CVE‑2026‑7591 MCP05 — Command Injection & Execution astro-mcp-server (TimBroddin)
139 2026‑05‑01 CVE‑2026‑7237 MCP05 — Command Injection & Execution scaffold-mcp
140 2026‑04‑30 CVE‑2026‑7205 MCP02 — Privilege Escalation via Scope Creep papers-mcp-server
141 2026‑04‑29 CVE‑2026‑7417 MCP05 — Command Injection & Execution Algovate xhs-mcp
142 2026‑04‑29 CVE‑2026‑7061 MCP05 — Command Injection & Execution chatgpt-mcp-server
143 2026‑04‑28 CVE‑2026‑7221 MCP05 — Command Injection & Execution TencentCloudBase CloudBase-MCP
144 2026‑04‑28 CVE‑2026‑7206 MCP05 — Command Injection & Execution sqlite-mcp
145 2026‑04‑27 CVE‑2026‑7158 MCP05 — Command Injection & Execution dmitryglhf mcp-url-downloader
146 2026‑04‑27 CVE‑2026‑7157 MCP05 — Command Injection & Execution disler aider-mcp-server
147 2026‑04‑27 CVE‑2026‑7150 MCP05 — Command Injection & Execution dh1011 auto-favicon MCP server
148 2026‑04‑27 CVE‑2026‑7147 MCP05 — Command Injection & Execution JoeCastrom mcp-chat-studio
149 2026‑04‑27 CVE‑2026‑7146 MCP05 — Command Injection & Execution AlejandroArciniegas mcp-data-vis
150 2026‑04‑23 CVE‑2026‑6599 MCP05 — Command Injection & Execution Langflow
151 2026‑04‑23 CVE‑2026‑40933 MCP05 — Command Injection & Execution Flowise (MCP adapter command injection via unsafe stdio serialization)
152 2026‑04‑23 CVE‑2026‑30623 MCP05 — Command Injection & Execution LiteLLM (authenticated RCE via MCP stdio server creation)
153 2026‑04‑21 CVE‑2026‑40608 MCP07 — Insufficient Authentication & Authorization Next AI Draw.io embedded MCP HTTP sidecar
154 2026‑04‑17 CVE‑2026‑6494 MCP08 — Lack of Audit and Telemetry AAP MCP server log injection via toolsetroute
155 2026‑04‑16 CVE‑2026‑39313 MCP05 — Command Injection & Execution mcp-framework (npm)
156 2026‑04‑15 CVE‑2026‑33224 MCP09 — Shadow MCP Servers Bisheng (authenticated RCE via MCP stdio server configuration)
157 2026‑04‑15 CVE‑2026‑30635 MCP05 — Command Injection & Execution automagik-genie MCP Server (command injection)
158 2026‑04‑15 CVE‑2026‑30625 MCP09 — Shadow MCP Servers Upsonic (unauthenticated RCE via MCP server/task creation)
159 2026‑04‑15 CVE‑2026‑30624 MCP09 — Shadow MCP Servers Agent Zero (RCE via external MCP stdio JSON configuration)
160 2026‑04‑15 CVE‑2026‑30618 MCP09 — Shadow MCP Servers Fay Digital Human Framework (unauthenticated RCE via MCP adapter stdio)
161 2026‑04‑15 CVE‑2026‑30617 MCP09 — Shadow MCP Servers LangChain-ChatChat (unauthenticated RCE via MCP STDIO server configuration)
162 2026‑04‑15 CVE‑2026‑30616 MCP09 — Shadow MCP Servers Jaaz (RCE via MCP STDIO handling when network-exposed)
163 2026‑04‑15 CVE‑2026‑30615 MCP06 — Prompt Injection via Contextual Payloads Windsurf (prompt injection leading to unauthorized MCP stdio registration / local RCE)
164 2026‑04‑15 CVE‑2026‑26015 MCP09 — Shadow MCP Servers DocsGPT (RCE via tampered MCP transport switching to hidden stdio configuration)
165 2026‑04‑15 CVE‑2026‑22688 MCP09 — Shadow MCP Servers WeKnora (untrusted MCP stdio input)
166 2026‑04‑15 CVE‑2026‑22252 MCP09 — Shadow MCP Servers LibreChat (untrusted MCP stdio input; cross-referenced in OX advisory)
167 2026‑04‑15 CVE‑2026‑20205 MCP01 — Token Mismanagement & Secret Exposure Splunk MCP Server
168 2026‑04‑14 CVE‑2026‑39884 MCP05 — Command Injection & Execution mcp-server-kubernetes (port_forward argument injection)
169 2026‑04‑13 CVE‑2026‑34476 MCP05 — Command Injection & Execution Apache SkyWalking MCP SSRF via SW-URL header
170 2026‑04‑13 CVE‑2026‑27826 MCP05 — Command Injection & Execution MCP Atlassian (mcp-atlassian) (SSRF via unvalidated URL headers):mcp-atlassian (pip)
171 2026‑04‑12 CVE‑2026‑6130 MCP09 — Shadow MCP Servers Chatbox StdioClientTransport MCP config args/env code execution
172 2026‑04‑12 CVE‑2026‑6108 MCP05 — Command Injection & Execution MaxKB MCP node OS command injection
173 2026‑04‑12 CVE‑2026‑40576 MCP02 — Privilege Escalation via Scope Creep excel-mcp-server (path traversal in remote file handlers)
174 2026‑04‑11 CVE‑2026‑5833 MCP05 — Command Injection & Execution mcp-server-taskwarrior
175 2026‑04‑11 CVE‑2026‑39987 MCP05 — Command Injection & Execution Marimo Python notebook server
176 2026‑04‑10 CVE‑2026‑5059 MCP05 — Command Injection & Execution aws-mcp / aws-mcp-server (command injection)
177 2026‑04‑10 CVE‑2026‑5058 MCP07 — Insufficient Authentication & Authorization aws-mcp / aws-mcp-server (unauthenticated command injection)
178 2026‑04‑10 CVE‑2026‑40159 MCP01 — Token Mismanagement & Secret Exposure PraisonAI MCP integration:PraisonAI (pip)
179 2026‑04‑09 CVE‑2026‑39974 MCP05 — Command Injection & Execution n8n-mcp (authenticated SSRF in multi-tenant HTTP mode)
180 2026‑04‑09 CVE‑2026‑35577 MCP07 — Insufficient Authentication & Authorization Apollo MCP Server (apollo-mcp-server; Streamable HTTP Host validation)
181 2026‑04‑08 CVE‑2026‑39885 MCP05 — Command Injection & Execution FrontMCP / mcp-from-openapi (OpenAPI $ref SSRF):mcp-from-openapi (npm)
182 2026‑04‑07 CVE‑2026‑35568 MCP07 — Insufficient Authentication & Authorization MCP Java SDK (io.modelcontextprotocol.sdk):io.modelcontextprotocol.sdk:mcp-core (maven)
183 2026‑04‑07 CVE‑2026‑35402 MCP02 — Privilege Escalation via Scope Creep mcp-neo4j-cypher
184 2026‑04‑07 CVE‑2026‑34200 MCP07 — Insufficient Authentication & Authorization Nhost CLI MCP server (authentication bypass when network-exposed)
185 2026‑04‑06 CVE‑2026‑5607 MCP05 — Command Injection & Execution imprvhub mcp-browser-agent
186 2026‑04‑06 CVE‑2026‑35394 MCP05 — Command Injection & Execution @mobilenext/mobile-mcp arbitrary Android intent execution
187 2026‑04‑03 CVE‑2026‑5470 MCP05 — Command Injection & Execution Google-Research-MCP (SSRF in extractContent)
188 2026‑04‑03 CVE‑2026‑34953 MCP07 — Insufficient Authentication & Authorization PraisonAI MCP server authentication bypass
189 2026‑04‑03 CVE‑2026‑32211 MCP07 — Insufficient Authentication & Authorization Azure MCP Server
190 2026‑04‑03 CVE‑2026‑27124 MCP07 — Insufficient Authentication & Authorization FastMCP (PrefectHQ/fastmcp) (OAuth consent verification bypass / confused deputy)
191 2026‑04‑02 CVE‑2026‑5323 MCP05 — Command Injection & Execution a11y-mcp
192 2026‑04‑02 CVE‑2026‑34742 MCP07 — Insufficient Authentication & Authorization MCP Go SDK (github.com/modelcontextprotocol/go-sdk):github.com/modelcontextprotocol/go-sdk (go)
193 2026‑04‑02 CVE‑2026‑32871 MCP02 — Privilege Escalation via Scope Creep FastMCP OpenAPI Provider (SSRF + path traversal via unencoded path params)
194 2026‑03‑31 CVE‑2026‑34237 MCP07 — Insufficient Authentication & Authorization MCP Java SDK (io.modelcontextprotocol.sdk) (wildcard CORS):io.modelcontextprotocol.sdk:mcp-core (maven)
195 2026‑03‑30 CVE‑2026‑33032 MCP05 — Command Injection & Execution nginx-ui MCP integration:github.com/0xJacky/Nginx-UI (go)
196 2026‑03‑29 CVE‑2026‑5023 MCP05 — Command Injection & Execution codebase-mcp (OS command injection)
197 2026‑03‑28 CVE‑2026‑5007 MCP02 — Privilege Escalation via Scope Creep mcp-docs-rag (OS command injection)
198 2026‑03‑27 CVE‑2026‑33989 MCP02 — Privilege Escalation via Scope Creep @mobilenext/mobile-mcp
199 2026‑03‑27 CVE‑2026‑33980 MCP05 — Command Injection & Execution Azure Data Explorer MCP Server (KQL injection)
200 2026‑03‑27 CVE‑2026‑33946 MCP01 — Token Mismanagement & Secret Exposure MCP Ruby SDK (modelcontextprotocol/ruby-sdk)
201 2026‑03‑27 CVE‑2026‑32112 MCP05 — Command Injection & Execution ha-mcp (OAuth consent f-string injection)
202 2026‑03‑27 CVE‑2026‑31951 MCP01 — Token Mismanagement & Secret Exposure LibreChat
203 2026‑03‑27 CVE‑2026‑31945 MCP05 — Command Injection & Execution LibreChat MCP server-side request forgery via DNS resolution
204 2026‑03‑23 CVE‑2026‑33252 MCP07 — Insufficient Authentication & Authorization MCP Go SDK (HTTP transport cross-site tool execution / CSRF class):github.com/modelcontextprotocol/go-sdk (go)
205 2026‑03‑23 CVE‑2026‑23882 MCP05 — Command Injection & Execution Blinko MCP server creation function
206 2026‑03‑20 CVE‑2026‑4496 MCP05 — Command Injection & Execution Git-MCP-Server
207 2026‑03‑20 CVE‑2026‑33060 MCP05 — Command Injection & Execution CKAN MCP Server SSRF via base_url parameter
208 2026‑03‑20 CVE‑2026‑33010 MCP10 — Context Injection & Over-Sharing mcp-memory-service (cross-origin memory read/write/delete)
209 2026‑03‑16 CVE‑2026‑4270 MCP02 — Privilege Escalation via Scope Creep AWS API MCP Server (awslabs/mcp):awslabs.aws-api-mcp-server (pip)
210 2026‑03‑16 CVE‑2026‑4198 MCP05 — Command Injection & Execution mcp-server-auto-commit
211 2026‑03‑13 CVE‑2026‑31944 MCP07 — Insufficient Authentication & Authorization LibreChat (MCP OAuth callback account takeover)
212 2026‑03‑13 CVE‑2026‑30861 MCP09 — Shadow MCP Servers WeKnora
213 2026‑03‑13 CVE‑2026‑26118 MCP05 — Command Injection & Execution Azure MCP Server (azure.mcp) (SSRF):Azure.Mcp (nuget)
214 2026‑03‑12 CVE‑2026‑32247 MCP06 — Prompt Injection via Contextual Payloads Graphiti MCP server (getzep/graphiti)
215 2026‑03‑11 CVE‑2026‑32111 MCP05 — Command Injection & Execution ha-mcp OAuth consent ha_url SSRF
216 2026‑03‑10 CVE‑2026‑27825 MCP05 — Command Injection & Execution MCP Atlassian (mcp-atlassian) (arbitrary file write / RCE)
217 2026‑03‑07 CVE‑2026‑30856 MCP03 — Tool Poisoning WeKnora MCP tool execution hijacking via ambiguous naming
218 2026‑03‑07 CVE‑2026‑29787 MCP07 — Insufficient Authentication & Authorization mcp-memory-service (/api/health/detailed information disclosure)
219 2026‑03‑06 CVE‑2026‑29783 MCP05 — Command Injection & Execution GitHub Copilot CLI
220 2026‑02‑26 CVE‑2026‑27896 MCP04 — Software Supply Chain Attacks & Dependency Tampering MCP Go SDK (case-sensitivity / JSON-RPC parsing inconsistency):github.com/modelcontextprotocol/go-sdk (go)
221 2026‑02‑25 CVE‑2026‑27735 MCP02 — Privilege Escalation via Scope Creep mcp-server-git (git_add path traversal; stage files outside repo)
222 2026‑02‑21 CVE‑2026‑27203 MCP09 — Shadow MCP Servers eBay API MCP Server environment variable injection
223 2026‑02‑18 CVE‑2026‑25546 MCP05 — Command Injection & Execution Godot MCP
224 2026‑02‑13 CVE‑2026‑1721 MCP07 — Insufficient Authentication & Authorization Cloudflare agents SDK AI Playground OAuth callback
225 2026‑02‑10 CVE‑2026‑21518 MCP04 — Software Supply Chain Attacks & Dependency Tampering Microsoft Visual Studio Code and GitHub Copilot (mcp.json handling)
226 2026‑02‑09 CVE‑2026‑26029 MCP05 — Command Injection & Execution sf-mcp-server (command injection)
227 2026‑02‑09 CVE‑2026‑25905 MCP09 — Shadow MCP Servers mcp-run-python
228 2026‑02‑09 CVE‑2026‑25904 MCP02 — Privilege Escalation via Scope Creep mcp-run-python / Pydantic-AI MCP Run Python
229 2026‑02‑08 CVE‑2026‑2178 MCP05 — Command Injection & Execution xcode-mcp-server (command injection)
230 2026‑02‑06 CVE‑2026‑25650 MCP01 — Token Mismanagement & Secret Exposure MCP Salesforce Connector (MCP-Salesforce / mcp-salesforce-connector) (auth token disclosure):mcp-salesforce-connector (pip)
231 2026‑02‑04 CVE‑2026‑25536 MCP10 — Context Injection & Over-Sharing MCP TypeScript SDK (cross-client data leak via shared server/transport reuse)
232 2026‑01‑23 CVE‑2026‑0758 MCP05 — Command Injection & Execution mcp-server-siri-shortcuts
233 2026‑01‑22 CVE‑2026‑0757 MCP05 — Command Injection & Execution MCP Manager for Claude Desktop
234 2026‑01‑22 CVE‑2026‑0756 MCP07 — Insufficient Authentication & Authorization github-kanban-mcp-server (unauthenticated RCE / command injection)
235 2026‑01‑21 CVE‑2026‑22793 MCP05 — Command Injection & Execution 5ire MCP client (ECharts option parsing → RCE)
236 2026‑01‑21 CVE‑2026‑22792 MCP05 — Command Injection & Execution 5ire Desktop MCP client (unsafe HTML rendering → arbitrary JS execution):5ire
237 2026‑01‑21 CVE‑2026‑21852 MCP01 — Token Mismanagement & Secret Exposure Claude Code (Anthropic agentic coding tool)
238 2026‑01‑16 CVE‑2026‑23744 MCP09 — Shadow MCP Servers MCPJam Inspector (unauthenticated RCE via exposed listener)
239 2026‑01‑16 CVE‑2026‑23523 MCP09 — Shadow MCP Servers Dive MCP Host Desktop Application
240 2026‑01‑12 CVE‑2026‑22785 MCP05 — Command Injection & Execution @orval/mcp (Orval MCP server generation from OpenAPI)
241 2026‑01‑09 CVE‑2026‑0755 MCP06 — Prompt Injection via Contextual Payloads gemini-mcp-tool (command injection via unsafe shell execution)
242 2026‑01‑05 CVE‑2026‑0621 MCP05 — Command Injection & Execution MCP TypeScript SDK (UriTemplate ReDoS)

2025

S.No Date CVE OWASP MCP Top 10 (2025) Affected product
3 2025‑08‑14 CVE‑2025‑55346 MCP05 — Command Injection & Execution Flowise unsafe dynamic Function constructor remote code execution
4 2025‑06‑27 CVE‑2025‑53098 MCP09 — Shadow MCP Servers Roo Code workspace .roo/mcp.json project MCP configuration code execution
5 2026‑06‑25 CVE‑2025‑71336 MCP05 — Command Injection & Execution Flowise Custom MCP unsandboxed RCE
6 2026‑06‑22 CVE‑2025‑66336 MCP05 — Command Injection & Execution Apache Doris MCP Server SQL injection in metadata query path
7 2026‑05‑12 CVE‑2025‑69443 MCP05 — Command Injection & Execution Archon (coleam00/archon research OS / UI)
8 2026‑05‑12 CVE‑2025‑65719 MCP01 — Token Mismanagement & Secret Exposure Open Source Kubectl MCP Server
9 2026‑04‑20 CVE‑2025‑66335 MCP05 — Command Injection & Execution Apache Doris MCP Server (doris-mcp-server; PyPI) (SQL injection via MCP query interface)
10 2026‑04‑15 CVE‑2025‑65720 MCP09 — Shadow MCP Servers GPT Researcher (unauthenticated RCE via malicious MCP stdio configuration)
11 2026‑04‑15 CVE‑2025‑54136 MCP04 — Software Supply Chain Attacks & Dependency Tampering Cursor (MCP JSON / stdio exposure)
12 2026‑04‑03 CVE‑2025‑64340 MCP05 — Command Injection & Execution FastMCP (fastmcp on PyPI): Windows fastmcp install command injection
13 2026‑01‑23 CVE‑2025‑15061 MCP05 — Command Injection & Execution Framelink Figma MCP Server
14 2026‑01‑22 CVE‑2025‑15063 MCP05 — Command Injection & Execution Ollama MCP Server (execAsync command injection)
15 2026‑01‑21 CVE‑2025‑68669 MCP05 — Command Injection & Execution 5ire MCP client (Mermaid securityLevel: loose → RCE)
16 2026‑01‑12 CVE‑2025‑66689 MCP02 — Privilege Escalation via Scope Creep Zen MCP Server (path traversal)
17 2026‑01‑07 CVE‑2025‑9611 MCP07 — Insufficient Authentication & Authorization Microsoft Playwright MCP Server (@playwright/mcp):@playwright/mcp (npm)
18 2026‑01‑07 CVE‑2025‑67366 MCP02 — Privilege Escalation via Scope Creep @sylphxltd/filesystem-mcp (path traversal / symlink bypass)
19 2025‑12‑30 CVE‑2025‑69256 MCP05 — Command Injection & Execution @serverless/mcp (command injection in Serverless Framework MCP feature)
20 2025‑12‑19 CVE‑2025‑66580 MCP06 — Prompt Injection via Contextual Payloads Dive MCP Host (Mermaid XSS → malicious MCP config / RCE)
21 2025‑12‑17 CVE‑2025‑68433 MCP09 — Shadow MCP Servers Zed IDE malicious MCP settings.json arbitrary code execution
22 2025‑12‑17 CVE‑2025‑68145 MCP02 — Privilege Escalation via Scope Creep mcp-server-git (repository boundary bypass via --repository)
23 2025‑12‑17 CVE‑2025‑68144 MCP05 — Command Injection & Execution mcp-server-git (argument injection in git operations)
24 2025‑12‑17 CVE‑2025‑68143 MCP02 — Privilege Escalation via Scope Creep mcp-server-git (git_init arbitrary path)
25 2025‑12‑09 CVE‑2025‑65513 MCP01 — Token Mismanagement & Secret Exposure fetch-mcp (MCP fetch / URL retrieval server; often referenced as MCP fetch server)
26 2025‑12‑03 CVE‑2025‑66404 MCP05 — Command Injection & Execution mcp-server-kubernetes (exec_in_pod command injection)
27 2025‑12‑03 CVE‑2025‑66222 MCP09 — Shadow MCP Servers DeepChat (deepchat; Electron app) — Stored XSS in Mermaid renderer escalated to RCE via MCP server registration
28 2025‑12‑03 CVE‑2025‑64443 MCP07 — Insufficient Authentication & Authorization Docker MCP Gateway:Docker MCP Plugin / Docker MCP Gateway:github.com/docker/mcp-gateway (go)
29 2025‑12‑03 CVE‑2025‑20381 MCP05 — Command Injection & Execution Splunk MCP Server app
30 2025‑12‑02 CVE‑2025‑66454 MCP07 — Insufficient Authentication & Authorization Arcade MCP (arcade-mcp)
31 2025‑12‑02 CVE‑2025‑66416 MCP07 — Insufficient Authentication & Authorization MCP Python SDK (mcp):mcp (pip)
32 2025‑12‑02 CVE‑2025‑66414 MCP07 — Insufficient Authentication & Authorization MCP TypeScript SDK (@modelcontextprotocol/sdk):@modelcontextprotocol/sdk (npm)
33 2025‑12‑01 CVE‑2025‑66401 MCP05 — Command Injection & Execution mcp-watch (command injection via cloneRepo URL)
34 2025‑11‑30 CVE‑2025‑35028 MCP05 — Command Injection & Execution HexStrike AI MCP server
35 2025‑11‑18 CVE‑2025‑69196 MCP02 — Privilege Escalation via Scope Creep FastMCP (OAuth resource scope bypass)
36 2025‑11‑18 CVE‑2025‑64109 MCP05 — Command Injection & Execution Cursor CLI Beta (command injection class)
37 2025‑11‑18 CVE‑2025‑64106 MCP04 — Software Supply Chain Attacks & Dependency Tampering Cursor (MCP server install input validation)
38 2025‑11‑18 CVE‑2025‑63604 MCP05 — Command Injection & Execution mcp-server-aws-resources-python (code injection / AWS credential exposure)
39 2025‑11‑18 CVE‑2025‑63603 MCP05 — Command Injection & Execution MCP Data Science Server (reading-plus-ai/mcp-server-data-exploration) (unsafe exec / code execution)
40 2025‑11‑18 CVE‑2025‑56406 MCP01 — Token Mismanagement & Secret Exposure mcp-neo4j (SSE sensitive information)
41 2025‑11‑15 CVE‑2025‑61260 MCP04 — Software Supply Chain Attacks & Dependency Tampering OpenAI Codex CLI
42 2025‑11‑05 CVE‑2025‑58337 MCP02 — Privilege Escalation via Scope Creep Apache Doris MCP Server (doris-mcp-server; PyPI) (read-only mode bypass)
43 2025‑10‑29 CVE‑2025‑64132 MCP07 — Insufficient Authentication & Authorization Jenkins MCP Server Plugin (missing permission checks in multiple tools)
44 2025‑10‑28 CVE‑2025‑62801 MCP05 — Command Injection & Execution FastMCP (install cursor command injection)
45 2025‑10‑28 CVE‑2025‑62800 MCP05 — Command Injection & Execution FastMCP (reflected XSS in OAuth callback)
46 2025‑10‑28 CVE‑2025‑61591 MCP07 — Insufficient Authentication & Authorization Cursor (MCP OAuth with untrusted MCP server)
47 2025‑10‑28 CVE‑2025‑10619 MCP07 — Insufficient Authentication & Authorization sequa-ai sequa-mcp (OAuth redirect issue)
48 2025‑10‑20 CVE‑2025‑6515 MCP01 — Token Mismanagement & Secret Exposure oatpp-mcp (oatpp MCP SSE endpoint)
49 2025‑10‑17 CVE‑2025‑58747 MCP05 — Command Injection & Execution Dify MCP OAuth component
50 2025‑10‑08 CVE‑2025‑53967 MCP05 — Command Injection & Execution Framelink Figma MCP Server
51 2025‑10‑08 CVE‑2025‑11445 MCP06 — Prompt Injection via Contextual Payloads Kilo Code (AI agent IDE; ClineProvider / Prompt Handler)
52 2025‑10‑05 CVE‑2025‑11286 MCP05 — Command Injection & Execution samanhappy MCPHub
53 2025‑10‑03 CVE‑2025‑61590 MCP04 — Software Supply Chain Attacks & Dependency Tampering Cursor IDE
54 2025‑10‑03 CVE‑2025‑59944 MCP04 — Software Supply Chain Attacks & Dependency Tampering Cursor IDE
55 2025‑10‑03 CVE‑2025‑59536 MCP04 — Software Supply Chain Attacks & Dependency Tampering Claude Code (Anthropic agentic coding tool)
56 2025‑09‑30 CVE‑2025‑59956 MCP10 — Context Injection & Over-Sharing Coder agentapi (HTTP API for Claude Code, Goose, Aider, Gemini, Amp, Codex)
57 2025‑09‑29 CVE‑2025‑59163 MCP07 — Insufficient Authentication & Authorization SafeDep vet (MCP SSE server mode)
58 2025‑09‑24 CVE‑2025‑61685 MCP10 — Context Injection & Over-Sharing @mastra/mcp-docs-server (directory listing / information exposure via path traversal logic flaw)
59 2025‑09‑24 CVE‑2025‑59834 MCP05 — Command Injection & Execution adb-mcp (command injection in ADB MCP Server)
60 2025‑09‑22 CVE‑2025‑59528 MCP05 — Command Injection & Execution Flowise CustomMCP node:flowise (npm)
61 2025‑09‑18 CVE‑2025‑59417 MCP07 — Insufficient Authentication & Authorization Lobe Chat
62 2025‑09‑16 CVE‑2025‑59333 MCP02 — Privilege Escalation via Scope Creep @executeautomation/database-server (read-only mode bypass)
63 2025‑09‑15 CVE‑2025‑59377 MCP05 — Command Injection & Execution feiskyer mcp-kubernetes-server (distinct from mcp-server-kubernetes)
64 2025‑09‑15 CVE‑2025‑59155 MCP05 — Command Injection & Execution hackmd-mcp
65 2025‑09‑11 CVE‑2025‑10193 MCP07 — Insufficient Authentication & Authorization Neo4j MCP Cypher server (mcp-neo4j-cypher)
66 2025‑09‑08 CVE‑2025‑58444 MCP05 — Command Injection & Execution MCP Inspector (@modelcontextprotocol/inspector) (XSS via untrusted redirect URL)
67 2025‑09‑08 CVE‑2025‑54994 MCP04 — Software Supply Chain Attacks & Dependency Tampering @akoskm/create-mcp-server-stdio (which-app-on-port command injection via unsafe exec; also cited in OX supply-chain advisory)
68 2025‑09‑04 CVE‑2025‑58358 MCP05 — Command Injection & Execution Markdownify MCP server command injection
69 2025‑09‑04 CVE‑2025‑58357 MCP06 — Prompt Injection via Contextual Payloads 5ire MCP client (content injection via compromised MCP servers)
70 2025‑09‑03 CVE‑2025‑58176 MCP05 — Command Injection & Execution Dive MCP Host Desktop Application
71 2025‑08‑29 CVE‑2025‑9654 MCP05 — Command Injection & Execution mcp-ssh command injection
72 2025‑08‑28 CVE‑2025‑58062 MCP07 — Insufficient Authentication & Authorization LSTM-Kirigaya openmcp-client VS Code plugin
73 2025‑08‑14 CVE‑2025‑8943 MCP05 — Command Injection & Execution Flowise Custom MCPs
74 2025‑08‑13 CVE‑2025‑54382 MCP05 — Command Injection & Execution Cherry Studio
75 2025‑08‑13 CVE‑2025‑54074 MCP05 — Command Injection & Execution Cherry Studio
76 2025‑08‑06 CVE‑2025‑8665 MCP05 — Command Injection & Execution agno MCPTools/MultiMCPTools command injection
77 2025‑08‑04 CVE‑2025‑54135 MCP04 — Software Supply Chain Attacks & Dependency Tampering Cursor
78 2025‑08‑01 CVE‑2025‑54424 MCP07 — Insufficient Authentication & Authorization 1Panel MCP Server
79 2025‑07‑21 CVE‑2025‑53832 MCP05 — Command Injection & Execution Lara Translate MCP Server (@translated/lara-mcp) (npm) — command injection / RCE via child_process.exec
80 2025‑07‑18 CVE‑2025‑54073 MCP05 — Command Injection & Execution mcp-package-docs (npm)
81 2025‑07‑14 CVE‑2025‑53818 MCP05 — Command Injection & Execution GitHub Kanban MCP Server
82 2025‑07‑09 CVE‑2025‑6514 MCP01 — Token Mismanagement & Secret Exposure mcp-remote (npm)
83 2025‑07‑08 CVE‑2025‑53372 MCP05 — Command Injection & Execution node-code-sandbox-mcp (npm)
84 2025‑07‑08 CVE‑2025‑53355 MCP05 — Command Injection & Execution mcp-server-kubernetes (npm)
85 2025‑07‑04 CVE‑2025‑53366 MCP07 — Insufficient Authentication & Authorization MCP Python SDK (mcp on PyPI): validation error → unhandled exception / DoS
86 2025‑07‑04 CVE‑2025‑53365 MCP07 — Insufficient Authentication & Authorization MCP Python SDK (mcp) (DoS via unhandled exception in Streamable HTTP transport):mcp (pip)
87 2025‑07‑02 CVE‑2025‑53110 MCP02 — Privilege Escalation via Scope Creep Filesystem MCP Server (@modelcontextprotocol/server-filesystem) (prefix/path collision bypass)
88 2025‑07‑02 CVE‑2025‑53109 MCP02 — Privilege Escalation via Scope Creep Filesystem MCP Server (@modelcontextprotocol/server-filesystem) (symlink containment bypass)
89 2025‑07‑02 CVE‑2025‑34072 MCP10 — Context Injection & Over-Sharing @modelcontextprotocol/server-slack (Slack link-unfurl data exfiltration)
90 2025‑07‑01 CVE‑2025‑53107 MCP05 — Command Injection & Execution @cyanheads/git-mcp-server (npm)
91 2025‑07‑01 CVE‑2025‑53100 MCP05 — Command Injection & Execution RestDB Codehooks.io MCP Server
92 2025‑06‑26 CVE‑2025‑52573 MCP05 — Command Injection & Execution iOS Simulator MCP Server (ios-simulator-mcp)
93 2025‑06‑13 CVE‑2025‑49596 MCP05 — Command Injection & Execution MCP Inspector (@modelcontextprotocol/inspector)
94 2025‑05‑29 CVE‑2025‑5276 MCP05 — Command Injection & Execution mcp-markdownify-server SSRF via Markdownify.get()
95 2025‑05‑29 CVE‑2025‑5273 MCP02 — Privilege Escalation via Scope Creep mcp-markdownify-server path traversal via get-markdown-file
96 2025‑05‑28 CVE‑2025‑5277 MCP05 — Command Injection & Execution aws-mcp-server
97 2025‑05‑28 CVE‑2025‑4143 MCP07 — Insufficient Authentication & Authorization Cloudflare workers-mcp (OAuth implementation flaw)
98 2025‑05‑14 CVE‑2025‑47777 MCP05 — Command Injection & Execution 5ire MCP client (stored XSS → RCE)
99 2025‑05‑12 CVE‑2025‑47274 MCP01 — Token Mismanagement & Secret Exposure Stacklok ToolHive

Newly verified missing CVEs added on 2026-09-07

These CVEs were found during the September 7, 2026 internet/NVD/advisory gap review for Model Context Protocol, MCP server, GitHub Security Advisory, @modelcontextprotocol, Streamable HTTP, SSE, DNS rebinding, command injection, path traversal, STDIO RCE, and MCP configuration code-execution searches. They have been added as separate notes under [cves/](cves/). Obvious non-Model-Context-Protocol acronym collisions, such as Linux/TinyOS hardware-driver records mentioning MCP chip names, remain excluded.

Date CVE OWASP MCP Top 10 (2025) Affected product / issue
2026-09-05 CVE-2026-86122 MCP07 - Insufficient Authentication & Authorization Rowboat through 0.9.1 fails to validate custom MCP server and webhook URLs, allowing authenticated users to configure arbitrary destinations.
2026-09-04 CVE-2026-9186 MCP07 - Insufficient Authentication & Authorization IBM Langflow OSS 1.0.0 through 1.11.2 allows remote authenticated attackers to bypass localhost-only MCP configuration installation by spoofing X-Forwarded-For: 127.0.0.1 header, enabling arbitrary writes to IDE config f
2026-09-04 CVE-2026-85787 MCP07 - Insufficient Authentication & Authorization An incomplete list of disallowed inputs in the SQL validation component in Amazon awslabs postgres-mcp-server before version 1.1.7 might allow an unauthenticated actor to modify data beyond the read-only scope by placing
2026-09-04 CVE-2026-85666 MCP01 - Token Mismanagement & Secret Exposure OGX (formerly Llama Stack, affected at commit fbe8e0f) contains an unauthenticated server-side request forgery vulnerability in the OpenAI-compatible POST /v1/responses endpoint.
2026-09-04 CVE-2026-85620 MCP02 - Privilege Escalation via Scope Creep Postgres MCP Pro 0.3.0 contains a restricted-mode bypass vulnerability where function-name validation is not applied to RangeFunction nodes in FROM clauses.
2026-09-04 CVE-2026-85580 MCP01 - Token Mismanagement & Secret Exposure SiYuan versions before v3.8.2 contain a path guard bypass vulnerability in the MCP file-access handler that uses case-sensitive matching on Linux filesystems.
2026-09-04 CVE-2026-18489 MCP01 - Token Mismanagement & Secret Exposure IBM ContextForge MCP Gateway - Translate utility <= 1.0.8 MCP Context Forge could allow a remote attacker to obtain sensitive information from other sessions due to exposure of data elements to the wrong session.
2026-09-04 CVE-2026-18486 MCP01 - Token Mismanagement & Secret Exposure IBM ContextForge MCP Gateway <= v1.0.7 MCP Context Forge could allow a remote authenticated attacker to obtain sensitive credentials and escalate privileges due to improper validation of jq filters.
2026-09-03 CVE-2026-85306 MCP07 - Insufficient Authentication & Authorization Missing Authorization vulnerability in Cascadia Web Services MountDev AI MCP Connector for WordPress allows Exploiting Incorrectly Configured Access Control Security Levels.
2026-09-03 CVE-2026-85166 MCP01 - Token Mismanagement & Secret Exposure n8n before 2.35.4 and 2.36.x before 2.36.2 does not validate credential references in the inline workflow JSON of nodes that execute an inline sub-workflow (e.g., the Workflow Tool node).
2026-09-03 CVE-2026-84779 MCP07 - Insufficient Authentication & Authorization Subscriber Broken Access Control in Agentimus – AI SEO, llms.txt & MCP for AI Agents <= 1.51.0 versions.
2026-09-01 CVE-2026-84289 MCP07 - Insufficient Authentication & Authorization NousResearch hermes-agent up to 0.18.2. This vulnerability affects the function list_tools of the file tools/mcp_tool.py of the component MCP Tool.
2026-09-01 CVE-2026-81846 MCP07 - Insufficient Authentication & Authorization An authorization bypass in the runZero Platform MCP service has been resolved in version 5.1.260826.0.
2026-09-01 CVE-2026-19591 MCP06 - Prompt Injection via Contextual Payloads OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows and macOS misclassified certain PowerShell commands as safe because their command-safety parser interpreted PowerShell's stop-parsing token (--
2026-08-31 CVE-2026-82905 MCP07 - Insufficient Authentication & Authorization sdcb chats up to 1.12.0. This affects the function McpController of the file src/BE/web/Controllers/Users/Mcps/McpController.cs of the component fetch-tools Endpoint.
2026-08-31 CVE-2026-79750 MCP05 - Command Injection & Execution MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies.
2026-08-31 CVE-2026-79749 MCP07 - Insufficient Authentication & Authorization MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies.
2026-08-31 CVE-2026-79747 MCP07 - Insufficient Authentication & Authorization MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies.
2026-08-31 CVE-2026-79746 MCP07 - Insufficient Authentication & Authorization MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies.
2026-08-31 CVE-2026-79745 MCP06 - Prompt Injection via Contextual Payloads MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies.
2026-08-31 CVE-2026-79744 MCP07 - Insufficient Authentication & Authorization MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies.
2026-08-31 CVE-2026-79743 MCP02 - Privilege Escalation via Scope Creep MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies.
2026-08-29 CVE-2026-82456 MCP05 - Command Injection & Execution argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller credentials when ARGOCD_API_TOKEN is configured.
2026-08-28 CVE-2026-82233 MCP06 - Prompt Injection via Contextual Payloads SiYuan before v3.8.1 contains a path traversal vulnerability in the asset.upload MCP tool that accepts arbitrary absolute file paths without workspace boundary validation.
2026-08-28 CVE-2026-82021 MCP04 - Software Supply Chain Attacks & Dependency Tampering Hermes Agent 0.18.2 prior to 0.19.0 contains a supply chain vulnerability in its bundled MCP catalog that allows a remote attacker to execute arbitrary code by compromising a third-party upstream repository referenced vi
2026-08-28 CVE-2026-81845 MCP01 - Token Mismanagement & Secret Exposure arben-adm mcp-sequential-thinking up to 0.5.0.
2026-08-28 CVE-2026-81835 MCP06 - Prompt Injection via Contextual Payloads RooCodeInc Roo-Code up to 3.51.1. This affects the function fetch_instructions of the file malicious_mcp_server.py of the component MCP Integration Trust Model.
2026-08-27 CVE-2026-81735 MCP05 - Command Injection & Execution startServer.ts in the mcp-http-server package of UI-TARS-desktop defaulted its listen address to '::' when no host was given, so startSseAndStreamableHttpMcpServer bound the Streamable HTTP and SSE MCP transports to ever
2026-08-27 CVE-2026-81486 MCP02 - Privilege Escalation via Scope Creep bsmi021 mcp-file-context-server 1.0.0. Affected by this issue is the function read_context of the file src/index.ts of the component Path Resolution.
2026-08-27 CVE-2026-81102 MCP01 - Token Mismanagement & Secret Exposure The Dash MCP server bound its listener to the loopback address but never checked the host a request named.
2026-08-27 CVE-2026-81101 MCP01 - Token Mismanagement & Secret Exposure The configure command accepted any endpoint URL and stored it beside the user's access token.
2026-08-27 CVE-2026-81100 MCP04 - Software Supply Chain Attacks & Dependency Tampering tiger-gh-mcp-server started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides.
2026-08-27 CVE-2026-81099 MCP04 - Software Supply Chain Attacks & Dependency Tampering tiger-slack started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides.
2026-08-27 CVE-2026-81098 MCP05 - Command Injection & Execution The Telnyx MCP server exposed its HTTP transport on every interface and did not require a caller credential.
2026-08-27 CVE-2026-81097 MCP05 - Command Injection & Execution The execute_ruby tool is documented as a read-only Ruby sandbox and is enforced by a pattern denylist together with replacements for the process-spawning methods on Kernel.
2026-08-27 CVE-2026-81096 MCP05 - Command Injection & Execution ToolUniverse ran caller-supplied Python inside a sandbox that could be escaped, on a server that required no authentication.
2026-08-27 CVE-2026-81095 MCP04 - Software Supply Chain Attacks & Dependency Tampering pg-aiguide started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides.
2026-08-27 CVE-2026-81094 MCP05 - Command Injection & Execution The mcp-router CLI served its MCP aggregator on every interface and enforced authentication only when the operator asked for it.
2026-08-27 CVE-2026-81093 MCP01 - Token Mismanagement & Secret Exposure The get-html-skeleton tool fetched a URL the caller supplied after checking only its syntax.
2026-08-27 CVE-2026-81091 MCP07 - Insufficient Authentication & Authorization The proxy middleware in mcp-use's inspector forwards requests to a destination the caller names.
2026-08-26 CVE-2026-80347 MCP07 - Insufficient Authentication & Authorization mcp-fetch checks a fetch target against its SSRF guard without removing the brackets that surround an IPv6 literal.
2026-08-25 CVE-2026-79786 MCP01 - Token Mismanagement & Secret Exposure Coroot's unauthenticated MCP OAuth dynamic client registration endpoint accepts any syntactically valid redirect URI without validation, allowing attackers to register clients pointing to attacker-controlled hosts.
2026-08-25 CVE-2026-55609 MCP07 - Insufficient Authentication & Authorization sublinear-time-solver is a Rust and WebAssembly library for solving asymmetric diagonally dominant systems in sublinear time.
2026-08-25 CVE-2026-55557 MCP06 - Prompt Injection via Contextual Payloads browse-mcp is a Playwright-based headless-browser MCP server for MCP-capable agents.
2026-08-14 CVE-2026-55157 MCP05 - Command Injection & Execution Token Optimizer MCP: OS command injection in smart_user via username
2026-08-12 CVE-2026-55071 MCP05 - Command Injection & Execution MCP-for-Stata: command injection via unsanitized package in ado_package_install
2026-07-15 CVE-2026-54504 MCP07 - Insufficient Authentication & Authorization @andrea9293/mcp-documentation-server: Web UI/API binds to all interfaces by default without authentication
2026-06-18 CVE-2026-57139 MCP07 - Insufficient Authentication & Authorization npm PraisonAI MCPServer exposes unauthenticated HTTP tools/call
2026-06-18 CVE-2026-57112 MCP07 - Insufficient Authentication & Authorization PraisonAI ToolsMCPServer legacy SSE transport lacks Host/Origin validation and authentication
2026-06-06 CVE-2026-54561 MCP02 - Privilege Escalation via Scope Creep mcp-memory-keeper: arbitrary local file read in context_import via unvalidated filePath
2026-05-30 CVE-2026-55786 MCP05 - Command Injection & Execution flyto-core: unauthenticated command execution via HTTP MCP execute_module
2026-05-29 CVE-2026-35674 MCP04 - Software Supply Chain Attacks & Dependency Tampering OpenClaw before 2026.5.18 contains a scope bypass vulnerability in the Gateway chat.send route that allows scoped clients to execute privileged commands.
2026-05-27 CVE-2026-9739 MCP07 - Insufficient Authentication & Authorization Vulnerable to DNS rebinding attacks when using SSE (http://b/499408790).
2026-05-25 CVE-2026-9467 MCP05 - Command Injection & Execution debugmcp mcp-debugger up to 0.20.0. Impacted is the function handleGetSourceContext of the file src/server.ts.
2026-05-17 CVE-2026-8719 MCP04 - Software Supply Chain Attacks & Dependency Tampering The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Privilege Escalation in version 3.4.9.
2026-05-12 CVE-2026-43989 MCP07 - Insufficient Authentication & Authorization JunoClaw is an agentic AI platform built on Juno Network.
2026-05-11 CVE-2026-43995 MCP07 - Insufficient Authentication & Authorization Flowise is a drag & drop user interface to build a customized large language model flow.
2026-05-11 CVE-2026-42856 MCP01 - Token Mismanagement & Secret Exposure Network-AI is a TypeScript/Node.js multi-agent orchestrator.
2026-05-08 CVE-2026-41497 MCP05 - Command Injection & Execution PraisonAI is a multi-agent teams system. Prior to version 4.6.9, the fix for PraisonAI's MCP command handling does not add a command allowlist or argument validation to parse_mcp_command(), allowing arbitrary executables
2026-05-05 CVE-2026-7812 MCP05 - Command Injection & Execution 54yyyu code-mcp up to 4cfc4643541a110c906d93635b391bf7e357f4a8.
2026-05-05 CVE-2026-7811 MCP02 - Privilege Escalation via Scope Creep 54yyyu code-mcp up to 4cfc4643541a110c906d93635b391bf7e357f4a8.
2026-05-05 CVE-2026-7788 MCP02 - Privilege Escalation via Scope Creep Axle-Bucamp MCP-Docusaurus up to 404bc028e15ec304c9a045528560f4b5f27a17e0.
2026-05-04 CVE-2026-42235 MCP05 - Command Injection & Execution n8n is an open source workflow automation platform.
2026-05-02 CVE-2026-7645 MCP02 - Privilege Escalation via Scope Creep ruvnet sublinear-time-solver 1.5.0. Affected by this vulnerability is the function export_state of the file src/consciousness-explorer/mcp/server.js of the component MCP Interface.
2026-05-02 CVE-2026-7642 MCP05 - Command Injection & Execution pskill9 website-downloader up to 0.1.0. This affects the function download_website of the file src/index.ts of the component MCP Interface.
2026-04-30 CVE-2026-7445 MCP05 - Command Injection & Execution ZachHandley ZMCPTools up to 0.2.2. Affected by this issue is some unknown functionality of the file src/managers/ResourceManager.ts of the component MCP Log Resource Handler.
2026-04-29 CVE-2026-7416 MCP05 - Command Injection & Execution PolarVista xcode-mcp-server 1.0.0. This issue affects the function build_project/run_tests of the file src/index.ts of the component MCP Interface.
2026-04-29 CVE-2026-7404 MCP02 - Privilege Escalation via Scope Creep A weakness has been identified in getsimpletool mcpo-simple-server up to 0.2.0.
2026-04-28 CVE-2026-7318 MCP02 - Privilege Escalation via Scope Creep elie mcp-project 0.1.0. The affected element is the function search_papers of the file research_server.py.
2026-04-28 CVE-2026-7215 MCP05 - Command Injection & Execution egtai gmx-vmd-mcp up to 0.1.0. This issue affects the function launch_vmd_gui_tool of the file mcp_server.py of the component VMD Launch Handler.
2026-04-28 CVE-2026-7211 MCP05 - Command Injection & Execution A weakness has been identified in dvladimirov MCP up to 0.1.0.
2026-04-14 CVE-2025-13822 MCP07 - Insufficient Authentication & Authorization MCPHub in versions below 0.11.0 is vulnerable to authentication bypass.
2026-04-12 CVE-2026-6118 MCP05 - Command Injection & Execution AstrBotDevs AstrBot up to 4.22.1. Impacted is the function add_mcp_server of the file astrbot/dashboard/routes/tools.py of the component MCP Endpoint.
2026-04-08 CVE-2026-5802 MCP05 - Command Injection & Execution idachev mcp-javadc up to 1.2.4. Impacted is an unknown function of the component HTTP Interface.
2026-04-07 CVE-2026-5379 MCP07 - Insufficient Authentication & Authorization allowed MCP agents to access certificate information from outside of their authorized organization scope has been resolved.
2026-04-07 CVE-2026-5374 MCP07 - Insufficient Authentication & Authorization allowed MCP agents to access remediation and asset information from outside of the authorized organization scope has been resolved.
2026-04-06 CVE-2026-5619 MCP05 - Command Injection & Execution Braffolk mcp-summarization-functions up to 0.1.5.
2026-04-03 CVE-2026-34939 MCP07 - Insufficient Authentication & Authorization PraisonAI is a multi-agent teams system. Prior to version 4.5.90, MCPToolIndex.search_tools() compiles a caller-supplied string directly as a Python regular expression with no validation, sanitization, or timeout.
2026-04-02 CVE-2026-5322 MCP07 - Insufficient Authentication & Authorization AlejandroArciniegas mcp-data-vis bc597e391f184d2187062fd567599a3cb72adf51/de5a51525a69822290eaee569a1ab447b490746d.
2026-03-30 CVE-2026-29872 MCP05 - Command Injection & Execution A cross-session information disclosure vulnerability exists in the awesome-llm-apps project in commit e46690f99c3f08be80a9877fab52acacf7ab8251 (2026-01-19).
2026-03-23 CVE-2026-4593 MCP07 - Insufficient Authentication & Authorization erupts erupt bis 1.13.3. Affected by this vulnerability is the function EruptDataQuery of the file erupt-ai/src/main/java/xyz/erupt/ai/call/impl/EruptDataQuery.java of the component MCP Tool Interface.
2026-03-16 CVE-2026-4199 MCP05 - Command Injection & Execution bazinga012 mcp_code_executor up to 0.3.0.
2026-03-12 CVE-2026-31841 MCP07 - Insufficient Authentication & Authorization Hyperterse is a tool-first MCP framework for building AI-ready backend surfaces from declarative config.
2026-03-06 CVE-2026-29791 MCP05 - Command Injection & Execution Agentgateway is an open source data plane for agentic AI connectivity within or across any agent framework or environment.
2026-03-02 CVE-2026-28361 MCP01 - Token Mismanagement & Secret Exposure NocoDB is software for building databases as spreadsheets.
2026-02-08 CVE-2026-2130 MCP05 - Command Injection & Execution BurtTheCoder mcp-maigret up to 1.0.12. This affects an unknown part of the file src/index.ts of the component search_username.
2026-02-06 CVE-2026-1977 MCP05 - Command Injection & Execution isaacwasserman mcp-vegalite-server up to 16aefed598b8cd897b78e99b907f6e2984572c61.
2026-01-07 CVE-2025-61489 MCP05 - Command Injection & Execution A command injection vulnerability in the shell_exec function of sonirico mcp-shell v0.3.1 allows attackers to execute arbitrary commands via supplying a crafted command string.

Newly verified missing CVEs added on 2026-08-25

These CVEs were found during the August 25, 2026 internet/NVD audit and have been added as separate notes under [cves/](cves/). The Linux kernel mcp23s08 hardware-driver false positive CVE 2026-53344 remains excluded because it is not a Model Context Protocol issue.

Date CVE OWASP MCP Top 10 (2025) Affected product / issue
2026-08-25 CVE-2026-19801 MCP02 — Privilege Escalation via Scope Creep The BetterLinks – Link Shortener, Link Cloaking, Redirects, Affiliate Link Manager & MCP plugin for WordPress is vulnerable to authorization bypass in
2026-08-25 CVE-2026-55529 MCP01 — Token Mismanagement & Secret Exposure PraisonAI is a multi-agent teams system
2026-08-25 CVE-2026-55531 MCP05 — Command Injection & Execution PraisonAI is a multi-agent teams system
2026-08-25 CVE-2026-55532 MCP01 — Token Mismanagement & Secret Exposure PraisonAI is a multi-agent teams system
2026-08-25 CVE-2026-55546 MCP01 — Token Mismanagement & Secret Exposure QWED-MCP is a deterministic verification gateway for MCP
2026-08-25 CVE-2026-55580 MCP04 — Software Supply Chain Attacks & Dependency Tampering mcp-shell is an MCP server for running shell commands securely, auditably, and on demand
2026-08-25 CVE-2026-55581 MCP01 — Token Mismanagement & Secret Exposure mcp-shell is an MCP server for running shell commands securely, auditably, and on demand
2026-08-25 CVE-2026-55582 MCP05 — Command Injection & Execution mcp-shell is an MCP server for running shell commands securely, auditably, and on demand
2026-08-25 CVE-2026-55640 MCP01 — Token Mismanagement & Secret Exposure Nextcloud MCP Server is a production-ready MCP server that connects AI assistants to a Nextcloud instance
2026-08-24 CVE-2026-78430 MCP05 — Command Injection & Execution A vulnerability was detected in sworddut mcp-ffmpeg-helper 0.1.0/0.1.1/0.2.1
2026-08-22 CVE-2026-59809 MCP01 — Token Mismanagement & Secret Exposure SiYuan before v3.8.0 interpolates secret placeholders into the destination URL parameter of the http_request MCP tool, allowing attackers to exfiltrat
2026-08-22 CVE-2026-60083 MCP01 — Token Mismanagement & Secret Exposure SiYuan versions before v3.8.0 contain an incomplete path blocklist in the MCP file tool that fails to restrict access to sensitive workspace files pro
2026-08-21 CVE-2026-53509 MCP05 — Command Injection & Execution CKAN MCP Server is a tool for querying CKAN open data portals
2026-08-21 CVE-2026-59279 MCP05 — Command Injection & Execution The MCP Streamable HTTP server transport (WebFlux and WebMvc variants) does not place any limit on the number of sessions it retains, and by default d
2026-08-21 CVE-2026-62674 MCP01 — Token Mismanagement & Secret Exposure Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents
2026-08-20 CVE-2026-18482 MCP05 — Command Injection & Execution Neo.mjs contains a command injection vulnerability within the FileSystemService.mjs component of the ai/mcp/server/file-system MCP server, where the c
2026-08-20 CVE-2026-72846 MCP05 — Command Injection & Execution Lightdash stores the webhook URL supplied with a scheduled delivery and later posts to it from sendWebhook in packages/backend/src/clients/GoogleChat/
2026-08-20 CVE-2026-77068 MCP02 — Privilege Escalation via Scope Creep n8n before 2.33.4 and 2.34.x before 2.34.1 contain a remote code execution vulnerability in the @n8n/workflow-sdk node-schema loader used for MCP node
2026-08-20 CVE-2026-77073 MCP01 — Token Mismanagement & Secret Exposure n8n versions before 2.34.1 contain a credential validation bypass in the MCP create_workflow_from_code tool when authentication type is set to an expr
2026-08-19 CVE-2026-75149 MCP04 — Software Supply Chain Attacks & Dependency Tampering marimo before 0.23.15 contains a code injection vulnerability in the notebook configuration handler that allows attackers to execute arbitrary command
2026-08-19 CVE-2026-76404 MCP01 — Token Mismanagement & Secret Exposure In Splunk MCP Server app versions below 1.2.1, a user who holds the "admin" Splunk role could execute arbitrary commands on the underlying operating s
2026-08-18 CVE-2026-34884 MCP05 — Command Injection & Execution SSRF via set_skywalking_url Tool and GraphQL expression injection vulnerability in Apache SkyWalking MCP
2026-08-18 CVE-2026-75130 MCP01 — Token Mismanagement & Secret Exposure Context7 through 2.1.2 contains a prompt injection vulnerability that allows attackers to execute malicious instructions in connected AI coding agents
2026-08-18 CVE-2026-75845 MCP02 — Privilege Escalation via Scope Creep ArcadeDB versions 26.4.2 through 26.7.3 contain an authorization bypass vulnerability in the set_server_setting MCP server-level tool
2026-08-18 CVE-2026-75857 MCP05 — Command Injection & Execution CodeWhale versions >= 0.8.41 and < 0.8.64 contain a vulnerability in the exec_shell_interact (alias exec_interact) tool, whose approval_requirement re
2026-08-18 CVE-2026-75858 MCP04 — Software Supply Chain Attacks & Dependency Tampering CodeWhale (packages codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain a remote code execution vulnerability in the rlm_eval tool
2026-08-17 CVE-2026-19984 MCP04 — Software Supply Chain Attacks & Dependency Tampering A flaw has been found in jkawamoto mcp-florence2 up to 0.3.13
2026-08-17 CVE-2026-71424 MCP01 — Token Mismanagement & Secret Exposure Onyx is an open-source AI platform
2026-08-17 CVE-2026-74798 MCP02 — Privilege Escalation via Scope Creep SiYuan kernel before v3.7.4 contains a path traversal vulnerability in the database_clean MCP tool
2026-08-17 CVE-2026-75060 MCP05 — Command Injection & Execution In JetBrains PyCharm before 2026.2.1 code execution was possible via unauthenticated Jupyter MCP tools
2026-08-14 CVE-2026-49986 MCP04 — Software Supply Chain Attacks & Dependency Tampering The Cortex MCP server (neuro-cortex-memory), a cross-platform persistent memory MCP, prior to version 3.17.1 treats the CLAUDE_PROJECT_DIR environ
2026-08-14 CVE-2026-50027 MCP01 — Token Mismanagement & Secret Exposure mcp-memory-service is a semantic memory layer for AI applications
2026-08-14 CVE-2026-73844 MCP05 — Command Injection & Execution CKAN MCP Server is a tool for querying CKAN open data portals
2026-08-14 CVE-2026-73845 MCP05 — Command Injection & Execution CKAN MCP Server is a tool for querying CKAN open data portals
2026-08-14 CVE-2026-73846 MCP08 — Lack of Audit and Telemetry CKAN MCP Server is a tool for querying CKAN open data portals
2026-08-13 CVE-2026-19751 MCP05 — Command Injection & Execution A flaw has been found in EnzoVezzaro mcp-dominican-layer up to 39dd373786712650097ad31db27d5c477c8f9c82
2026-08-13 CVE-2026-19752 MCP05 — Command Injection & Execution A vulnerability was found in EnzoVezzaro mcp-dominican-layer up to 39dd373786712650097ad31db27d5c477c8f9c82
2026-08-13 CVE-2026-19753 MCP05 — Command Injection & Execution A vulnerability was detected in Model Context Protocol mcp-rdf-explorer 1.0.0
2026-08-13 CVE-2026-49856 MCP05 — Command Injection & Execution @jshookmcp/jshook is an MCP server that gives AI agents tools for JavaScript analysis and security research
2026-08-13 CVE-2026-49857 MCP04 — Software Supply Chain Attacks & Dependency Tampering auth-fetch-mcp is an MCP server that lets AI assistants fetch content from authenticated web pages
2026-08-13 CVE-2026-73037 MCP01 — Token Mismanagement & Secret Exposure Next AI Draw.io 0.2.1 through 0.4.16 contains a reflected cross-site scripting vulnerability in the mcp query parameter that is interpolated without e
2026-08-13 CVE-2026-73601 MCP05 — Command Injection & Execution Flowise versions before 3.1.3 contain a remote code execution vulnerability in the Custom MCP node when CUSTOM_MCP_PROTOCOL is set to stdio, allowing
2026-08-12 CVE-2026-73296 MCP05 — Command Injection & Execution Microsoft UFO open-source framework for intelligent automation across devices and platforms
2026-08-11 CVE-2026-19516 MCP01 — Token Mismanagement & Secret Exposure A caller-supplied X-Grafana-URL request header controls the destination of mcp-grafana's outbound requests, and the grafana_api_request tool lets the
2026-08-11 CVE-2026-72768 MCP05 — Command Injection & Execution n8n versions before 2.32.1 contain a server-side request forgery protection bypass vulnerability in the MCP Client node that allows authenticated user
2026-08-09 CVE-2026-19329 MCP05 — Command Injection & Execution A vulnerability was found in andreahaku codex_mcp up to 1ff521cc6cc57cfe56ddef946c644b8534771390
2026-08-09 CVE-2026-19332 MCP05 — Command Injection & Execution A security vulnerability has been detected in NellyW8 MCP4EDA 1.0.0
2026-08-09 CVE-2026-19337 MCP05 — Command Injection & Execution A vulnerability was determined in adenot mcp-google-search up to 0.3.1
2026-08-09 CVE-2026-19338 MCP02 — Privilege Escalation via Scope Creep A vulnerability was identified in automateyournetwork MCPyATS up to 0.1.4
2026-08-08 CVE-2026-19263 MCP05 — Command Injection & Execution A vulnerability was found in INQUIRELAB mcp-bridge-api up to b30a82aa1d1d1139e0de846c41c8aadee6e06114
2026-08-08 CVE-2026-19268 MCP05 — Command Injection & Execution A vulnerability was identified in abdullah1854 MCPGateway up to 549f494a9e363f40530149de324b8097de424230
2026-08-08 CVE-2026-19270 MCP02 — Privilege Escalation via Scope Creep A security flaw has been discovered in Hulupeep mcp-ui-probe up to 0.2.0
2026-08-08 CVE-2026-19279 MCP05 — Command Injection & Execution A vulnerability was identified in MIMICLab mcp-pdf-vision 1.1.0
2026-08-07 CVE-2026-19244 MCP02 — Privilege Escalation via Scope Creep A vulnerability was detected in HKUDS nanobot up to 0.2.1
2026-08-07 CVE-2026-48039 MCP01 — Token Mismanagement & Secret Exposure Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads
2026-08-06 CVE-2026-19039 MCP05 — Command Injection & Execution A vulnerability was detected in Kino-Kafkaesque ssh-mcp-server up to 8ebbbb99b26f80ff6162fe00957c6dec73fbc5a5
2026-08-06 CVE-2026-19040 MCP05 — Command Injection & Execution A flaw has been found in MissionSquad mcp-api up to 1.11.9
2026-08-06 CVE-2026-19041 MCP04 — Software Supply Chain Attacks & Dependency Tampering A vulnerability has been found in MissionSquad mcp-api up to 1.11.8
2026-08-06 CVE-2026-67531 MCP01 — Token Mismanagement & Secret Exposure FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP)
2026-08-05 CVE-2026-17623 MCP04 — Software Supply Chain Attacks & Dependency Tampering IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper validation of the comm
2026-08-05 CVE-2026-17626 MCP01 — Token Mismanagement & Secret Exposure IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow an authenticated attacker to read, modify, or expose sensitive host files via Docker-based
2026-08-05 CVE-2026-18954 MCP02 — Privilege Escalation via Scope Creep Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server before 1.0.12 might allow an authenticated MCP clien
2026-08-05 CVE-2026-7646 MCP01 — Token Mismanagement & Secret Exposure IBM Langflow OSS 1.0.0 through 1.10.3 allows users to read arbitrary files from the server filesystem, including other users' uploaded documents, the
2026-08-05 CVE-2026-8446 MCP04 — Software Supply Chain Attacks & Dependency Tampering IBM Langflow OSS 1.0.0 through 1.10.3 contain an authentication bypass vulnerability in the Model Context Protocol (MCP) composer endpoint when mcp_co
2026-08-05 CVE-2026-9077 MCP04 — Software Supply Chain Attacks & Dependency Tampering IBM Langflow OSS 1.0.0 through 1.10.3 Langflow allows remote authenticated attackers to bypass localhost-only restrictions and write arbitrary MCP ser
2026-08-04 CVE-2026-69257 MCP05 — Command Injection & Execution Flowise is a drag & drop user interface to build a customized large language model flow
2026-08-04 CVE-2026-69263 MCP04 — Software Supply Chain Attacks & Dependency Tampering Flowise is a drag & drop user interface to build a customized large language model flow
2026-08-03 CVE-2026-18655 MCP01 — Token Mismanagement & Secret Exposure Improper restriction of intended endpoints in the RabbitMQ broker connection tools of the Amazon MQ MCP Server (awslabs.amazon-mq-mcp-server) before 2
2026-08-03 CVE-2026-66065 MCP04 — Software Supply Chain Attacks & Dependency Tampering Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to constrain behavior
2026-08-02 CVE-2026-67357 MCP01 — Token Mismanagement & Secret Exposure ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability in the MCP get_server_settings tool that leaks the arcadedb.ha.cluster
2026-08-02 CVE-2026-68578 MCP02 — Privilege Escalation via Scope Creep ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP transport, causing all engine permission checks to silently p
2026-08-01 CVE-2026-15988 MCP01 — Token Mismanagement & Secret Exposure The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,
2026-08-01 CVE-2026-67333 MCP05 — Command Injection & Execution better-auth before 1.6.13 (and pre-release builds 1.7.0-beta.0 through 1.7.0-beta.3) fail to validate the scheme of redirect_uris registered via the d
2026-08-01 CVE-2026-67336 MCP01 — Token Mismanagement & Secret Exposure better-auth versions before 1.6.11 contain insecure cryptographic defaults in the oidcProvider and mcp plugins that advertise the none algorithm and a
2026-07-31 CVE-2026-14537 MCP02 — Privilege Escalation via Scope Creep Incorrect Authorization in the direct HTTP API tool invocation endpoint in Google mcp-toolbox versions v1.3.0 and v1.4.0 allows an unauthenticated att
2026-07-31 CVE-2026-14538 MCP02 — Privilege Escalation via Scope Creep An improper authorization and security-boundary bypass vulnerability in the bigquery-execute-sql tool component of Google mcp-toolbox versions 0.16.1
2026-07-31 CVE-2026-14539 MCP05 — Command Injection & Execution An allocation of resources without limits vulnerability in the HTTP handler component of Google mcp-toolbox versions up to and including 1.4.0 allows
2026-07-31 CVE-2026-14540 MCP04 — Software Supply Chain Attacks & Dependency Tampering A Server-Side Request Forgery (SSRF) vulnerability exists in the generic HTTP source and tool components of Google mcp-toolbox versions 0.3.0 through
2026-07-31 CVE-2026-14541 MCP01 — Token Mismanagement & Secret Exposure An authentication bypass and audience confusion vulnerability exists in the Google OAuth provider component of Google mcp-toolbox version 1.4.0
2026-07-31 CVE-2026-54785 MCP02 — Privilege Escalation via Scope Creep gemini-bridge is a lightweight MCP server bridging AI agents to Google's Gemini AI via the official CLI
2026-07-30 CVE-2026-12940 MCP05 — Command Injection & Execution IBM Langflow OSS 1.0.0 through 1.10.1 are vulnerable to unauthenticated remote code execution via environment variable injection in the MCP (Model Con
2026-07-28 CVE-2026-16496 MCP01 — Token Mismanagement & Secret Exposure The terraform-mcp-server before version 1.1.0 is vulnerable to an authorization bypass in the streamable-HTTP stateful transport mode that may allow a
2026-07-28 CVE-2026-47427 MCP01 — Token Mismanagement & Secret Exposure GitHub MCP Server is GitHub's official MCP Server
2026-07-28 CVE-2026-9680 MCP05 — Command Injection & Execution Improper exposure of the MCP server in alibabacloud-rds-openapi-mcp-server allows remote attackers to invoke exposed MCP tools via network access to a
2026-07-26 CVE-2026-17433 MCP02 — Privilege Escalation via Scope Creep A vulnerability was detected in nanocoai NanoClaw up to 2.0.64
2026-07-25 CVE-2026-66012 MCP01 — Token Mismanagement & Secret Exposure SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (mod
2026-07-24 CVE-2026-66005 MCP01 — Token Mismanagement & Secret Exposure Jan through 0.8.4, fixed in commit 3e1c1e7, contains a CORS misconfiguration vulnerability in its local API server that allows network-adjacent attack
2026-07-23 CVE-2026-15015 MCP01 — Token Mismanagement & Secret Exposure The MountDev AI MCP Connector for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.6.1
2026-07-23 CVE-2026-16584 MCP01 — Token Mismanagement & Secret Exposure Improper handling of an initialization failure in AWS API MCP Server from 0.2.13 through 1.3.46 might allow an actor to bypass the user-configured sec
2026-07-23 CVE-2026-47769 MCP05 — Command Injection & Execution APIFold reads an OpenAPI 3.x or Swagger 2.x specification and generates a live, production-ready MCP server endpoint
2026-07-23 CVE-2026-63732 MCP01 — Token Mismanagement & Secret Exposure 9router 0.4.59 (fixed in 0.4.60) contains a chain of vulnerabilities: a hardcoded default password (123456) that authenticates any fresh installation,
2026-07-22 CVE-2026-44192 MCP01 — Token Mismanagement & Secret Exposure A flaw was found in the Ansible Lightspeed Model Context Protocol (MCP) server
2026-07-22 CVE-2026-65594 MCP01 — Token Mismanagement & Secret Exposure n8n before 2.29.8 and 2.30.x before 2.30.1 (affected from 2.27.0, when the OAuth 2.1 consent and token-issuance flow was introduced) does not verify t
2026-07-21 CVE-2026-15829 MCP02 — Privilege Escalation via Scope Creep A SQL injection (CWE-89) and security boundary bypass (CWE-863) vulnerability exists in the prebuilt BigQuery forecasting tool (bigquery-forecast) of
2026-07-21 CVE-2026-47394 MCP01 — Token Mismanagement & Secret Exposure PraisonAI is a multi-agent teams system
2026-07-21 CVE-2026-47708 MCP05 — Command Injection & Execution MCP-for-Stata is an MCP server for Stata to integrate Stata into an agent
2026-07-21 CVE-2026-50758 MCP05 — Command Injection & Execution Cross Site Scripting vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to execute arbitrary code via the mcp parameter
2026-07-21 CVE-2026-65056 MCP01 — Token Mismanagement & Secret Exposure mcp-webresearch 0.1.7 contains a server-side request forgery vulnerability that allows attackers to access internal network services by supplying loop
2026-07-20 CVE-2026-46555 MCP01 — Token Mismanagement & Secret Exposure WhatsApp MCP Server is a Model Context Protocol (MCP) server for WhatsApp, enabling Claude to read and send WhatsApp messages
2026-07-20 CVE-2026-55544 MCP01 — Token Mismanagement & Secret Exposure NextCRM is open-source customer relationship management (CRM) software
2026-07-20 CVE-2026-55550 MCP01 — Token Mismanagement & Secret Exposure NextCRM is open-source customer relationship management (CRM) software
2026-07-20 CVE-2026-57495 MCP02 — Privilege Escalation via Scope Creep AgenticMail gives AI agents real email addresses and phone numbers
2026-07-18 CVE-2026-16133 MCP05 — Command Injection & Execution A flaw has been found in LiuMengxuan04 MiniCode 0.1.0
2026-07-17 CVE-2026-15415 MCP02 — Privilege Escalation via Scope Creep AWS HealthOmics is a HIPAA-eligible service that fully manages the compute, storage, and workflow engine infrastructure required to run bioinformatics
2026-07-17 CVE-2026-57860 MCP04 — Software Supply Chain Attacks & Dependency Tampering ForgeCode (tailcallhq/forgecode), an AI pair-programming CLI, automatically loads and executes the MCP servers defined in a repository's .mcp.json fil
2026-07-17 CVE-2026-58195 MCP05 — Command Injection & Execution Agentic-Flow is an AI agent orchestration platform
2026-07-17 CVE-2026-62208 MCP01 — Token Mismanagement & Secret Exposure OpenClaw before 2026.6.5 could forward Authorization headers during MCP SSE redirects
2026-07-17 CVE-2026-7755 MCP04 — Software Supply Chain Attacks & Dependency Tampering IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to incomplete validation enforcement on MCP server configuration
2026-07-17 CVE-2026-9135 MCP04 — Software Supply Chain Attacks & Dependency Tampering IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc33a32d) contain a code injection vulnera
2026-07-17 CVE-2026-9810 MCP01 — Token Mismanagement & Secret Exposure The AI Copilot WordPress plugin before 1.5.4 does not bind OAuth access tokens to a WordPress user, and accepts any valid token as an administrator se
2026-07-16 CVE-2026-46512 MCP05 — Command Injection & Execution Frogman provides headless PBX control through MCP and HTTP API
2026-07-16 CVE-2026-46513 MCP01 — Token Mismanagement & Secret Exposure Frogman provides headless PBX control through MCP and HTTP API
2026-07-16 CVE-2026-46514 MCP01 — Token Mismanagement & Secret Exposure Frogman provides headless PBX control through MCP and HTTP API
2026-07-16 CVE-2026-46515 MCP01 — Token Mismanagement & Secret Exposure Frogman provides headless PBX control through MCP and HTTP API
2026-07-15 CVE-2026-15583 MCP01 — Token Mismanagement & Secret Exposure A confused-deputy flaw in Grafana MCP Server allows an unauthenticated remote attacker to exfiltrate the server's environment-configured Grafana servi
2026-07-15 CVE-2026-49353 MCP01 — Token Mismanagement & Secret Exposure 9Router is an AI router & token saver
2026-07-15 CVE-2026-49988 MCP01 — Token Mismanagement & Secret Exposure Repomix is a tool that packs repositories into AI-friendly files
2026-07-15 CVE-2026-53512 MCP01 — Token Mismanagement & Secret Exposure Better Auth is an authentication and authorization library for TypeScript
2026-07-15 CVE-2026-53518 MCP01 — Token Mismanagement & Secret Exposure Better Auth is an authentication and authorization library for TypeScript
2026-07-15 CVE-2026-54052 MCP01 — Token Mismanagement & Secret Exposure n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations
2026-07-15 CVE-2026-55608 MCP02 — Privilege Escalation via Scope Creep n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations
2026-07-15 CVE-2026-61427 MCP01 — Token Mismanagement & Secret Exposure PraisonAI before 4.6.78 exposes the MCP HTTP-stream transport without authentication by default: the CLI --api-key option defaults to None, and the se
2026-07-15 CVE-2026-62312 MCP01 — Token Mismanagement & Secret Exposure 9Router is an AI router & token saver
2026-07-14 CVE-2026-15643 MCP01 — Token Mismanagement & Secret Exposure AWS HealthLake MCP Server (awslabs.healthlake-mcp-server) is a Model Context Protocol server that enables AI assistants to interact with AWS HealthLak
2026-07-14 CVE-2026-15749 MCP02 — Privilege Escalation via Scope Creep A security flaw has been discovered in mastergo-design mastergo-magic-mcp up to 0.2.0
2026-07-14 CVE-2026-15750 MCP05 — Command Injection & Execution A weakness has been identified in mastergo-design mastergo-magic-mcp up to 0.2.0
2026-07-14 CVE-2026-15751 MCP02 — Privilege Escalation via Scope Creep A security vulnerability has been detected in mastergo-design mastergo-magic-mcp up to 0.2.0
2026-07-13 CVE-2026-58500 MCP05 — Command Injection & Execution MCP Appium is an MCP server that provides AI assistants with tools to automate mobile app testing on Android and iOS
2026-07-13 CVE-2026-61462 MCP01 — Token Mismanagement & Secret Exposure mcp-gitlab contains a path traversal vulnerability in the job_id parameter of build/index.js that allows attackers to redirect GitLab API requests to
2026-07-13 CVE-2026-62195 MCP02 — Privilege Escalation via Scope Creep OpenClaw versions 2026.5.20 before 2026.6.6 contain an authorization bypass vulnerability in the MCP loopback feature that allows lower-trust callers
2026-07-12 CVE-2026-15501 MCP04 — Software Supply Chain Attacks & Dependency Tampering A security vulnerability has been detected in AstrBotDevs AstrBot up to 4.25.2
2026-07-10 CVE-2026-54149 MCP04 — Software Supply Chain Attacks & Dependency Tampering MaxKB is an open-source AI assistant for enterprise
2026-07-09 CVE-2026-15138 MCP02 — Privilege Escalation via Scope Creep A security vulnerability has been detected in tumf mcp-text-editor up to 1.0.2
2026-07-09 CVE-2026-15189 MCP05 — Command Injection & Execution A security vulnerability has been detected in aerostackdev aerostack-mcp up to 6315dfde7df0a15aaf743f88d91347115e09ba23
2026-07-09 CVE-2026-55604 MCP02 — Privilege Escalation via Scope Creep DeepSeek MCP Server is an MCP server for DeepSeek V4
2026-07-09 CVE-2026-55605 MCP01 — Token Mismanagement & Secret Exposure DeepSeek MCP Server is an MCP server for DeepSeek V4
2026-07-09 CVE-2026-59207 MCP01 — Token Mismanagement & Secret Exposure n8n is an open source workflow automation platform
2026-07-09 CVE-2026-59726 MCP01 — Token Mismanagement & Secret Exposure Ruflo is an agent meta-harness for Claude Code and Codex
2026-07-08 CVE-2026-59723 MCP01 — Token Mismanagement & Secret Exposure Cline is an autonomous coding agent as an SDK, IDE extension, or CLI assistant
2026-07-08 CVE-2026-59822 MCP01 — Token Mismanagement & Secret Exposure LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format
2026-07-07 CVE-2026-49471 MCP05 — Command Injection & Execution Serena is a powerful MCP toolkit for coding that provides semantic retrieval and editing capabilities
2026-07-06 CVE-2026-14471 MCP05 — Command Injection & Execution Improper Neutralization of Special Elements in the metrics-service retention policy management component in Amazon mcp-gateway-registry before 1.0.13
2026-07-05 CVE-2026-14748 MCP05 — Command Injection & Execution A flaw has been found in AIAnytime Awesome-MCP-Server up to a884bb51bcd99e08e14fd712c749d55d9d9a13ab
2026-07-02 CVE-2026-52830 MCP01 — Token Mismanagement & Secret Exposure fast-mcp-telegram is a Telegram MCP Server
2026-07-01 CVE-2026-10750 MCP01 — Token Mismanagement & Secret Exposure The Royal MCP WordPress plugin before 1.4.26 does not perform capability checks on the majority of its MCP tools after token authentication, allowing

CVE Information schema (template)

Field Value
CVE / NVD CVE-YYYY-NNNNN
Date (index) YYYY-MM-DD
Affected product (index)
GHSA ID
OWASP MCP Top 10 (2025) MCP0X — …
Published / disclosed YYYY-MM-DD
Ecosystem <e.g. npm, PyPI — or omit row>
Component <specific component — or omit row>
EPSS score
CVSS score <score + version — or omit row>
CWE CWE-…
Affected versions
Fixed versions
Fix status <Patched / Unfixed / unknown / …>
Exploit status <Public advisory / PoC / …>
Notes <optional — or omit row>

Contribution Rules for This Section

Use these rules in your repository contribution guide:

A vulnerability entry must include:
- CVE ID and GHSA ID, if available.
- Affected component and version.
- Fixed version or mitigation.
- Severity and source.
- Root cause category.
- Exploit / PoC safety label.
- At least one official reference.
- Defensive notes.

Do not submit:
- Unverified rumors as confirmed CVEs.
- Working exploit payloads in the README.
- Duplicate advisories without linking aliases.
- Vulnerabilities that merely mention “MCP” but have no MCP security relevance.

from github.com/mcp-security-project/mcp-cve-project

Installing Cve Project

This server has no published package — it is built from source. Open the repository and follow its README.

▸ github.com/mcp-security-project/mcp-cve-project

FAQ

Is Cve Project MCP free?

Yes, Cve Project MCP is free — one-click install via Unyly at no cost.

Does Cve Project need an API key?

No, Cve Project runs without API keys or environment variables.

Is Cve Project hosted or self-hosted?

Self-hosted: the server runs locally on your machine via the install command above.

How do I install Cve Project in Claude Desktop, Claude Code or Cursor?

Open Cve Project on unyly.org, pick your client tab (Claude Desktop, Claude Code, Cursor) and press Install — the config is generated automatically, no JSON editing.

Related MCPs

Compare Cve Project with

Not sure what to pick?

Find your stack in 60 seconds

Author?

Embed badge for your README

Browse similar

All ai MCPs