Cve Project
БесплатноНе проверенThe Project shares all information on MCP related CVE's published
Описание
The Project shares all information on MCP related CVE's published
README
This repository is a curated index of publicly disclosed Common Vulnerabilities and Exposures (CVEs) that touch the Model Context Protocol (MCP) ecosystem: official and third-party servers, SDKs, gateways, clients, and integrations where MCP is part of the attack surface or fix scope. Each linked note under [cves/](cves/) summarizes the affected component, weakness class, and pointers for defenders and maintainers.
Coverage: 570 indexed CVEs (indexed below, newest first by disclosure-related date).
Maintained and curated by Vandana Verma Sehgal.
OWASP MCP Top 10 (2025) mapping
Indexed CVEs are mapped to the primary category in the OWASP MCP Top 10 (2025). Mappings use NVD/CWE and index summaries where available. A CVE may relate to more than one MCP risk; only the primary mapping is shown in the tables below.
| ID | Category | Count |
|---|---|---|
| MCP01 | Token Mismanagement & Secret Exposure | 92 |
| MCP02 | Privilege Escalation via Scope Creep | 75 |
| MCP03 | Tool Poisoning | 2 |
| MCP04 | Software Supply Chain Attacks & Dependency Tampering | 37 |
| MCP05 | Command Injection & Execution | 210 |
| MCP06 | Prompt Injection via Contextual Payloads | 13 |
| MCP07 | Insufficient Authentication & Authorization | 112 |
| MCP08 | Lack of Audit and Telemetry | 4 |
| MCP09 | Shadow MCP Servers | 22 |
| MCP10 | Context Injection & Over-Sharing | 5 |
CVE Breakdown
2026
| S.No | Date | CVE | OWASP MCP Top 10 (2025) | Affected product |
|---|---|---|---|---|
| 1 | 2026‑09‑04 | CVE‑2026‑77822 | MCP07 — Insufficient Authentication & Authorization | IBM ContextForge MCP Gateway (mcp-contextforge-gateway): A2A invoke DNS rebinding SSRF |
| 2 | 2026‑09‑04 | CVE‑2026‑18905 | MCP07 — Insufficient Authentication & Authorization | IBM ContextForge MCP Gateway (mcp-contextforge-gateway): tool-invocation DNS rebinding |
| 3 | 2026‑08‑31 | CVE‑2026‑79748 | MCP07 — Insufficient Authentication & Authorization | MCPHub (samanhappy/mcphub): STDIO MCP server create/update authorization gap |
| 4 | 2026‑08‑31 | CVE‑2026‑81315 | MCP07 — Insufficient Authentication & Authorization | ash_ai MCP HTTP transport DNS rebinding / X-Forwarded-Proto origin bypass |
| 5 | 2026‑08‑27 | CVE‑2026‑81092 | MCP07 — Insufficient Authentication & Authorization | mcp-go (mark3labs/mcp-go): StreamableHTTP / SSE DNS rebinding via missing Host validation |
| 6 | 2026‑08‑27 | CVE‑2026‑37006 | MCP05 — Command Injection & Execution | GPT Researcher WebSocket endpoint malicious MCP configuration RCE |
| 7 | 2026‑08‑26 | CVE‑2026‑75062 | MCP05 — Command Injection & Execution | Google langfun (langfun): default lf.query eval injection |
| 8 | 2026‑08‑25 | CVE‑2026‑45018 | MCP05 — Command Injection & Execution | Chainlit (chainlit): MCP stdio command injection via POST /mcp |
| 9 | 2026‑08‑25 | CVE‑2026‑45019 | MCP05 — Command Injection & Execution | Chainlit (chainlit): MCP SSE / streamable-http SSRF via POST /mcp |
| 10 | 2026‑08‑25 | CVE‑2026‑55637 | MCP07 — Insufficient Authentication & Authorization | genieacs-mcp: Streamable HTTP DNS rebinding on localhost listener |
| 11 | 2026‑05‑15 | CVE‑2026‑45350 | MCP02 — Privilege Escalation via Scope Creep | Open WebUI chat completion API MCP tool restriction bypass |
| 12 | 2026‑04‑23 | CVE‑2026‑41268 | MCP05 — Command Injection & Execution | Flowise Custom MCP mcpServerConfig parameter override / NODE_OPTIONS injection RCE |
| 13 | 2026‑04‑14 | CVE‑2026‑39417 | MCP05 — Command Injection & Execution | MaxKB workflow MCP node STDIO RCE (incomplete fix for CVE-2025-53928) |
| 14 | 2026‑03‑18 | GHSA‑q382‑vc8q‑7jhj | MCP04 — Software Supply Chain Attacks & Dependency Tampering | MCP Go SDK (modelcontextprotocol/go-sdk): null-Unicode JSON key override (no CVE assigned) |
| 15 | 2026‑03‑18 | CVE‑2026‑32632 | MCP07 — Insufficient Authentication & Authorization | Glances REST/WebUI MCP DNS rebinding / missing Host validation |
| 16 | 2026‑02‑03 | CVE‑2026‑24052 | MCP06 — Prompt Injection via Contextual Payloads | Claude Code (@anthropic-ai/claude-code): WebFetch trusted-domain validation bypass |
| 17 | 2026‑08‑19 | CVE‑2026‑53965 | MCP07 — Insufficient Authentication & Authorization | MCP PHP SDK (modelcontextprotocol/php-sdk): HttpTransport unbounded SSE buffer DoS |
| 18 | 2026‑08‑12 | CVE‑2026‑73498 | MCP02 — Privilege Escalation via Scope Creep | MCP Atlassian (mcp-atlassian): confluence_upload_attachment path traversal / arbitrary file read |
| 19 | 2026‑07‑30 | CVE‑2026‑67430 | MCP07 — Insufficient Authentication & Authorization | MCP Ruby SDK (modelcontextprotocol/ruby-sdk): Streamable HTTP unbounded session retention DoS |
| 20 | 2026‑07‑30 | CVE‑2026‑67431 | MCP07 — Insufficient Authentication & Authorization | MCP Ruby SDK (modelcontextprotocol/ruby-sdk): Streamable HTTP session poisoning / missing session owner binding |
| 21 | 2026‑07‑30 | CVE‑2026‑67432 | MCP07 — Insufficient Authentication & Authorization | MCP Ruby SDK (modelcontextprotocol/ruby-sdk): Streamable HTTP unbounded JSON-RPC body DoS |
| 22 | 2026‑07‑16 | CVE‑2026‑44968 | MCP05 — Command Injection & Execution | dbt-mcp: dbt CLI argument injection via node_selection / resource_type |
| 23 | 2026‑07‑16 | CVE‑2026‑44969 | MCP01 — Token Mismanagement & Secret Exposure | dbt-mcp: plaintext SQL/credentials in tool argument logs when file logging enabled |
| 24 | 2026‑07‑16 | CVE‑2026‑44970 | MCP01 — Token Mismanagement & Secret Exposure | dbt-mcp: unredacted MCP tool arguments sent to dbt Labs telemetry by default |
| 25 | 2026‑07‑17 | CVE‑2026‑50143 | MCP01 — Token Mismanagement & Secret Exposure | @apify/actors-mcp-server Actor webServerMcpPath authority injection / Apify token leak |
| 26 | 2026‑07‑15 | CVE‑2026‑59950 | MCP07 — Insufficient Authentication & Authorization | MCP Python SDK (mcp): deprecated WebSocket transport Host/Origin validation gap |
| 27 | 2026‑07‑10 | CVE‑2026‑61459 | MCP02 — Privilege Escalation via Scope Creep | mcp-server-kubernetes structured tools --server argument injection / bearer token exfiltration |
| 28 | 2026‑07‑08 | CVE‑2026‑63118 | MCP07 — Insufficient Authentication & Authorization | MCP Ruby SDK (modelcontextprotocol/ruby-sdk): Streamable HTTP DNS rebinding |
| 29 | 2026‑07‑08 | CVE‑2026‑63119 | MCP07 — Insufficient Authentication & Authorization | MCP Ruby SDK (modelcontextprotocol/ruby-sdk): stdio unbounded line buffer DoS |
| 30 | 2026‑07‑03 | CVE‑2026‑13341 | MCP06 — Prompt Injection via Contextual Payloads | Kong Konnect MCP server (mcp-konnect) indirect prompt injection |
| 31 | 2026‑06‑30 | CVE‑2026‑7663 | MCP07 — Insufficient Authentication & Authorization | IBM Langflow Streamable MCP authorization bypass |
| 32 | 2026‑06‑30 | CVE‑2026‑58446 | MCP07 — Insufficient Authentication & Authorization | Presenton bundled MCP server unauthenticated /mcp access |
| 33 | 2026‑06‑30 | CVE‑2026‑58171 | MCP02 — Privilege Escalation via Scope Creep | Vibe-Trading path traversal affecting MCP/agent workflow storage |
| 34 | 2026‑06‑30 | CVE‑2026‑58168 | MCP07 — Insufficient Authentication & Authorization | DeepTutor MCP tool authorization bypass |
| 35 | 2026‑06‑29 | CVE‑2026‑13524 | MCP07 — Insufficient Authentication & Authorization | Cherry Studio MCP OAuth local callback issue |
| 36 | 2026‑06‑28 | CVE‑2026‑58057 | MCP05 — Command Injection & Execution | Flowise Custom MCP Windows env-var denylist bypass |
| 37 | 2026‑06‑28 | CVE‑2026‑13489 | MCP07 — Insufficient Authentication & Authorization | xiaozhi-esp32 MCP response handler validation issue |
| 38 | 2026‑06‑26 | CVE‑2026‑57922 | MCP01 — Token Mismanagement & Secret Exposure | JetBrains YouTrack project settings disclosure via MCP |
| 39 | 2026‑06‑26 | CVE‑2026‑48529 | MCP02 — Privilege Escalation via Scope Creep | GitHub MCP Server HTTP lockdown-mode repo access cache issue |
| 40 | 2026‑06‑26 | CVE‑2026‑4339 | MCP05 — Command Injection & Execution | Mattermost Agents plugin MCP server internal/private IP validation issue |
| 41 | 2026‑06‑25 | CVE‑2026‑54842 | MCP07 — Insufficient Authentication & Authorization | Royal MCP missing authorization |
| 42 | 2026‑06‑25 | CVE‑2026‑54030 | MCP07 — Insufficient Authentication & Authorization | LibreChat MCP OAuth resource validation issue |
| 43 | 2026‑06‑24 | CVE‑2026‑57300 | MCP07 — Insufficient Authentication & Authorization | Jenkins MCP Server Plugin missing permission check |
| 44 | 2026‑06‑24 | CVE‑2026‑53766 | MCP02 — Privilege Escalation via Scope Creep | chrome-devtools-mcp workspace path validation issue |
| 45 | 2026‑06‑24 | CVE‑2026‑12958 | MCP02 — Privilege Escalation via Scope Creep | Amazon Q Developer / Language Servers for AWS (symlink write outside workspace trust boundary) |
| 46 | 2026‑06‑24 | CVE‑2026‑12957 | MCP09 — Shadow MCP Servers | Amazon Q Developer / Language Servers for AWS (.amazonq/mcp.json auto-execution) |
| 47 | 2026‑06‑24 | CVE‑2026‑12537 | MCP09 — Shadow MCP Servers | Google Gemini CLI / run-gemini-cli GitHub Action |
| 48 | 2026‑06‑23 | CVE‑2026‑56274 | MCP05 — Command Injection & Execution | Flowise Custom MCP Server command injection |
| 49 | 2026‑06‑23 | CVE‑2026‑54309 | MCP07 — Insufficient Authentication & Authorization | @n8n/mcp-browser unauthenticated HTTP transport |
| 50 | 2026‑06‑23 | CVE‑2026‑47388 | MCP02 — Privilege Escalation via Scope Creep | NocoDB MCP token attachment ownership bypass / file read |
| 51 | 2026‑06‑23 | CVE‑2026‑46549 | MCP02 — Privilege Escalation via Scope Creep | NocoDB MCP OAuth token scope bypass |
| 52 | 2026‑06‑23 | CVE‑2026‑12112 | MCP07 — Insufficient Authentication & Authorization | foreman-mcp-server session hijack via non-secret session IDs |
| 53 | 2026‑06‑22 | CVE‑2026‑7664 | MCP07 — Insufficient Authentication & Authorization | IBM Langflow Streamable MCP authorization bypass |
| 54 | 2026‑06‑22 | CVE‑2026‑10789 | MCP05 — Command Injection & Execution | Autodesk Fusion Desktop MCP extension arbitrary code execution |
| 55 | 2026‑06‑21 | CVE‑2026‑12798 | MCP05 — Command Injection & Execution | LiteLLM OpenAPI-to-MCP generator SSRF |
| 56 | 2026‑06‑21 | CVE‑2026‑12774 | MCP05 — Command Injection & Execution | LiteLLM MCP connection testing SSRF |
| 57 | 2026‑06‑21 | CVE‑2026‑12773 | MCP07 — Insufficient Authentication & Authorization | LiteLLM MCP Proxy improper authentication |
| 58 | 2026‑06‑19 | CVE‑2026‑49357 | MCP07 — Insufficient Authentication & Authorization | line-desktop-mcp unauthenticated HTTP mode chat access |
| 59 | 2026‑06‑19 | CVE‑2026‑49291 | MCP02 — Privilege Escalation via Scope Creep | mcp-memory-service OAuth read-scope tools/call bypass |
| 60 | 2026‑06‑19 | CVE‑2026‑48787 | MCP05 — Command Injection & Execution | gin-vue-admin MCP management code-generation command injection |
| 61 | 2026‑06‑19 | CVE‑2026‑48774 | MCP02 — Privilege Escalation via Scope Creep | ProxySQL GenAI/MCP run_sql_readonly multi-statement bypass |
| 62 | 2026‑06‑18 | CVE‑2026‑55887 | MCP05 — Command Injection & Execution | Docker MCP Gateway (github.com/docker/mcp-gateway) |
| 63 | 2026‑06‑18 | CVE‑2026‑49257 | MCP07 — Insufficient Authentication & Authorization | mcp-pinot unauthenticated 0.0.0.0 HTTP MCP server |
| 64 | 2026‑06‑18 | CVE‑2026‑11719 | MCP02 — Privilege Escalation via Scope Creep | MCP Toolbox for Databases protocol-version scope bypass |
| 65 | 2026‑06‑17 | CVE‑2026‑48989 | MCP07 — Insufficient Authentication & Authorization | Windows-MCP unauthenticated HTTP control plane / PowerShell execution |
| 66 | 2026‑06‑17 | CVE‑2026‑48814 | MCP07 — Insufficient Authentication & Authorization | Network-AI MCP SSE unauthenticated tool invocation |
| 67 | 2026‑06‑16 | CVE‑2026‑53840 | MCP01 — Token Mismanagement & Secret Exposure | OpenClaw Streamable HTTP MCP custom-header leak on redirects |
| 68 | 2026‑06‑15 | CVE‑2026‑40775 | MCP07 — Insufficient Authentication & Authorization | Royal MCP unauthenticated broken access control |
| 69 | 2026‑06‑13 | CVE‑2026‑11624 | MCP07 — Insufficient Authentication & Authorization | MCP Origin/Host validation gap for DNS rebinding controls |
| 70 | 2026‑06‑12 | CVE‑2026‑53820 | MCP05 — Command Injection & Execution | OpenClaw bundled MCP exec denylist bypass |
| 71 | 2026‑06‑12 | CVE‑2026‑50287 | MCP07 — Insufficient Authentication & Authorization | @agenticmail/mcp unauthenticated Streamable HTTP endpoint |
| 72 | 2026‑06‑11 | CVE‑2026‑53818 | MCP07 — Insufficient Authentication & Authorization | OpenClaw MCP loopback owner-only policy bypass |
| 73 | 2026‑06‑11 | CVE‑2026‑53814 | MCP02 — Privilege Escalation via Scope Creep | OpenClaw hook-triggered MCP loopback privilege escalation |
| 74 | 2026‑06‑11 | CVE‑2026‑47250 | MCP02 — Privilege Escalation via Scope Creep | mcp-server-kubernetes kubectl_generic unsafe flags / token exfiltration |
| 75 | 2026‑06‑05 | CVE‑2026‑52869 | MCP07 — Insufficient Authentication & Authorization | MCP Python SDK (mcp): HTTP session auth bypass (SseServerTransport / Streamable HTTP) |
| 76 | 2026‑06‑05 | CVE‑2026‑52870 | MCP07 — Insufficient Authentication & Authorization | MCP Python SDK (mcp): experimental task handlers cross-client access |
| 77 | 2026‑06‑04 | CVE‑2026‑54449 | MCP09 — Shadow MCP Servers | LangBot |
| 78 | 2026‑06‑02 | CVE‑2026‑44653 | MCP07 — Insufficient Authentication & Authorization | LibreChat — GET /api/mcp/servers returns plaintext apiKey.key and oauth.client_secret to VIEW-only users |
| 79 | 2026‑06‑02 | CVE‑2026‑42073 | MCP07 — Insufficient Authentication & Authorization | OpenClaude MCP OAuth callback CSRF state bypass / DoS |
| 80 | 2026‑06‑02 | CVE‑2026‑32625 | MCP01 — Token Mismanagement & Secret Exposure | LibreChat — MCP server URL ${VAR} interpolation exfiltrates JWT_SECRET, CREDS_KEY, CREDS_IV, MONGO_URI |
| 81 | 2026‑06‑01 | CVE‑2026‑10280 | MCP05 — Command Injection & Execution | mcpilot MCP API call endpoint SSRF via serverBaseUrl |
| 82 | 2026‑06‑01 | CVE‑2026‑10277 | MCP02 — Privilege Escalation via Scope Creep | mcp-google-workspace Gmail saveToDisk improper access controls |
| 83 | 2026‑05‑29 | CVE‑2026‑47751 | MCP04 — Software Supply Chain Attacks & Dependency Tampering | Anthropic Claude Code Action (claude-code-action) |
| 84 | 2026‑05‑29 | CVE‑2026‑45707 | MCP07 — Insufficient Authentication & Authorization | n8n-mcp multi-tenant HTTP transport authentication gap |
| 85 | 2026‑05‑29 | CVE‑2026‑45609 | MCP05 — Command Injection & Execution | Spring AI mcp-security missing MCP-spec SSRF mitigations |
| 86 | 2026‑05‑29 | CVE‑2026‑45582 | MCP01 — Token Mismanagement & Secret Exposure | n8n-MCP (czlonkowski/n8n-mcp) |
| 87 | 2026‑05‑29 | CVE‑2026‑45555 | MCP05 — Command Injection & Execution | Roslyn CodeLens MCP Server arbitrary DiagnosticAnalyzer load |
| 88 | 2026‑05‑26 | CVE‑2026‑48710 | MCP07 — Insufficient Authentication & Authorization | Starlette / FastAPI-based MCP and AI gateways |
| 89 | 2026‑05‑19 | CVE‑2026‑46341 | MCP02 — Privilege Escalation via Scope Creep | @apify/actors-mcp-server |
| 90 | 2026‑05‑19 | CVE‑2026‑46339 | MCP07 — Insufficient Authentication & Authorization | 9router MCP routes |
| 91 | 2026‑05‑19 | CVE‑2026‑45805 | MCP07 — Insufficient Authentication & Authorization | @penpot/mcp |
| 92 | 2026‑05‑18 | CVE‑2026‑46519 | MCP02 — Privilege Escalation via Scope Creep | mcp-server-kubernetes |
| 93 | 2026‑05‑15 | CVE‑2026‑44717 | MCP05 — Command Injection & Execution | MCP Calculate Server |
| 94 | 2026‑05‑14 | CVE‑2026‑44895 | MCP07 — Insufficient Authentication & Authorization | GitLab MCP Server (HTTP transport without authentication) |
| 95 | 2026‑05‑14 | CVE‑2026‑44830 | MCP07 — Insufficient Authentication & Authorization | Nocturne Memory MCP server (missing auth when token unset) |
| 96 | 2026‑05‑14 | CVE‑2026‑44284 | MCP05 — Command Injection & Execution | FastGPT (MCP tool URL SSRF gap) |
| 97 | 2026‑05‑14 | CVE‑2026‑42559 | MCP07 — Insufficient Authentication & Authorization | MCP Rust SDK (rmcp crate): Streamable HTTP server transport DNS rebinding |
| 98 | 2026‑05‑14 | CVE‑2026‑34163 | MCP07 — Insufficient Authentication & Authorization | FastGPT (MCP tools endpoint auth gap) |
| 99 | 2026‑05‑12 | CVE‑2026‑5029 | MCP07 — Insufficient Authentication & Authorization | Code Runner MCP Server |
| 100 | 2026‑05‑12 | CVE‑2026‑45781 | MCP02 — Privilege Escalation via Scope Creep | MCP Registry |
| 101 | 2026‑05‑12 | CVE‑2026‑43992 | MCP01 — Token Mismanagement & Secret Exposure | JunoClaw |
| 102 | 2026‑05‑12 | CVE‑2026‑42260 | MCP05 — Command Injection & Execution | Open-WebSearch MCP server |
| 103 | 2026‑05‑11 | CVE‑2026‑45001 | MCP04 — Software Supply Chain Attacks & Dependency Tampering | OpenClaw |
| 104 | 2026‑05‑11 | CVE‑2026‑44998 | MCP03 — Tool Poisoning | OpenClaw |
| 105 | 2026‑05‑11 | CVE‑2026‑44995 | MCP05 — Command Injection & Execution | OpenClaw |
| 106 | 2026‑05‑11 | CVE‑2026‑44450 | MCP05 — Command Injection & Execution | Lumiverse (MCP server command allowlist bypass) |
| 107 | 2026‑05‑11 | CVE‑2026‑44430 | MCP05 — Command Injection & Execution | MCP Registry |
| 108 | 2026‑05‑11 | CVE‑2026‑44429 | MCP05 — Command Injection & Execution | MCP Registry |
| 109 | 2026‑05‑11 | CVE‑2026‑44428 | MCP07 — Insufficient Authentication & Authorization | MCP Registry |
| 110 | 2026‑05‑11 | CVE‑2026‑44427 | MCP07 — Insufficient Authentication & Authorization | MCP Registry |
| 111 | 2026‑05‑11 | CVE‑2026‑43901 | MCP02 — Privilege Escalation via Scope Creep | Wireshark MCP (wireshark-mcp) |
| 112 | 2026‑05‑10 | CVE‑2026‑7738 | MCP02 — Privilege Escalation via Scope Creep | doc-tools-mcp |
| 113 | 2026‑05‑09 | CVE‑2026‑7729 | MCP05 — Command Injection & Execution | directus-mcp |
| 114 | 2026‑05‑09 | CVE‑2026‑7728 | MCP02 — Privilege Escalation via Scope Creep | mcp-rtfm |
| 115 | 2026‑05‑09 | CVE‑2026‑7715 | MCP02 — Privilege Escalation via Scope Creep | mcp-server-arangodb |
| 116 | 2026‑05‑08 | CVE‑2026‑7653 | MCP05 — Command Injection & Execution | mcp-server-rijksmuseum |
| 117 | 2026‑05‑08 | CVE‑2026‑7628 | MCP05 — Command Injection & Execution | mcp-code-review-server |
| 118 | 2026‑05‑08 | CVE‑2026‑7627 | MCP02 — Privilege Escalation via Scope Creep | metatrader-4-mcp |
| 119 | 2026‑05‑08 | CVE‑2026‑44694 | MCP05 — Command Injection & Execution | n8n-mcp |
| 120 | 2026‑05‑08 | CVE‑2026‑44336 | MCP05 — Command Injection & Execution | PraisonAI MCP tools/call path traversal to RCE via .pth injection |
| 121 | 2026‑05‑08 | CVE‑2026‑42282 | MCP08 — Lack of Audit and Telemetry | n8n-mcp |
| 122 | 2026‑05‑08 | CVE‑2026‑42271 | MCP05 — Command Injection & Execution | LiteLLM MCP server preview endpoints |
| 123 | 2026‑05‑08 | CVE‑2026‑41495 | MCP08 — Lack of Audit and Telemetry | n8n-mcp |
| 124 | 2026‑05‑07 | CVE‑2026‑7600 | MCP05 — Command Injection & Execution | mcp-server-yii2 |
| 125 | 2026‑05‑07 | CVE‑2026‑7599 | MCP05 — Command Injection & Execution | terminalcraft |
| 126 | 2026‑05‑07 | CVE‑2026‑7594 | MCP02 — Privilege Escalation via Scope Creep | DungeonMind-MCP |
| 127 | 2026‑05‑07 | CVE‑2026‑7593 | MCP05 — Command Injection & Execution | command-executor-mcp-server |
| 128 | 2026‑05‑07 | CVE‑2026‑42449 | MCP05 — Command Injection & Execution | n8n-mcp |
| 129 | 2026‑05‑06 | CVE‑2026‑7446 | MCP05 — Command Injection & Execution | mcp-server-semgrep |
| 130 | 2026‑05‑06 | CVE‑2026‑7443 | MCP05 — Command Injection & Execution | mcp-dnstwist |
| 131 | 2026‑05‑06 | CVE‑2026‑44118 | MCP07 — Insufficient Authentication & Authorization | OpenClaw (loopback MCP owner-context spoofing) |
| 132 | 2026‑05‑05 | CVE‑2026‑7386 | MCP05 — Command Injection & Execution | mail-mcp-bridge |
| 133 | 2026‑05‑05 | CVE‑2026‑35228 | MCP05 — Command Injection & Execution | Oracle MCP Server Helper Tool (SQL injection) |
| 134 | 2026‑05‑04 | CVE‑2026‑7730 | MCP05 — Command Injection & Execution | privsim/mcp-test-runner |
| 135 | 2026‑05‑04 | CVE‑2026‑42236 | MCP07 — Insufficient Authentication & Authorization | n8n (MCP OAuth client registration DoS) |
| 136 | 2026‑05‑04 | CVE‑2026‑42230 | MCP07 — Insufficient Authentication & Authorization | n8n (MCP OAuth open redirect) |
| 137 | 2026‑05‑02 | CVE‑2026‑7272 | MCP02 — Privilege Escalation via Scope Creep | matlab-mcp-server |
| 138 | 2026‑05‑01 | CVE‑2026‑7591 | MCP05 — Command Injection & Execution | astro-mcp-server (TimBroddin) |
| 139 | 2026‑05‑01 | CVE‑2026‑7237 | MCP05 — Command Injection & Execution | scaffold-mcp |
| 140 | 2026‑04‑30 | CVE‑2026‑7205 | MCP02 — Privilege Escalation via Scope Creep | papers-mcp-server |
| 141 | 2026‑04‑29 | CVE‑2026‑7417 | MCP05 — Command Injection & Execution | Algovate xhs-mcp |
| 142 | 2026‑04‑29 | CVE‑2026‑7061 | MCP05 — Command Injection & Execution | chatgpt-mcp-server |
| 143 | 2026‑04‑28 | CVE‑2026‑7221 | MCP05 — Command Injection & Execution | TencentCloudBase CloudBase-MCP |
| 144 | 2026‑04‑28 | CVE‑2026‑7206 | MCP05 — Command Injection & Execution | sqlite-mcp |
| 145 | 2026‑04‑27 | CVE‑2026‑7158 | MCP05 — Command Injection & Execution | dmitryglhf mcp-url-downloader |
| 146 | 2026‑04‑27 | CVE‑2026‑7157 | MCP05 — Command Injection & Execution | disler aider-mcp-server |
| 147 | 2026‑04‑27 | CVE‑2026‑7150 | MCP05 — Command Injection & Execution | dh1011 auto-favicon MCP server |
| 148 | 2026‑04‑27 | CVE‑2026‑7147 | MCP05 — Command Injection & Execution | JoeCastrom mcp-chat-studio |
| 149 | 2026‑04‑27 | CVE‑2026‑7146 | MCP05 — Command Injection & Execution | AlejandroArciniegas mcp-data-vis |
| 150 | 2026‑04‑23 | CVE‑2026‑6599 | MCP05 — Command Injection & Execution | Langflow |
| 151 | 2026‑04‑23 | CVE‑2026‑40933 | MCP05 — Command Injection & Execution | Flowise (MCP adapter command injection via unsafe stdio serialization) |
| 152 | 2026‑04‑23 | CVE‑2026‑30623 | MCP05 — Command Injection & Execution | LiteLLM (authenticated RCE via MCP stdio server creation) |
| 153 | 2026‑04‑21 | CVE‑2026‑40608 | MCP07 — Insufficient Authentication & Authorization | Next AI Draw.io embedded MCP HTTP sidecar |
| 154 | 2026‑04‑17 | CVE‑2026‑6494 | MCP08 — Lack of Audit and Telemetry | AAP MCP server log injection via toolsetroute |
| 155 | 2026‑04‑16 | CVE‑2026‑39313 | MCP05 — Command Injection & Execution | mcp-framework (npm) |
| 156 | 2026‑04‑15 | CVE‑2026‑33224 | MCP09 — Shadow MCP Servers | Bisheng (authenticated RCE via MCP stdio server configuration) |
| 157 | 2026‑04‑15 | CVE‑2026‑30635 | MCP05 — Command Injection & Execution | automagik-genie MCP Server (command injection) |
| 158 | 2026‑04‑15 | CVE‑2026‑30625 | MCP09 — Shadow MCP Servers | Upsonic (unauthenticated RCE via MCP server/task creation) |
| 159 | 2026‑04‑15 | CVE‑2026‑30624 | MCP09 — Shadow MCP Servers | Agent Zero (RCE via external MCP stdio JSON configuration) |
| 160 | 2026‑04‑15 | CVE‑2026‑30618 | MCP09 — Shadow MCP Servers | Fay Digital Human Framework (unauthenticated RCE via MCP adapter stdio) |
| 161 | 2026‑04‑15 | CVE‑2026‑30617 | MCP09 — Shadow MCP Servers | LangChain-ChatChat (unauthenticated RCE via MCP STDIO server configuration) |
| 162 | 2026‑04‑15 | CVE‑2026‑30616 | MCP09 — Shadow MCP Servers | Jaaz (RCE via MCP STDIO handling when network-exposed) |
| 163 | 2026‑04‑15 | CVE‑2026‑30615 | MCP06 — Prompt Injection via Contextual Payloads | Windsurf (prompt injection leading to unauthorized MCP stdio registration / local RCE) |
| 164 | 2026‑04‑15 | CVE‑2026‑26015 | MCP09 — Shadow MCP Servers | DocsGPT (RCE via tampered MCP transport switching to hidden stdio configuration) |
| 165 | 2026‑04‑15 | CVE‑2026‑22688 | MCP09 — Shadow MCP Servers | WeKnora (untrusted MCP stdio input) |
| 166 | 2026‑04‑15 | CVE‑2026‑22252 | MCP09 — Shadow MCP Servers | LibreChat (untrusted MCP stdio input; cross-referenced in OX advisory) |
| 167 | 2026‑04‑15 | CVE‑2026‑20205 | MCP01 — Token Mismanagement & Secret Exposure | Splunk MCP Server |
| 168 | 2026‑04‑14 | CVE‑2026‑39884 | MCP05 — Command Injection & Execution | mcp-server-kubernetes (port_forward argument injection) |
| 169 | 2026‑04‑13 | CVE‑2026‑34476 | MCP05 — Command Injection & Execution | Apache SkyWalking MCP SSRF via SW-URL header |
| 170 | 2026‑04‑13 | CVE‑2026‑27826 | MCP05 — Command Injection & Execution | MCP Atlassian (mcp-atlassian) (SSRF via unvalidated URL headers):mcp-atlassian (pip) |
| 171 | 2026‑04‑12 | CVE‑2026‑6130 | MCP09 — Shadow MCP Servers | Chatbox StdioClientTransport MCP config args/env code execution |
| 172 | 2026‑04‑12 | CVE‑2026‑6108 | MCP05 — Command Injection & Execution | MaxKB MCP node OS command injection |
| 173 | 2026‑04‑12 | CVE‑2026‑40576 | MCP02 — Privilege Escalation via Scope Creep | excel-mcp-server (path traversal in remote file handlers) |
| 174 | 2026‑04‑11 | CVE‑2026‑5833 | MCP05 — Command Injection & Execution | mcp-server-taskwarrior |
| 175 | 2026‑04‑11 | CVE‑2026‑39987 | MCP05 — Command Injection & Execution | Marimo Python notebook server |
| 176 | 2026‑04‑10 | CVE‑2026‑5059 | MCP05 — Command Injection & Execution | aws-mcp / aws-mcp-server (command injection) |
| 177 | 2026‑04‑10 | CVE‑2026‑5058 | MCP07 — Insufficient Authentication & Authorization | aws-mcp / aws-mcp-server (unauthenticated command injection) |
| 178 | 2026‑04‑10 | CVE‑2026‑40159 | MCP01 — Token Mismanagement & Secret Exposure | PraisonAI MCP integration:PraisonAI (pip) |
| 179 | 2026‑04‑09 | CVE‑2026‑39974 | MCP05 — Command Injection & Execution | n8n-mcp (authenticated SSRF in multi-tenant HTTP mode) |
| 180 | 2026‑04‑09 | CVE‑2026‑35577 | MCP07 — Insufficient Authentication & Authorization | Apollo MCP Server (apollo-mcp-server; Streamable HTTP Host validation) |
| 181 | 2026‑04‑08 | CVE‑2026‑39885 | MCP05 — Command Injection & Execution | FrontMCP / mcp-from-openapi (OpenAPI $ref SSRF):mcp-from-openapi (npm) |
| 182 | 2026‑04‑07 | CVE‑2026‑35568 | MCP07 — Insufficient Authentication & Authorization | MCP Java SDK (io.modelcontextprotocol.sdk):io.modelcontextprotocol.sdk:mcp-core (maven) |
| 183 | 2026‑04‑07 | CVE‑2026‑35402 | MCP02 — Privilege Escalation via Scope Creep | mcp-neo4j-cypher |
| 184 | 2026‑04‑07 | CVE‑2026‑34200 | MCP07 — Insufficient Authentication & Authorization | Nhost CLI MCP server (authentication bypass when network-exposed) |
| 185 | 2026‑04‑06 | CVE‑2026‑5607 | MCP05 — Command Injection & Execution | imprvhub mcp-browser-agent |
| 186 | 2026‑04‑06 | CVE‑2026‑35394 | MCP05 — Command Injection & Execution | @mobilenext/mobile-mcp arbitrary Android intent execution |
| 187 | 2026‑04‑03 | CVE‑2026‑5470 | MCP05 — Command Injection & Execution | Google-Research-MCP (SSRF in extractContent) |
| 188 | 2026‑04‑03 | CVE‑2026‑34953 | MCP07 — Insufficient Authentication & Authorization | PraisonAI MCP server authentication bypass |
| 189 | 2026‑04‑03 | CVE‑2026‑32211 | MCP07 — Insufficient Authentication & Authorization | Azure MCP Server |
| 190 | 2026‑04‑03 | CVE‑2026‑27124 | MCP07 — Insufficient Authentication & Authorization | FastMCP (PrefectHQ/fastmcp) (OAuth consent verification bypass / confused deputy) |
| 191 | 2026‑04‑02 | CVE‑2026‑5323 | MCP05 — Command Injection & Execution | a11y-mcp |
| 192 | 2026‑04‑02 | CVE‑2026‑34742 | MCP07 — Insufficient Authentication & Authorization | MCP Go SDK (github.com/modelcontextprotocol/go-sdk):github.com/modelcontextprotocol/go-sdk (go) |
| 193 | 2026‑04‑02 | CVE‑2026‑32871 | MCP02 — Privilege Escalation via Scope Creep | FastMCP OpenAPI Provider (SSRF + path traversal via unencoded path params) |
| 194 | 2026‑03‑31 | CVE‑2026‑34237 | MCP07 — Insufficient Authentication & Authorization | MCP Java SDK (io.modelcontextprotocol.sdk) (wildcard CORS):io.modelcontextprotocol.sdk:mcp-core (maven) |
| 195 | 2026‑03‑30 | CVE‑2026‑33032 | MCP05 — Command Injection & Execution | nginx-ui MCP integration:github.com/0xJacky/Nginx-UI (go) |
| 196 | 2026‑03‑29 | CVE‑2026‑5023 | MCP05 — Command Injection & Execution | codebase-mcp (OS command injection) |
| 197 | 2026‑03‑28 | CVE‑2026‑5007 | MCP02 — Privilege Escalation via Scope Creep | mcp-docs-rag (OS command injection) |
| 198 | 2026‑03‑27 | CVE‑2026‑33989 | MCP02 — Privilege Escalation via Scope Creep | @mobilenext/mobile-mcp |
| 199 | 2026‑03‑27 | CVE‑2026‑33980 | MCP05 — Command Injection & Execution | Azure Data Explorer MCP Server (KQL injection) |
| 200 | 2026‑03‑27 | CVE‑2026‑33946 | MCP01 — Token Mismanagement & Secret Exposure | MCP Ruby SDK (modelcontextprotocol/ruby-sdk) |
| 201 | 2026‑03‑27 | CVE‑2026‑32112 | MCP05 — Command Injection & Execution | ha-mcp (OAuth consent f-string injection) |
| 202 | 2026‑03‑27 | CVE‑2026‑31951 | MCP01 — Token Mismanagement & Secret Exposure | LibreChat |
| 203 | 2026‑03‑27 | CVE‑2026‑31945 | MCP05 — Command Injection & Execution | LibreChat MCP server-side request forgery via DNS resolution |
| 204 | 2026‑03‑23 | CVE‑2026‑33252 | MCP07 — Insufficient Authentication & Authorization | MCP Go SDK (HTTP transport cross-site tool execution / CSRF class):github.com/modelcontextprotocol/go-sdk (go) |
| 205 | 2026‑03‑23 | CVE‑2026‑23882 | MCP05 — Command Injection & Execution | Blinko MCP server creation function |
| 206 | 2026‑03‑20 | CVE‑2026‑4496 | MCP05 — Command Injection & Execution | Git-MCP-Server |
| 207 | 2026‑03‑20 | CVE‑2026‑33060 | MCP05 — Command Injection & Execution | CKAN MCP Server SSRF via base_url parameter |
| 208 | 2026‑03‑20 | CVE‑2026‑33010 | MCP10 — Context Injection & Over-Sharing | mcp-memory-service (cross-origin memory read/write/delete) |
| 209 | 2026‑03‑16 | CVE‑2026‑4270 | MCP02 — Privilege Escalation via Scope Creep | AWS API MCP Server (awslabs/mcp):awslabs.aws-api-mcp-server (pip) |
| 210 | 2026‑03‑16 | CVE‑2026‑4198 | MCP05 — Command Injection & Execution | mcp-server-auto-commit |
| 211 | 2026‑03‑13 | CVE‑2026‑31944 | MCP07 — Insufficient Authentication & Authorization | LibreChat (MCP OAuth callback account takeover) |
| 212 | 2026‑03‑13 | CVE‑2026‑30861 | MCP09 — Shadow MCP Servers | WeKnora |
| 213 | 2026‑03‑13 | CVE‑2026‑26118 | MCP05 — Command Injection & Execution | Azure MCP Server (azure.mcp) (SSRF):Azure.Mcp (nuget) |
| 214 | 2026‑03‑12 | CVE‑2026‑32247 | MCP06 — Prompt Injection via Contextual Payloads | Graphiti MCP server (getzep/graphiti) |
| 215 | 2026‑03‑11 | CVE‑2026‑32111 | MCP05 — Command Injection & Execution | ha-mcp OAuth consent ha_url SSRF |
| 216 | 2026‑03‑10 | CVE‑2026‑27825 | MCP05 — Command Injection & Execution | MCP Atlassian (mcp-atlassian) (arbitrary file write / RCE) |
| 217 | 2026‑03‑07 | CVE‑2026‑30856 | MCP03 — Tool Poisoning | WeKnora MCP tool execution hijacking via ambiguous naming |
| 218 | 2026‑03‑07 | CVE‑2026‑29787 | MCP07 — Insufficient Authentication & Authorization | mcp-memory-service (/api/health/detailed information disclosure) |
| 219 | 2026‑03‑06 | CVE‑2026‑29783 | MCP05 — Command Injection & Execution | GitHub Copilot CLI |
| 220 | 2026‑02‑26 | CVE‑2026‑27896 | MCP04 — Software Supply Chain Attacks & Dependency Tampering | MCP Go SDK (case-sensitivity / JSON-RPC parsing inconsistency):github.com/modelcontextprotocol/go-sdk (go) |
| 221 | 2026‑02‑25 | CVE‑2026‑27735 | MCP02 — Privilege Escalation via Scope Creep | mcp-server-git (git_add path traversal; stage files outside repo) |
| 222 | 2026‑02‑21 | CVE‑2026‑27203 | MCP09 — Shadow MCP Servers | eBay API MCP Server environment variable injection |
| 223 | 2026‑02‑18 | CVE‑2026‑25546 | MCP05 — Command Injection & Execution | Godot MCP |
| 224 | 2026‑02‑13 | CVE‑2026‑1721 | MCP07 — Insufficient Authentication & Authorization | Cloudflare agents SDK AI Playground OAuth callback |
| 225 | 2026‑02‑10 | CVE‑2026‑21518 | MCP04 — Software Supply Chain Attacks & Dependency Tampering | Microsoft Visual Studio Code and GitHub Copilot (mcp.json handling) |
| 226 | 2026‑02‑09 | CVE‑2026‑26029 | MCP05 — Command Injection & Execution | sf-mcp-server (command injection) |
| 227 | 2026‑02‑09 | CVE‑2026‑25905 | MCP09 — Shadow MCP Servers | mcp-run-python |
| 228 | 2026‑02‑09 | CVE‑2026‑25904 | MCP02 — Privilege Escalation via Scope Creep | mcp-run-python / Pydantic-AI MCP Run Python |
| 229 | 2026‑02‑08 | CVE‑2026‑2178 | MCP05 — Command Injection & Execution | xcode-mcp-server (command injection) |
| 230 | 2026‑02‑06 | CVE‑2026‑25650 | MCP01 — Token Mismanagement & Secret Exposure | MCP Salesforce Connector (MCP-Salesforce / mcp-salesforce-connector) (auth token disclosure):mcp-salesforce-connector (pip) |
| 231 | 2026‑02‑04 | CVE‑2026‑25536 | MCP10 — Context Injection & Over-Sharing | MCP TypeScript SDK (cross-client data leak via shared server/transport reuse) |
| 232 | 2026‑01‑23 | CVE‑2026‑0758 | MCP05 — Command Injection & Execution | mcp-server-siri-shortcuts |
| 233 | 2026‑01‑22 | CVE‑2026‑0757 | MCP05 — Command Injection & Execution | MCP Manager for Claude Desktop |
| 234 | 2026‑01‑22 | CVE‑2026‑0756 | MCP07 — Insufficient Authentication & Authorization | github-kanban-mcp-server (unauthenticated RCE / command injection) |
| 235 | 2026‑01‑21 | CVE‑2026‑22793 | MCP05 — Command Injection & Execution | 5ire MCP client (ECharts option parsing → RCE) |
| 236 | 2026‑01‑21 | CVE‑2026‑22792 | MCP05 — Command Injection & Execution | 5ire Desktop MCP client (unsafe HTML rendering → arbitrary JS execution):5ire |
| 237 | 2026‑01‑21 | CVE‑2026‑21852 | MCP01 — Token Mismanagement & Secret Exposure | Claude Code (Anthropic agentic coding tool) |
| 238 | 2026‑01‑16 | CVE‑2026‑23744 | MCP09 — Shadow MCP Servers | MCPJam Inspector (unauthenticated RCE via exposed listener) |
| 239 | 2026‑01‑16 | CVE‑2026‑23523 | MCP09 — Shadow MCP Servers | Dive MCP Host Desktop Application |
| 240 | 2026‑01‑12 | CVE‑2026‑22785 | MCP05 — Command Injection & Execution | @orval/mcp (Orval MCP server generation from OpenAPI) |
| 241 | 2026‑01‑09 | CVE‑2026‑0755 | MCP06 — Prompt Injection via Contextual Payloads | gemini-mcp-tool (command injection via unsafe shell execution) |
| 242 | 2026‑01‑05 | CVE‑2026‑0621 | MCP05 — Command Injection & Execution | MCP TypeScript SDK (UriTemplate ReDoS) |
2025
| S.No | Date | CVE | OWASP MCP Top 10 (2025) | Affected product |
|---|---|---|---|---|
| 3 | 2025‑08‑14 | CVE‑2025‑55346 | MCP05 — Command Injection & Execution | Flowise unsafe dynamic Function constructor remote code execution |
| 4 | 2025‑06‑27 | CVE‑2025‑53098 | MCP09 — Shadow MCP Servers | Roo Code workspace .roo/mcp.json project MCP configuration code execution |
| 5 | 2026‑06‑25 | CVE‑2025‑71336 | MCP05 — Command Injection & Execution | Flowise Custom MCP unsandboxed RCE |
| 6 | 2026‑06‑22 | CVE‑2025‑66336 | MCP05 — Command Injection & Execution | Apache Doris MCP Server SQL injection in metadata query path |
| 7 | 2026‑05‑12 | CVE‑2025‑69443 | MCP05 — Command Injection & Execution | Archon (coleam00/archon research OS / UI) |
| 8 | 2026‑05‑12 | CVE‑2025‑65719 | MCP01 — Token Mismanagement & Secret Exposure | Open Source Kubectl MCP Server |
| 9 | 2026‑04‑20 | CVE‑2025‑66335 | MCP05 — Command Injection & Execution | Apache Doris MCP Server (doris-mcp-server; PyPI) (SQL injection via MCP query interface) |
| 10 | 2026‑04‑15 | CVE‑2025‑65720 | MCP09 — Shadow MCP Servers | GPT Researcher (unauthenticated RCE via malicious MCP stdio configuration) |
| 11 | 2026‑04‑15 | CVE‑2025‑54136 | MCP04 — Software Supply Chain Attacks & Dependency Tampering | Cursor (MCP JSON / stdio exposure) |
| 12 | 2026‑04‑03 | CVE‑2025‑64340 | MCP05 — Command Injection & Execution | FastMCP (fastmcp on PyPI): Windows fastmcp install command injection |
| 13 | 2026‑01‑23 | CVE‑2025‑15061 | MCP05 — Command Injection & Execution | Framelink Figma MCP Server |
| 14 | 2026‑01‑22 | CVE‑2025‑15063 | MCP05 — Command Injection & Execution | Ollama MCP Server (execAsync command injection) |
| 15 | 2026‑01‑21 | CVE‑2025‑68669 | MCP05 — Command Injection & Execution | 5ire MCP client (Mermaid securityLevel: loose → RCE) |
| 16 | 2026‑01‑12 | CVE‑2025‑66689 | MCP02 — Privilege Escalation via Scope Creep | Zen MCP Server (path traversal) |
| 17 | 2026‑01‑07 | CVE‑2025‑9611 | MCP07 — Insufficient Authentication & Authorization | Microsoft Playwright MCP Server (@playwright/mcp):@playwright/mcp (npm) |
| 18 | 2026‑01‑07 | CVE‑2025‑67366 | MCP02 — Privilege Escalation via Scope Creep | @sylphxltd/filesystem-mcp (path traversal / symlink bypass) |
| 19 | 2025‑12‑30 | CVE‑2025‑69256 | MCP05 — Command Injection & Execution | @serverless/mcp (command injection in Serverless Framework MCP feature) |
| 20 | 2025‑12‑19 | CVE‑2025‑66580 | MCP06 — Prompt Injection via Contextual Payloads | Dive MCP Host (Mermaid XSS → malicious MCP config / RCE) |
| 21 | 2025‑12‑17 | CVE‑2025‑68433 | MCP09 — Shadow MCP Servers | Zed IDE malicious MCP settings.json arbitrary code execution |
| 22 | 2025‑12‑17 | CVE‑2025‑68145 | MCP02 — Privilege Escalation via Scope Creep | mcp-server-git (repository boundary bypass via --repository) |
| 23 | 2025‑12‑17 | CVE‑2025‑68144 | MCP05 — Command Injection & Execution | mcp-server-git (argument injection in git operations) |
| 24 | 2025‑12‑17 | CVE‑2025‑68143 | MCP02 — Privilege Escalation via Scope Creep | mcp-server-git (git_init arbitrary path) |
| 25 | 2025‑12‑09 | CVE‑2025‑65513 | MCP01 — Token Mismanagement & Secret Exposure | fetch-mcp (MCP fetch / URL retrieval server; often referenced as MCP fetch server) |
| 26 | 2025‑12‑03 | CVE‑2025‑66404 | MCP05 — Command Injection & Execution | mcp-server-kubernetes (exec_in_pod command injection) |
| 27 | 2025‑12‑03 | CVE‑2025‑66222 | MCP09 — Shadow MCP Servers | DeepChat (deepchat; Electron app) — Stored XSS in Mermaid renderer escalated to RCE via MCP server registration |
| 28 | 2025‑12‑03 | CVE‑2025‑64443 | MCP07 — Insufficient Authentication & Authorization | Docker MCP Gateway:Docker MCP Plugin / Docker MCP Gateway:github.com/docker/mcp-gateway (go) |
| 29 | 2025‑12‑03 | CVE‑2025‑20381 | MCP05 — Command Injection & Execution | Splunk MCP Server app |
| 30 | 2025‑12‑02 | CVE‑2025‑66454 | MCP07 — Insufficient Authentication & Authorization | Arcade MCP (arcade-mcp) |
| 31 | 2025‑12‑02 | CVE‑2025‑66416 | MCP07 — Insufficient Authentication & Authorization | MCP Python SDK (mcp):mcp (pip) |
| 32 | 2025‑12‑02 | CVE‑2025‑66414 | MCP07 — Insufficient Authentication & Authorization | MCP TypeScript SDK (@modelcontextprotocol/sdk):@modelcontextprotocol/sdk (npm) |
| 33 | 2025‑12‑01 | CVE‑2025‑66401 | MCP05 — Command Injection & Execution | mcp-watch (command injection via cloneRepo URL) |
| 34 | 2025‑11‑30 | CVE‑2025‑35028 | MCP05 — Command Injection & Execution | HexStrike AI MCP server |
| 35 | 2025‑11‑18 | CVE‑2025‑69196 | MCP02 — Privilege Escalation via Scope Creep | FastMCP (OAuth resource scope bypass) |
| 36 | 2025‑11‑18 | CVE‑2025‑64109 | MCP05 — Command Injection & Execution | Cursor CLI Beta (command injection class) |
| 37 | 2025‑11‑18 | CVE‑2025‑64106 | MCP04 — Software Supply Chain Attacks & Dependency Tampering | Cursor (MCP server install input validation) |
| 38 | 2025‑11‑18 | CVE‑2025‑63604 | MCP05 — Command Injection & Execution | mcp-server-aws-resources-python (code injection / AWS credential exposure) |
| 39 | 2025‑11‑18 | CVE‑2025‑63603 | MCP05 — Command Injection & Execution | MCP Data Science Server (reading-plus-ai/mcp-server-data-exploration) (unsafe exec / code execution) |
| 40 | 2025‑11‑18 | CVE‑2025‑56406 | MCP01 — Token Mismanagement & Secret Exposure | mcp-neo4j (SSE sensitive information) |
| 41 | 2025‑11‑15 | CVE‑2025‑61260 | MCP04 — Software Supply Chain Attacks & Dependency Tampering | OpenAI Codex CLI |
| 42 | 2025‑11‑05 | CVE‑2025‑58337 | MCP02 — Privilege Escalation via Scope Creep | Apache Doris MCP Server (doris-mcp-server; PyPI) (read-only mode bypass) |
| 43 | 2025‑10‑29 | CVE‑2025‑64132 | MCP07 — Insufficient Authentication & Authorization | Jenkins MCP Server Plugin (missing permission checks in multiple tools) |
| 44 | 2025‑10‑28 | CVE‑2025‑62801 | MCP05 — Command Injection & Execution | FastMCP (install cursor command injection) |
| 45 | 2025‑10‑28 | CVE‑2025‑62800 | MCP05 — Command Injection & Execution | FastMCP (reflected XSS in OAuth callback) |
| 46 | 2025‑10‑28 | CVE‑2025‑61591 | MCP07 — Insufficient Authentication & Authorization | Cursor (MCP OAuth with untrusted MCP server) |
| 47 | 2025‑10‑28 | CVE‑2025‑10619 | MCP07 — Insufficient Authentication & Authorization | sequa-ai sequa-mcp (OAuth redirect issue) |
| 48 | 2025‑10‑20 | CVE‑2025‑6515 | MCP01 — Token Mismanagement & Secret Exposure | oatpp-mcp (oatpp MCP SSE endpoint) |
| 49 | 2025‑10‑17 | CVE‑2025‑58747 | MCP05 — Command Injection & Execution | Dify MCP OAuth component |
| 50 | 2025‑10‑08 | CVE‑2025‑53967 | MCP05 — Command Injection & Execution | Framelink Figma MCP Server |
| 51 | 2025‑10‑08 | CVE‑2025‑11445 | MCP06 — Prompt Injection via Contextual Payloads | Kilo Code (AI agent IDE; ClineProvider / Prompt Handler) |
| 52 | 2025‑10‑05 | CVE‑2025‑11286 | MCP05 — Command Injection & Execution | samanhappy MCPHub |
| 53 | 2025‑10‑03 | CVE‑2025‑61590 | MCP04 — Software Supply Chain Attacks & Dependency Tampering | Cursor IDE |
| 54 | 2025‑10‑03 | CVE‑2025‑59944 | MCP04 — Software Supply Chain Attacks & Dependency Tampering | Cursor IDE |
| 55 | 2025‑10‑03 | CVE‑2025‑59536 | MCP04 — Software Supply Chain Attacks & Dependency Tampering | Claude Code (Anthropic agentic coding tool) |
| 56 | 2025‑09‑30 | CVE‑2025‑59956 | MCP10 — Context Injection & Over-Sharing | Coder agentapi (HTTP API for Claude Code, Goose, Aider, Gemini, Amp, Codex) |
| 57 | 2025‑09‑29 | CVE‑2025‑59163 | MCP07 — Insufficient Authentication & Authorization | SafeDep vet (MCP SSE server mode) |
| 58 | 2025‑09‑24 | CVE‑2025‑61685 | MCP10 — Context Injection & Over-Sharing | @mastra/mcp-docs-server (directory listing / information exposure via path traversal logic flaw) |
| 59 | 2025‑09‑24 | CVE‑2025‑59834 | MCP05 — Command Injection & Execution | adb-mcp (command injection in ADB MCP Server) |
| 60 | 2025‑09‑22 | CVE‑2025‑59528 | MCP05 — Command Injection & Execution | Flowise CustomMCP node:flowise (npm) |
| 61 | 2025‑09‑18 | CVE‑2025‑59417 | MCP07 — Insufficient Authentication & Authorization | Lobe Chat |
| 62 | 2025‑09‑16 | CVE‑2025‑59333 | MCP02 — Privilege Escalation via Scope Creep | @executeautomation/database-server (read-only mode bypass) |
| 63 | 2025‑09‑15 | CVE‑2025‑59377 | MCP05 — Command Injection & Execution | feiskyer mcp-kubernetes-server (distinct from mcp-server-kubernetes) |
| 64 | 2025‑09‑15 | CVE‑2025‑59155 | MCP05 — Command Injection & Execution | hackmd-mcp |
| 65 | 2025‑09‑11 | CVE‑2025‑10193 | MCP07 — Insufficient Authentication & Authorization | Neo4j MCP Cypher server (mcp-neo4j-cypher) |
| 66 | 2025‑09‑08 | CVE‑2025‑58444 | MCP05 — Command Injection & Execution | MCP Inspector (@modelcontextprotocol/inspector) (XSS via untrusted redirect URL) |
| 67 | 2025‑09‑08 | CVE‑2025‑54994 | MCP04 — Software Supply Chain Attacks & Dependency Tampering | @akoskm/create-mcp-server-stdio (which-app-on-port command injection via unsafe exec; also cited in OX supply-chain advisory) |
| 68 | 2025‑09‑04 | CVE‑2025‑58358 | MCP05 — Command Injection & Execution | Markdownify MCP server command injection |
| 69 | 2025‑09‑04 | CVE‑2025‑58357 | MCP06 — Prompt Injection via Contextual Payloads | 5ire MCP client (content injection via compromised MCP servers) |
| 70 | 2025‑09‑03 | CVE‑2025‑58176 | MCP05 — Command Injection & Execution | Dive MCP Host Desktop Application |
| 71 | 2025‑08‑29 | CVE‑2025‑9654 | MCP05 — Command Injection & Execution | mcp-ssh command injection |
| 72 | 2025‑08‑28 | CVE‑2025‑58062 | MCP07 — Insufficient Authentication & Authorization | LSTM-Kirigaya openmcp-client VS Code plugin |
| 73 | 2025‑08‑14 | CVE‑2025‑8943 | MCP05 — Command Injection & Execution | Flowise Custom MCPs |
| 74 | 2025‑08‑13 | CVE‑2025‑54382 | MCP05 — Command Injection & Execution | Cherry Studio |
| 75 | 2025‑08‑13 | CVE‑2025‑54074 | MCP05 — Command Injection & Execution | Cherry Studio |
| 76 | 2025‑08‑06 | CVE‑2025‑8665 | MCP05 — Command Injection & Execution | agno MCPTools/MultiMCPTools command injection |
| 77 | 2025‑08‑04 | CVE‑2025‑54135 | MCP04 — Software Supply Chain Attacks & Dependency Tampering | Cursor |
| 78 | 2025‑08‑01 | CVE‑2025‑54424 | MCP07 — Insufficient Authentication & Authorization | 1Panel MCP Server |
| 79 | 2025‑07‑21 | CVE‑2025‑53832 | MCP05 — Command Injection & Execution | Lara Translate MCP Server (@translated/lara-mcp) (npm) — command injection / RCE via child_process.exec |
| 80 | 2025‑07‑18 | CVE‑2025‑54073 | MCP05 — Command Injection & Execution | mcp-package-docs (npm) |
| 81 | 2025‑07‑14 | CVE‑2025‑53818 | MCP05 — Command Injection & Execution | GitHub Kanban MCP Server |
| 82 | 2025‑07‑09 | CVE‑2025‑6514 | MCP01 — Token Mismanagement & Secret Exposure | mcp-remote (npm) |
| 83 | 2025‑07‑08 | CVE‑2025‑53372 | MCP05 — Command Injection & Execution | node-code-sandbox-mcp (npm) |
| 84 | 2025‑07‑08 | CVE‑2025‑53355 | MCP05 — Command Injection & Execution | mcp-server-kubernetes (npm) |
| 85 | 2025‑07‑04 | CVE‑2025‑53366 | MCP07 — Insufficient Authentication & Authorization | MCP Python SDK (mcp on PyPI): validation error → unhandled exception / DoS |
| 86 | 2025‑07‑04 | CVE‑2025‑53365 | MCP07 — Insufficient Authentication & Authorization | MCP Python SDK (mcp) (DoS via unhandled exception in Streamable HTTP transport):mcp (pip) |
| 87 | 2025‑07‑02 | CVE‑2025‑53110 | MCP02 — Privilege Escalation via Scope Creep | Filesystem MCP Server (@modelcontextprotocol/server-filesystem) (prefix/path collision bypass) |
| 88 | 2025‑07‑02 | CVE‑2025‑53109 | MCP02 — Privilege Escalation via Scope Creep | Filesystem MCP Server (@modelcontextprotocol/server-filesystem) (symlink containment bypass) |
| 89 | 2025‑07‑02 | CVE‑2025‑34072 | MCP10 — Context Injection & Over-Sharing | @modelcontextprotocol/server-slack (Slack link-unfurl data exfiltration) |
| 90 | 2025‑07‑01 | CVE‑2025‑53107 | MCP05 — Command Injection & Execution | @cyanheads/git-mcp-server (npm) |
| 91 | 2025‑07‑01 | CVE‑2025‑53100 | MCP05 — Command Injection & Execution | RestDB Codehooks.io MCP Server |
| 92 | 2025‑06‑26 | CVE‑2025‑52573 | MCP05 — Command Injection & Execution | iOS Simulator MCP Server (ios-simulator-mcp) |
| 93 | 2025‑06‑13 | CVE‑2025‑49596 | MCP05 — Command Injection & Execution | MCP Inspector (@modelcontextprotocol/inspector) |
| 94 | 2025‑05‑29 | CVE‑2025‑5276 | MCP05 — Command Injection & Execution | mcp-markdownify-server SSRF via Markdownify.get() |
| 95 | 2025‑05‑29 | CVE‑2025‑5273 | MCP02 — Privilege Escalation via Scope Creep | mcp-markdownify-server path traversal via get-markdown-file |
| 96 | 2025‑05‑28 | CVE‑2025‑5277 | MCP05 — Command Injection & Execution | aws-mcp-server |
| 97 | 2025‑05‑28 | CVE‑2025‑4143 | MCP07 — Insufficient Authentication & Authorization | Cloudflare workers-mcp (OAuth implementation flaw) |
| 98 | 2025‑05‑14 | CVE‑2025‑47777 | MCP05 — Command Injection & Execution | 5ire MCP client (stored XSS → RCE) |
| 99 | 2025‑05‑12 | CVE‑2025‑47274 | MCP01 — Token Mismanagement & Secret Exposure | Stacklok ToolHive |
Newly verified missing CVEs added on 2026-09-07
These CVEs were found during the September 7, 2026 internet/NVD/advisory gap review for Model Context Protocol, MCP server, GitHub Security Advisory, @modelcontextprotocol, Streamable HTTP, SSE, DNS rebinding, command injection, path traversal, STDIO RCE, and MCP configuration code-execution searches. They have been added as separate notes under [cves/](cves/). Obvious non-Model-Context-Protocol acronym collisions, such as Linux/TinyOS hardware-driver records mentioning MCP chip names, remain excluded.
| Date | CVE | OWASP MCP Top 10 (2025) | Affected product / issue |
|---|---|---|---|
| 2026-09-05 | CVE-2026-86122 | MCP07 - Insufficient Authentication & Authorization | Rowboat through 0.9.1 fails to validate custom MCP server and webhook URLs, allowing authenticated users to configure arbitrary destinations. |
| 2026-09-04 | CVE-2026-9186 | MCP07 - Insufficient Authentication & Authorization | IBM Langflow OSS 1.0.0 through 1.11.2 allows remote authenticated attackers to bypass localhost-only MCP configuration installation by spoofing X-Forwarded-For: 127.0.0.1 header, enabling arbitrary writes to IDE config f |
| 2026-09-04 | CVE-2026-85787 | MCP07 - Insufficient Authentication & Authorization | An incomplete list of disallowed inputs in the SQL validation component in Amazon awslabs postgres-mcp-server before version 1.1.7 might allow an unauthenticated actor to modify data beyond the read-only scope by placing |
| 2026-09-04 | CVE-2026-85666 | MCP01 - Token Mismanagement & Secret Exposure | OGX (formerly Llama Stack, affected at commit fbe8e0f) contains an unauthenticated server-side request forgery vulnerability in the OpenAI-compatible POST /v1/responses endpoint. |
| 2026-09-04 | CVE-2026-85620 | MCP02 - Privilege Escalation via Scope Creep | Postgres MCP Pro 0.3.0 contains a restricted-mode bypass vulnerability where function-name validation is not applied to RangeFunction nodes in FROM clauses. |
| 2026-09-04 | CVE-2026-85580 | MCP01 - Token Mismanagement & Secret Exposure | SiYuan versions before v3.8.2 contain a path guard bypass vulnerability in the MCP file-access handler that uses case-sensitive matching on Linux filesystems. |
| 2026-09-04 | CVE-2026-18489 | MCP01 - Token Mismanagement & Secret Exposure | IBM ContextForge MCP Gateway - Translate utility <= 1.0.8 MCP Context Forge could allow a remote attacker to obtain sensitive information from other sessions due to exposure of data elements to the wrong session. |
| 2026-09-04 | CVE-2026-18486 | MCP01 - Token Mismanagement & Secret Exposure | IBM ContextForge MCP Gateway <= v1.0.7 MCP Context Forge could allow a remote authenticated attacker to obtain sensitive credentials and escalate privileges due to improper validation of jq filters. |
| 2026-09-03 | CVE-2026-85306 | MCP07 - Insufficient Authentication & Authorization | Missing Authorization vulnerability in Cascadia Web Services MountDev AI MCP Connector for WordPress allows Exploiting Incorrectly Configured Access Control Security Levels. |
| 2026-09-03 | CVE-2026-85166 | MCP01 - Token Mismanagement & Secret Exposure | n8n before 2.35.4 and 2.36.x before 2.36.2 does not validate credential references in the inline workflow JSON of nodes that execute an inline sub-workflow (e.g., the Workflow Tool node). |
| 2026-09-03 | CVE-2026-84779 | MCP07 - Insufficient Authentication & Authorization | Subscriber Broken Access Control in Agentimus – AI SEO, llms.txt & MCP for AI Agents <= 1.51.0 versions. |
| 2026-09-01 | CVE-2026-84289 | MCP07 - Insufficient Authentication & Authorization | NousResearch hermes-agent up to 0.18.2. This vulnerability affects the function list_tools of the file tools/mcp_tool.py of the component MCP Tool. |
| 2026-09-01 | CVE-2026-81846 | MCP07 - Insufficient Authentication & Authorization | An authorization bypass in the runZero Platform MCP service has been resolved in version 5.1.260826.0. |
| 2026-09-01 | CVE-2026-19591 | MCP06 - Prompt Injection via Contextual Payloads | OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows and macOS misclassified certain PowerShell commands as safe because their command-safety parser interpreted PowerShell's stop-parsing token (-- |
| 2026-08-31 | CVE-2026-82905 | MCP07 - Insufficient Authentication & Authorization | sdcb chats up to 1.12.0. This affects the function McpController of the file src/BE/web/Controllers/Users/Mcps/McpController.cs of the component fetch-tools Endpoint. |
| 2026-08-31 | CVE-2026-79750 | MCP05 - Command Injection & Execution | MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. |
| 2026-08-31 | CVE-2026-79749 | MCP07 - Insufficient Authentication & Authorization | MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. |
| 2026-08-31 | CVE-2026-79747 | MCP07 - Insufficient Authentication & Authorization | MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. |
| 2026-08-31 | CVE-2026-79746 | MCP07 - Insufficient Authentication & Authorization | MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. |
| 2026-08-31 | CVE-2026-79745 | MCP06 - Prompt Injection via Contextual Payloads | MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. |
| 2026-08-31 | CVE-2026-79744 | MCP07 - Insufficient Authentication & Authorization | MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. |
| 2026-08-31 | CVE-2026-79743 | MCP02 - Privilege Escalation via Scope Creep | MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. |
| 2026-08-29 | CVE-2026-82456 | MCP05 - Command Injection & Execution | argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller credentials when ARGOCD_API_TOKEN is configured. |
| 2026-08-28 | CVE-2026-82233 | MCP06 - Prompt Injection via Contextual Payloads | SiYuan before v3.8.1 contains a path traversal vulnerability in the asset.upload MCP tool that accepts arbitrary absolute file paths without workspace boundary validation. |
| 2026-08-28 | CVE-2026-82021 | MCP04 - Software Supply Chain Attacks & Dependency Tampering | Hermes Agent 0.18.2 prior to 0.19.0 contains a supply chain vulnerability in its bundled MCP catalog that allows a remote attacker to execute arbitrary code by compromising a third-party upstream repository referenced vi |
| 2026-08-28 | CVE-2026-81845 | MCP01 - Token Mismanagement & Secret Exposure | arben-adm mcp-sequential-thinking up to 0.5.0. |
| 2026-08-28 | CVE-2026-81835 | MCP06 - Prompt Injection via Contextual Payloads | RooCodeInc Roo-Code up to 3.51.1. This affects the function fetch_instructions of the file malicious_mcp_server.py of the component MCP Integration Trust Model. |
| 2026-08-27 | CVE-2026-81735 | MCP05 - Command Injection & Execution | startServer.ts in the mcp-http-server package of UI-TARS-desktop defaulted its listen address to '::' when no host was given, so startSseAndStreamableHttpMcpServer bound the Streamable HTTP and SSE MCP transports to ever |
| 2026-08-27 | CVE-2026-81486 | MCP02 - Privilege Escalation via Scope Creep | bsmi021 mcp-file-context-server 1.0.0. Affected by this issue is the function read_context of the file src/index.ts of the component Path Resolution. |
| 2026-08-27 | CVE-2026-81102 | MCP01 - Token Mismanagement & Secret Exposure | The Dash MCP server bound its listener to the loopback address but never checked the host a request named. |
| 2026-08-27 | CVE-2026-81101 | MCP01 - Token Mismanagement & Secret Exposure | The configure command accepted any endpoint URL and stored it beside the user's access token. |
| 2026-08-27 | CVE-2026-81100 | MCP04 - Software Supply Chain Attacks & Dependency Tampering | tiger-gh-mcp-server started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides. |
| 2026-08-27 | CVE-2026-81099 | MCP04 - Software Supply Chain Attacks & Dependency Tampering | tiger-slack started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides. |
| 2026-08-27 | CVE-2026-81098 | MCP05 - Command Injection & Execution | The Telnyx MCP server exposed its HTTP transport on every interface and did not require a caller credential. |
| 2026-08-27 | CVE-2026-81097 | MCP05 - Command Injection & Execution | The execute_ruby tool is documented as a read-only Ruby sandbox and is enforced by a pattern denylist together with replacements for the process-spawning methods on Kernel. |
| 2026-08-27 | CVE-2026-81096 | MCP05 - Command Injection & Execution | ToolUniverse ran caller-supplied Python inside a sandbox that could be escaped, on a server that required no authentication. |
| 2026-08-27 | CVE-2026-81095 | MCP04 - Software Supply Chain Attacks & Dependency Tampering | pg-aiguide started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides. |
| 2026-08-27 | CVE-2026-81094 | MCP05 - Command Injection & Execution | The mcp-router CLI served its MCP aggregator on every interface and enforced authentication only when the operator asked for it. |
| 2026-08-27 | CVE-2026-81093 | MCP01 - Token Mismanagement & Secret Exposure | The get-html-skeleton tool fetched a URL the caller supplied after checking only its syntax. |
| 2026-08-27 | CVE-2026-81091 | MCP07 - Insufficient Authentication & Authorization | The proxy middleware in mcp-use's inspector forwards requests to a destination the caller names. |
| 2026-08-26 | CVE-2026-80347 | MCP07 - Insufficient Authentication & Authorization | mcp-fetch checks a fetch target against its SSRF guard without removing the brackets that surround an IPv6 literal. |
| 2026-08-25 | CVE-2026-79786 | MCP01 - Token Mismanagement & Secret Exposure | Coroot's unauthenticated MCP OAuth dynamic client registration endpoint accepts any syntactically valid redirect URI without validation, allowing attackers to register clients pointing to attacker-controlled hosts. |
| 2026-08-25 | CVE-2026-55609 | MCP07 - Insufficient Authentication & Authorization | sublinear-time-solver is a Rust and WebAssembly library for solving asymmetric diagonally dominant systems in sublinear time. |
| 2026-08-25 | CVE-2026-55557 | MCP06 - Prompt Injection via Contextual Payloads | browse-mcp is a Playwright-based headless-browser MCP server for MCP-capable agents. |
| 2026-08-14 | CVE-2026-55157 | MCP05 - Command Injection & Execution | Token Optimizer MCP: OS command injection in smart_user via username |
| 2026-08-12 | CVE-2026-55071 | MCP05 - Command Injection & Execution | MCP-for-Stata: command injection via unsanitized package in ado_package_install |
| 2026-07-15 | CVE-2026-54504 | MCP07 - Insufficient Authentication & Authorization | @andrea9293/mcp-documentation-server: Web UI/API binds to all interfaces by default without authentication |
| 2026-06-18 | CVE-2026-57139 | MCP07 - Insufficient Authentication & Authorization | npm PraisonAI MCPServer exposes unauthenticated HTTP tools/call |
| 2026-06-18 | CVE-2026-57112 | MCP07 - Insufficient Authentication & Authorization | PraisonAI ToolsMCPServer legacy SSE transport lacks Host/Origin validation and authentication |
| 2026-06-06 | CVE-2026-54561 | MCP02 - Privilege Escalation via Scope Creep | mcp-memory-keeper: arbitrary local file read in context_import via unvalidated filePath |
| 2026-05-30 | CVE-2026-55786 | MCP05 - Command Injection & Execution | flyto-core: unauthenticated command execution via HTTP MCP execute_module |
| 2026-05-29 | CVE-2026-35674 | MCP04 - Software Supply Chain Attacks & Dependency Tampering | OpenClaw before 2026.5.18 contains a scope bypass vulnerability in the Gateway chat.send route that allows scoped clients to execute privileged commands. |
| 2026-05-27 | CVE-2026-9739 | MCP07 - Insufficient Authentication & Authorization | Vulnerable to DNS rebinding attacks when using SSE (http://b/499408790). |
| 2026-05-25 | CVE-2026-9467 | MCP05 - Command Injection & Execution | debugmcp mcp-debugger up to 0.20.0. Impacted is the function handleGetSourceContext of the file src/server.ts. |
| 2026-05-17 | CVE-2026-8719 | MCP04 - Software Supply Chain Attacks & Dependency Tampering | The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Privilege Escalation in version 3.4.9. |
| 2026-05-12 | CVE-2026-43989 | MCP07 - Insufficient Authentication & Authorization | JunoClaw is an agentic AI platform built on Juno Network. |
| 2026-05-11 | CVE-2026-43995 | MCP07 - Insufficient Authentication & Authorization | Flowise is a drag & drop user interface to build a customized large language model flow. |
| 2026-05-11 | CVE-2026-42856 | MCP01 - Token Mismanagement & Secret Exposure | Network-AI is a TypeScript/Node.js multi-agent orchestrator. |
| 2026-05-08 | CVE-2026-41497 | MCP05 - Command Injection & Execution | PraisonAI is a multi-agent teams system. Prior to version 4.6.9, the fix for PraisonAI's MCP command handling does not add a command allowlist or argument validation to parse_mcp_command(), allowing arbitrary executables |
| 2026-05-05 | CVE-2026-7812 | MCP05 - Command Injection & Execution | 54yyyu code-mcp up to 4cfc4643541a110c906d93635b391bf7e357f4a8. |
| 2026-05-05 | CVE-2026-7811 | MCP02 - Privilege Escalation via Scope Creep | 54yyyu code-mcp up to 4cfc4643541a110c906d93635b391bf7e357f4a8. |
| 2026-05-05 | CVE-2026-7788 | MCP02 - Privilege Escalation via Scope Creep | Axle-Bucamp MCP-Docusaurus up to 404bc028e15ec304c9a045528560f4b5f27a17e0. |
| 2026-05-04 | CVE-2026-42235 | MCP05 - Command Injection & Execution | n8n is an open source workflow automation platform. |
| 2026-05-02 | CVE-2026-7645 | MCP02 - Privilege Escalation via Scope Creep | ruvnet sublinear-time-solver 1.5.0. Affected by this vulnerability is the function export_state of the file src/consciousness-explorer/mcp/server.js of the component MCP Interface. |
| 2026-05-02 | CVE-2026-7642 | MCP05 - Command Injection & Execution | pskill9 website-downloader up to 0.1.0. This affects the function download_website of the file src/index.ts of the component MCP Interface. |
| 2026-04-30 | CVE-2026-7445 | MCP05 - Command Injection & Execution | ZachHandley ZMCPTools up to 0.2.2. Affected by this issue is some unknown functionality of the file src/managers/ResourceManager.ts of the component MCP Log Resource Handler. |
| 2026-04-29 | CVE-2026-7416 | MCP05 - Command Injection & Execution | PolarVista xcode-mcp-server 1.0.0. This issue affects the function build_project/run_tests of the file src/index.ts of the component MCP Interface. |
| 2026-04-29 | CVE-2026-7404 | MCP02 - Privilege Escalation via Scope Creep | A weakness has been identified in getsimpletool mcpo-simple-server up to 0.2.0. |
| 2026-04-28 | CVE-2026-7318 | MCP02 - Privilege Escalation via Scope Creep | elie mcp-project 0.1.0. The affected element is the function search_papers of the file research_server.py. |
| 2026-04-28 | CVE-2026-7215 | MCP05 - Command Injection & Execution | egtai gmx-vmd-mcp up to 0.1.0. This issue affects the function launch_vmd_gui_tool of the file mcp_server.py of the component VMD Launch Handler. |
| 2026-04-28 | CVE-2026-7211 | MCP05 - Command Injection & Execution | A weakness has been identified in dvladimirov MCP up to 0.1.0. |
| 2026-04-14 | CVE-2025-13822 | MCP07 - Insufficient Authentication & Authorization | MCPHub in versions below 0.11.0 is vulnerable to authentication bypass. |
| 2026-04-12 | CVE-2026-6118 | MCP05 - Command Injection & Execution | AstrBotDevs AstrBot up to 4.22.1. Impacted is the function add_mcp_server of the file astrbot/dashboard/routes/tools.py of the component MCP Endpoint. |
| 2026-04-08 | CVE-2026-5802 | MCP05 - Command Injection & Execution | idachev mcp-javadc up to 1.2.4. Impacted is an unknown function of the component HTTP Interface. |
| 2026-04-07 | CVE-2026-5379 | MCP07 - Insufficient Authentication & Authorization | allowed MCP agents to access certificate information from outside of their authorized organization scope has been resolved. |
| 2026-04-07 | CVE-2026-5374 | MCP07 - Insufficient Authentication & Authorization | allowed MCP agents to access remediation and asset information from outside of the authorized organization scope has been resolved. |
| 2026-04-06 | CVE-2026-5619 | MCP05 - Command Injection & Execution | Braffolk mcp-summarization-functions up to 0.1.5. |
| 2026-04-03 | CVE-2026-34939 | MCP07 - Insufficient Authentication & Authorization | PraisonAI is a multi-agent teams system. Prior to version 4.5.90, MCPToolIndex.search_tools() compiles a caller-supplied string directly as a Python regular expression with no validation, sanitization, or timeout. |
| 2026-04-02 | CVE-2026-5322 | MCP07 - Insufficient Authentication & Authorization | AlejandroArciniegas mcp-data-vis bc597e391f184d2187062fd567599a3cb72adf51/de5a51525a69822290eaee569a1ab447b490746d. |
| 2026-03-30 | CVE-2026-29872 | MCP05 - Command Injection & Execution | A cross-session information disclosure vulnerability exists in the awesome-llm-apps project in commit e46690f99c3f08be80a9877fab52acacf7ab8251 (2026-01-19). |
| 2026-03-23 | CVE-2026-4593 | MCP07 - Insufficient Authentication & Authorization | erupts erupt bis 1.13.3. Affected by this vulnerability is the function EruptDataQuery of the file erupt-ai/src/main/java/xyz/erupt/ai/call/impl/EruptDataQuery.java of the component MCP Tool Interface. |
| 2026-03-16 | CVE-2026-4199 | MCP05 - Command Injection & Execution | bazinga012 mcp_code_executor up to 0.3.0. |
| 2026-03-12 | CVE-2026-31841 | MCP07 - Insufficient Authentication & Authorization | Hyperterse is a tool-first MCP framework for building AI-ready backend surfaces from declarative config. |
| 2026-03-06 | CVE-2026-29791 | MCP05 - Command Injection & Execution | Agentgateway is an open source data plane for agentic AI connectivity within or across any agent framework or environment. |
| 2026-03-02 | CVE-2026-28361 | MCP01 - Token Mismanagement & Secret Exposure | NocoDB is software for building databases as spreadsheets. |
| 2026-02-08 | CVE-2026-2130 | MCP05 - Command Injection & Execution | BurtTheCoder mcp-maigret up to 1.0.12. This affects an unknown part of the file src/index.ts of the component search_username. |
| 2026-02-06 | CVE-2026-1977 | MCP05 - Command Injection & Execution | isaacwasserman mcp-vegalite-server up to 16aefed598b8cd897b78e99b907f6e2984572c61. |
| 2026-01-07 | CVE-2025-61489 | MCP05 - Command Injection & Execution | A command injection vulnerability in the shell_exec function of sonirico mcp-shell v0.3.1 allows attackers to execute arbitrary commands via supplying a crafted command string. |
Newly verified missing CVEs added on 2026-08-25
These CVEs were found during the August 25, 2026 internet/NVD audit and have been added as separate notes under [cves/](cves/). The Linux kernel mcp23s08 hardware-driver false positive CVE 2026-53344 remains excluded because it is not a Model Context Protocol issue.
| Date | CVE | OWASP MCP Top 10 (2025) | Affected product / issue |
|---|---|---|---|
| 2026-08-25 | CVE-2026-19801 | MCP02 — Privilege Escalation via Scope Creep | The BetterLinks – Link Shortener, Link Cloaking, Redirects, Affiliate Link Manager & MCP plugin for WordPress is vulnerable to authorization bypass in |
| 2026-08-25 | CVE-2026-55529 | MCP01 — Token Mismanagement & Secret Exposure | PraisonAI is a multi-agent teams system |
| 2026-08-25 | CVE-2026-55531 | MCP05 — Command Injection & Execution | PraisonAI is a multi-agent teams system |
| 2026-08-25 | CVE-2026-55532 | MCP01 — Token Mismanagement & Secret Exposure | PraisonAI is a multi-agent teams system |
| 2026-08-25 | CVE-2026-55546 | MCP01 — Token Mismanagement & Secret Exposure | QWED-MCP is a deterministic verification gateway for MCP |
| 2026-08-25 | CVE-2026-55580 | MCP04 — Software Supply Chain Attacks & Dependency Tampering | mcp-shell is an MCP server for running shell commands securely, auditably, and on demand |
| 2026-08-25 | CVE-2026-55581 | MCP01 — Token Mismanagement & Secret Exposure | mcp-shell is an MCP server for running shell commands securely, auditably, and on demand |
| 2026-08-25 | CVE-2026-55582 | MCP05 — Command Injection & Execution | mcp-shell is an MCP server for running shell commands securely, auditably, and on demand |
| 2026-08-25 | CVE-2026-55640 | MCP01 — Token Mismanagement & Secret Exposure | Nextcloud MCP Server is a production-ready MCP server that connects AI assistants to a Nextcloud instance |
| 2026-08-24 | CVE-2026-78430 | MCP05 — Command Injection & Execution | A vulnerability was detected in sworddut mcp-ffmpeg-helper 0.1.0/0.1.1/0.2.1 |
| 2026-08-22 | CVE-2026-59809 | MCP01 — Token Mismanagement & Secret Exposure | SiYuan before v3.8.0 interpolates secret placeholders into the destination URL parameter of the http_request MCP tool, allowing attackers to exfiltrat |
| 2026-08-22 | CVE-2026-60083 | MCP01 — Token Mismanagement & Secret Exposure | SiYuan versions before v3.8.0 contain an incomplete path blocklist in the MCP file tool that fails to restrict access to sensitive workspace files pro |
| 2026-08-21 | CVE-2026-53509 | MCP05 — Command Injection & Execution | CKAN MCP Server is a tool for querying CKAN open data portals |
| 2026-08-21 | CVE-2026-59279 | MCP05 — Command Injection & Execution | The MCP Streamable HTTP server transport (WebFlux and WebMvc variants) does not place any limit on the number of sessions it retains, and by default d |
| 2026-08-21 | CVE-2026-62674 | MCP01 — Token Mismanagement & Secret Exposure | Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents |
| 2026-08-20 | CVE-2026-18482 | MCP05 — Command Injection & Execution | Neo.mjs contains a command injection vulnerability within the FileSystemService.mjs component of the ai/mcp/server/file-system MCP server, where the c |
| 2026-08-20 | CVE-2026-72846 | MCP05 — Command Injection & Execution | Lightdash stores the webhook URL supplied with a scheduled delivery and later posts to it from sendWebhook in packages/backend/src/clients/GoogleChat/ |
| 2026-08-20 | CVE-2026-77068 | MCP02 — Privilege Escalation via Scope Creep | n8n before 2.33.4 and 2.34.x before 2.34.1 contain a remote code execution vulnerability in the @n8n/workflow-sdk node-schema loader used for MCP node |
| 2026-08-20 | CVE-2026-77073 | MCP01 — Token Mismanagement & Secret Exposure | n8n versions before 2.34.1 contain a credential validation bypass in the MCP create_workflow_from_code tool when authentication type is set to an expr |
| 2026-08-19 | CVE-2026-75149 | MCP04 — Software Supply Chain Attacks & Dependency Tampering | marimo before 0.23.15 contains a code injection vulnerability in the notebook configuration handler that allows attackers to execute arbitrary command |
| 2026-08-19 | CVE-2026-76404 | MCP01 — Token Mismanagement & Secret Exposure | In Splunk MCP Server app versions below 1.2.1, a user who holds the "admin" Splunk role could execute arbitrary commands on the underlying operating s |
| 2026-08-18 | CVE-2026-34884 | MCP05 — Command Injection & Execution | SSRF via set_skywalking_url Tool and GraphQL expression injection vulnerability in Apache SkyWalking MCP |
| 2026-08-18 | CVE-2026-75130 | MCP01 — Token Mismanagement & Secret Exposure | Context7 through 2.1.2 contains a prompt injection vulnerability that allows attackers to execute malicious instructions in connected AI coding agents |
| 2026-08-18 | CVE-2026-75845 | MCP02 — Privilege Escalation via Scope Creep | ArcadeDB versions 26.4.2 through 26.7.3 contain an authorization bypass vulnerability in the set_server_setting MCP server-level tool |
| 2026-08-18 | CVE-2026-75857 | MCP05 — Command Injection & Execution | CodeWhale versions >= 0.8.41 and < 0.8.64 contain a vulnerability in the exec_shell_interact (alias exec_interact) tool, whose approval_requirement re |
| 2026-08-18 | CVE-2026-75858 | MCP04 — Software Supply Chain Attacks & Dependency Tampering | CodeWhale (packages codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain a remote code execution vulnerability in the rlm_eval tool |
| 2026-08-17 | CVE-2026-19984 | MCP04 — Software Supply Chain Attacks & Dependency Tampering | A flaw has been found in jkawamoto mcp-florence2 up to 0.3.13 |
| 2026-08-17 | CVE-2026-71424 | MCP01 — Token Mismanagement & Secret Exposure | Onyx is an open-source AI platform |
| 2026-08-17 | CVE-2026-74798 | MCP02 — Privilege Escalation via Scope Creep | SiYuan kernel before v3.7.4 contains a path traversal vulnerability in the database_clean MCP tool |
| 2026-08-17 | CVE-2026-75060 | MCP05 — Command Injection & Execution | In JetBrains PyCharm before 2026.2.1 code execution was possible via unauthenticated Jupyter MCP tools |
| 2026-08-14 | CVE-2026-49986 | MCP04 — Software Supply Chain Attacks & Dependency Tampering | The Cortex MCP server (neuro-cortex-memory), a cross-platform persistent memory MCP, prior to version 3.17.1 treats the CLAUDE_PROJECT_DIR environ |
| 2026-08-14 | CVE-2026-50027 | MCP01 — Token Mismanagement & Secret Exposure | mcp-memory-service is a semantic memory layer for AI applications |
| 2026-08-14 | CVE-2026-73844 | MCP05 — Command Injection & Execution | CKAN MCP Server is a tool for querying CKAN open data portals |
| 2026-08-14 | CVE-2026-73845 | MCP05 — Command Injection & Execution | CKAN MCP Server is a tool for querying CKAN open data portals |
| 2026-08-14 | CVE-2026-73846 | MCP08 — Lack of Audit and Telemetry | CKAN MCP Server is a tool for querying CKAN open data portals |
| 2026-08-13 | CVE-2026-19751 | MCP05 — Command Injection & Execution | A flaw has been found in EnzoVezzaro mcp-dominican-layer up to 39dd373786712650097ad31db27d5c477c8f9c82 |
| 2026-08-13 | CVE-2026-19752 | MCP05 — Command Injection & Execution | A vulnerability was found in EnzoVezzaro mcp-dominican-layer up to 39dd373786712650097ad31db27d5c477c8f9c82 |
| 2026-08-13 | CVE-2026-19753 | MCP05 — Command Injection & Execution | A vulnerability was detected in Model Context Protocol mcp-rdf-explorer 1.0.0 |
| 2026-08-13 | CVE-2026-49856 | MCP05 — Command Injection & Execution | @jshookmcp/jshook is an MCP server that gives AI agents tools for JavaScript analysis and security research |
| 2026-08-13 | CVE-2026-49857 | MCP04 — Software Supply Chain Attacks & Dependency Tampering | auth-fetch-mcp is an MCP server that lets AI assistants fetch content from authenticated web pages |
| 2026-08-13 | CVE-2026-73037 | MCP01 — Token Mismanagement & Secret Exposure | Next AI Draw.io 0.2.1 through 0.4.16 contains a reflected cross-site scripting vulnerability in the mcp query parameter that is interpolated without e |
| 2026-08-13 | CVE-2026-73601 | MCP05 — Command Injection & Execution | Flowise versions before 3.1.3 contain a remote code execution vulnerability in the Custom MCP node when CUSTOM_MCP_PROTOCOL is set to stdio, allowing |
| 2026-08-12 | CVE-2026-73296 | MCP05 — Command Injection & Execution | Microsoft UFO open-source framework for intelligent automation across devices and platforms |
| 2026-08-11 | CVE-2026-19516 | MCP01 — Token Mismanagement & Secret Exposure | A caller-supplied X-Grafana-URL request header controls the destination of mcp-grafana's outbound requests, and the grafana_api_request tool lets the |
| 2026-08-11 | CVE-2026-72768 | MCP05 — Command Injection & Execution | n8n versions before 2.32.1 contain a server-side request forgery protection bypass vulnerability in the MCP Client node that allows authenticated user |
| 2026-08-09 | CVE-2026-19329 | MCP05 — Command Injection & Execution | A vulnerability was found in andreahaku codex_mcp up to 1ff521cc6cc57cfe56ddef946c644b8534771390 |
| 2026-08-09 | CVE-2026-19332 | MCP05 — Command Injection & Execution | A security vulnerability has been detected in NellyW8 MCP4EDA 1.0.0 |
| 2026-08-09 | CVE-2026-19337 | MCP05 — Command Injection & Execution | A vulnerability was determined in adenot mcp-google-search up to 0.3.1 |
| 2026-08-09 | CVE-2026-19338 | MCP02 — Privilege Escalation via Scope Creep | A vulnerability was identified in automateyournetwork MCPyATS up to 0.1.4 |
| 2026-08-08 | CVE-2026-19263 | MCP05 — Command Injection & Execution | A vulnerability was found in INQUIRELAB mcp-bridge-api up to b30a82aa1d1d1139e0de846c41c8aadee6e06114 |
| 2026-08-08 | CVE-2026-19268 | MCP05 — Command Injection & Execution | A vulnerability was identified in abdullah1854 MCPGateway up to 549f494a9e363f40530149de324b8097de424230 |
| 2026-08-08 | CVE-2026-19270 | MCP02 — Privilege Escalation via Scope Creep | A security flaw has been discovered in Hulupeep mcp-ui-probe up to 0.2.0 |
| 2026-08-08 | CVE-2026-19279 | MCP05 — Command Injection & Execution | A vulnerability was identified in MIMICLab mcp-pdf-vision 1.1.0 |
| 2026-08-07 | CVE-2026-19244 | MCP02 — Privilege Escalation via Scope Creep | A vulnerability was detected in HKUDS nanobot up to 0.2.1 |
| 2026-08-07 | CVE-2026-48039 | MCP01 — Token Mismanagement & Secret Exposure | Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads |
| 2026-08-06 | CVE-2026-19039 | MCP05 — Command Injection & Execution | A vulnerability was detected in Kino-Kafkaesque ssh-mcp-server up to 8ebbbb99b26f80ff6162fe00957c6dec73fbc5a5 |
| 2026-08-06 | CVE-2026-19040 | MCP05 — Command Injection & Execution | A flaw has been found in MissionSquad mcp-api up to 1.11.9 |
| 2026-08-06 | CVE-2026-19041 | MCP04 — Software Supply Chain Attacks & Dependency Tampering | A vulnerability has been found in MissionSquad mcp-api up to 1.11.8 |
| 2026-08-06 | CVE-2026-67531 | MCP01 — Token Mismanagement & Secret Exposure | FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP) |
| 2026-08-05 | CVE-2026-17623 | MCP04 — Software Supply Chain Attacks & Dependency Tampering | IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper validation of the comm |
| 2026-08-05 | CVE-2026-17626 | MCP01 — Token Mismanagement & Secret Exposure | IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow an authenticated attacker to read, modify, or expose sensitive host files via Docker-based |
| 2026-08-05 | CVE-2026-18954 | MCP02 — Privilege Escalation via Scope Creep | Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server before 1.0.12 might allow an authenticated MCP clien |
| 2026-08-05 | CVE-2026-7646 | MCP01 — Token Mismanagement & Secret Exposure | IBM Langflow OSS 1.0.0 through 1.10.3 allows users to read arbitrary files from the server filesystem, including other users' uploaded documents, the |
| 2026-08-05 | CVE-2026-8446 | MCP04 — Software Supply Chain Attacks & Dependency Tampering | IBM Langflow OSS 1.0.0 through 1.10.3 contain an authentication bypass vulnerability in the Model Context Protocol (MCP) composer endpoint when mcp_co |
| 2026-08-05 | CVE-2026-9077 | MCP04 — Software Supply Chain Attacks & Dependency Tampering | IBM Langflow OSS 1.0.0 through 1.10.3 Langflow allows remote authenticated attackers to bypass localhost-only restrictions and write arbitrary MCP ser |
| 2026-08-04 | CVE-2026-69257 | MCP05 — Command Injection & Execution | Flowise is a drag & drop user interface to build a customized large language model flow |
| 2026-08-04 | CVE-2026-69263 | MCP04 — Software Supply Chain Attacks & Dependency Tampering | Flowise is a drag & drop user interface to build a customized large language model flow |
| 2026-08-03 | CVE-2026-18655 | MCP01 — Token Mismanagement & Secret Exposure | Improper restriction of intended endpoints in the RabbitMQ broker connection tools of the Amazon MQ MCP Server (awslabs.amazon-mq-mcp-server) before 2 |
| 2026-08-03 | CVE-2026-66065 | MCP04 — Software Supply Chain Attacks & Dependency Tampering | Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to constrain behavior |
| 2026-08-02 | CVE-2026-67357 | MCP01 — Token Mismanagement & Secret Exposure | ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability in the MCP get_server_settings tool that leaks the arcadedb.ha.cluster |
| 2026-08-02 | CVE-2026-68578 | MCP02 — Privilege Escalation via Scope Creep | ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP transport, causing all engine permission checks to silently p |
| 2026-08-01 | CVE-2026-15988 | MCP01 — Token Mismanagement & Secret Exposure | The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, |
| 2026-08-01 | CVE-2026-67333 | MCP05 — Command Injection & Execution | better-auth before 1.6.13 (and pre-release builds 1.7.0-beta.0 through 1.7.0-beta.3) fail to validate the scheme of redirect_uris registered via the d |
| 2026-08-01 | CVE-2026-67336 | MCP01 — Token Mismanagement & Secret Exposure | better-auth versions before 1.6.11 contain insecure cryptographic defaults in the oidcProvider and mcp plugins that advertise the none algorithm and a |
| 2026-07-31 | CVE-2026-14537 | MCP02 — Privilege Escalation via Scope Creep | Incorrect Authorization in the direct HTTP API tool invocation endpoint in Google mcp-toolbox versions v1.3.0 and v1.4.0 allows an unauthenticated att |
| 2026-07-31 | CVE-2026-14538 | MCP02 — Privilege Escalation via Scope Creep | An improper authorization and security-boundary bypass vulnerability in the bigquery-execute-sql tool component of Google mcp-toolbox versions 0.16.1 |
| 2026-07-31 | CVE-2026-14539 | MCP05 — Command Injection & Execution | An allocation of resources without limits vulnerability in the HTTP handler component of Google mcp-toolbox versions up to and including 1.4.0 allows |
| 2026-07-31 | CVE-2026-14540 | MCP04 — Software Supply Chain Attacks & Dependency Tampering | A Server-Side Request Forgery (SSRF) vulnerability exists in the generic HTTP source and tool components of Google mcp-toolbox versions 0.3.0 through |
| 2026-07-31 | CVE-2026-14541 | MCP01 — Token Mismanagement & Secret Exposure | An authentication bypass and audience confusion vulnerability exists in the Google OAuth provider component of Google mcp-toolbox version 1.4.0 |
| 2026-07-31 | CVE-2026-54785 | MCP02 — Privilege Escalation via Scope Creep | gemini-bridge is a lightweight MCP server bridging AI agents to Google's Gemini AI via the official CLI |
| 2026-07-30 | CVE-2026-12940 | MCP05 — Command Injection & Execution | IBM Langflow OSS 1.0.0 through 1.10.1 are vulnerable to unauthenticated remote code execution via environment variable injection in the MCP (Model Con |
| 2026-07-28 | CVE-2026-16496 | MCP01 — Token Mismanagement & Secret Exposure | The terraform-mcp-server before version 1.1.0 is vulnerable to an authorization bypass in the streamable-HTTP stateful transport mode that may allow a |
| 2026-07-28 | CVE-2026-47427 | MCP01 — Token Mismanagement & Secret Exposure | GitHub MCP Server is GitHub's official MCP Server |
| 2026-07-28 | CVE-2026-9680 | MCP05 — Command Injection & Execution | Improper exposure of the MCP server in alibabacloud-rds-openapi-mcp-server allows remote attackers to invoke exposed MCP tools via network access to a |
| 2026-07-26 | CVE-2026-17433 | MCP02 — Privilege Escalation via Scope Creep | A vulnerability was detected in nanocoai NanoClaw up to 2.0.64 |
| 2026-07-25 | CVE-2026-66012 | MCP01 — Token Mismanagement & Secret Exposure | SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (mod |
| 2026-07-24 | CVE-2026-66005 | MCP01 — Token Mismanagement & Secret Exposure | Jan through 0.8.4, fixed in commit 3e1c1e7, contains a CORS misconfiguration vulnerability in its local API server that allows network-adjacent attack |
| 2026-07-23 | CVE-2026-15015 | MCP01 — Token Mismanagement & Secret Exposure | The MountDev AI MCP Connector for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.6.1 |
| 2026-07-23 | CVE-2026-16584 | MCP01 — Token Mismanagement & Secret Exposure | Improper handling of an initialization failure in AWS API MCP Server from 0.2.13 through 1.3.46 might allow an actor to bypass the user-configured sec |
| 2026-07-23 | CVE-2026-47769 | MCP05 — Command Injection & Execution | APIFold reads an OpenAPI 3.x or Swagger 2.x specification and generates a live, production-ready MCP server endpoint |
| 2026-07-23 | CVE-2026-63732 | MCP01 — Token Mismanagement & Secret Exposure | 9router 0.4.59 (fixed in 0.4.60) contains a chain of vulnerabilities: a hardcoded default password (123456) that authenticates any fresh installation, |
| 2026-07-22 | CVE-2026-44192 | MCP01 — Token Mismanagement & Secret Exposure | A flaw was found in the Ansible Lightspeed Model Context Protocol (MCP) server |
| 2026-07-22 | CVE-2026-65594 | MCP01 — Token Mismanagement & Secret Exposure | n8n before 2.29.8 and 2.30.x before 2.30.1 (affected from 2.27.0, when the OAuth 2.1 consent and token-issuance flow was introduced) does not verify t |
| 2026-07-21 | CVE-2026-15829 | MCP02 — Privilege Escalation via Scope Creep | A SQL injection (CWE-89) and security boundary bypass (CWE-863) vulnerability exists in the prebuilt BigQuery forecasting tool (bigquery-forecast) of |
| 2026-07-21 | CVE-2026-47394 | MCP01 — Token Mismanagement & Secret Exposure | PraisonAI is a multi-agent teams system |
| 2026-07-21 | CVE-2026-47708 | MCP05 — Command Injection & Execution | MCP-for-Stata is an MCP server for Stata to integrate Stata into an agent |
| 2026-07-21 | CVE-2026-50758 | MCP05 — Command Injection & Execution | Cross Site Scripting vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to execute arbitrary code via the mcp parameter |
| 2026-07-21 | CVE-2026-65056 | MCP01 — Token Mismanagement & Secret Exposure | mcp-webresearch 0.1.7 contains a server-side request forgery vulnerability that allows attackers to access internal network services by supplying loop |
| 2026-07-20 | CVE-2026-46555 | MCP01 — Token Mismanagement & Secret Exposure | WhatsApp MCP Server is a Model Context Protocol (MCP) server for WhatsApp, enabling Claude to read and send WhatsApp messages |
| 2026-07-20 | CVE-2026-55544 | MCP01 — Token Mismanagement & Secret Exposure | NextCRM is open-source customer relationship management (CRM) software |
| 2026-07-20 | CVE-2026-55550 | MCP01 — Token Mismanagement & Secret Exposure | NextCRM is open-source customer relationship management (CRM) software |
| 2026-07-20 | CVE-2026-57495 | MCP02 — Privilege Escalation via Scope Creep | AgenticMail gives AI agents real email addresses and phone numbers |
| 2026-07-18 | CVE-2026-16133 | MCP05 — Command Injection & Execution | A flaw has been found in LiuMengxuan04 MiniCode 0.1.0 |
| 2026-07-17 | CVE-2026-15415 | MCP02 — Privilege Escalation via Scope Creep | AWS HealthOmics is a HIPAA-eligible service that fully manages the compute, storage, and workflow engine infrastructure required to run bioinformatics |
| 2026-07-17 | CVE-2026-57860 | MCP04 — Software Supply Chain Attacks & Dependency Tampering | ForgeCode (tailcallhq/forgecode), an AI pair-programming CLI, automatically loads and executes the MCP servers defined in a repository's .mcp.json fil |
| 2026-07-17 | CVE-2026-58195 | MCP05 — Command Injection & Execution | Agentic-Flow is an AI agent orchestration platform |
| 2026-07-17 | CVE-2026-62208 | MCP01 — Token Mismanagement & Secret Exposure | OpenClaw before 2026.6.5 could forward Authorization headers during MCP SSE redirects |
| 2026-07-17 | CVE-2026-7755 | MCP04 — Software Supply Chain Attacks & Dependency Tampering | IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to incomplete validation enforcement on MCP server configuration |
| 2026-07-17 | CVE-2026-9135 | MCP04 — Software Supply Chain Attacks & Dependency Tampering | IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc33a32d) contain a code injection vulnera |
| 2026-07-17 | CVE-2026-9810 | MCP01 — Token Mismanagement & Secret Exposure | The AI Copilot WordPress plugin before 1.5.4 does not bind OAuth access tokens to a WordPress user, and accepts any valid token as an administrator se |
| 2026-07-16 | CVE-2026-46512 | MCP05 — Command Injection & Execution | Frogman provides headless PBX control through MCP and HTTP API |
| 2026-07-16 | CVE-2026-46513 | MCP01 — Token Mismanagement & Secret Exposure | Frogman provides headless PBX control through MCP and HTTP API |
| 2026-07-16 | CVE-2026-46514 | MCP01 — Token Mismanagement & Secret Exposure | Frogman provides headless PBX control through MCP and HTTP API |
| 2026-07-16 | CVE-2026-46515 | MCP01 — Token Mismanagement & Secret Exposure | Frogman provides headless PBX control through MCP and HTTP API |
| 2026-07-15 | CVE-2026-15583 | MCP01 — Token Mismanagement & Secret Exposure | A confused-deputy flaw in Grafana MCP Server allows an unauthenticated remote attacker to exfiltrate the server's environment-configured Grafana servi |
| 2026-07-15 | CVE-2026-49353 | MCP01 — Token Mismanagement & Secret Exposure | 9Router is an AI router & token saver |
| 2026-07-15 | CVE-2026-49988 | MCP01 — Token Mismanagement & Secret Exposure | Repomix is a tool that packs repositories into AI-friendly files |
| 2026-07-15 | CVE-2026-53512 | MCP01 — Token Mismanagement & Secret Exposure | Better Auth is an authentication and authorization library for TypeScript |
| 2026-07-15 | CVE-2026-53518 | MCP01 — Token Mismanagement & Secret Exposure | Better Auth is an authentication and authorization library for TypeScript |
| 2026-07-15 | CVE-2026-54052 | MCP01 — Token Mismanagement & Secret Exposure | n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations |
| 2026-07-15 | CVE-2026-55608 | MCP02 — Privilege Escalation via Scope Creep | n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations |
| 2026-07-15 | CVE-2026-61427 | MCP01 — Token Mismanagement & Secret Exposure | PraisonAI before 4.6.78 exposes the MCP HTTP-stream transport without authentication by default: the CLI --api-key option defaults to None, and the se |
| 2026-07-15 | CVE-2026-62312 | MCP01 — Token Mismanagement & Secret Exposure | 9Router is an AI router & token saver |
| 2026-07-14 | CVE-2026-15643 | MCP01 — Token Mismanagement & Secret Exposure | AWS HealthLake MCP Server (awslabs.healthlake-mcp-server) is a Model Context Protocol server that enables AI assistants to interact with AWS HealthLak |
| 2026-07-14 | CVE-2026-15749 | MCP02 — Privilege Escalation via Scope Creep | A security flaw has been discovered in mastergo-design mastergo-magic-mcp up to 0.2.0 |
| 2026-07-14 | CVE-2026-15750 | MCP05 — Command Injection & Execution | A weakness has been identified in mastergo-design mastergo-magic-mcp up to 0.2.0 |
| 2026-07-14 | CVE-2026-15751 | MCP02 — Privilege Escalation via Scope Creep | A security vulnerability has been detected in mastergo-design mastergo-magic-mcp up to 0.2.0 |
| 2026-07-13 | CVE-2026-58500 | MCP05 — Command Injection & Execution | MCP Appium is an MCP server that provides AI assistants with tools to automate mobile app testing on Android and iOS |
| 2026-07-13 | CVE-2026-61462 | MCP01 — Token Mismanagement & Secret Exposure | mcp-gitlab contains a path traversal vulnerability in the job_id parameter of build/index.js that allows attackers to redirect GitLab API requests to |
| 2026-07-13 | CVE-2026-62195 | MCP02 — Privilege Escalation via Scope Creep | OpenClaw versions 2026.5.20 before 2026.6.6 contain an authorization bypass vulnerability in the MCP loopback feature that allows lower-trust callers |
| 2026-07-12 | CVE-2026-15501 | MCP04 — Software Supply Chain Attacks & Dependency Tampering | A security vulnerability has been detected in AstrBotDevs AstrBot up to 4.25.2 |
| 2026-07-10 | CVE-2026-54149 | MCP04 — Software Supply Chain Attacks & Dependency Tampering | MaxKB is an open-source AI assistant for enterprise |
| 2026-07-09 | CVE-2026-15138 | MCP02 — Privilege Escalation via Scope Creep | A security vulnerability has been detected in tumf mcp-text-editor up to 1.0.2 |
| 2026-07-09 | CVE-2026-15189 | MCP05 — Command Injection & Execution | A security vulnerability has been detected in aerostackdev aerostack-mcp up to 6315dfde7df0a15aaf743f88d91347115e09ba23 |
| 2026-07-09 | CVE-2026-55604 | MCP02 — Privilege Escalation via Scope Creep | DeepSeek MCP Server is an MCP server for DeepSeek V4 |
| 2026-07-09 | CVE-2026-55605 | MCP01 — Token Mismanagement & Secret Exposure | DeepSeek MCP Server is an MCP server for DeepSeek V4 |
| 2026-07-09 | CVE-2026-59207 | MCP01 — Token Mismanagement & Secret Exposure | n8n is an open source workflow automation platform |
| 2026-07-09 | CVE-2026-59726 | MCP01 — Token Mismanagement & Secret Exposure | Ruflo is an agent meta-harness for Claude Code and Codex |
| 2026-07-08 | CVE-2026-59723 | MCP01 — Token Mismanagement & Secret Exposure | Cline is an autonomous coding agent as an SDK, IDE extension, or CLI assistant |
| 2026-07-08 | CVE-2026-59822 | MCP01 — Token Mismanagement & Secret Exposure | LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format |
| 2026-07-07 | CVE-2026-49471 | MCP05 — Command Injection & Execution | Serena is a powerful MCP toolkit for coding that provides semantic retrieval and editing capabilities |
| 2026-07-06 | CVE-2026-14471 | MCP05 — Command Injection & Execution | Improper Neutralization of Special Elements in the metrics-service retention policy management component in Amazon mcp-gateway-registry before 1.0.13 |
| 2026-07-05 | CVE-2026-14748 | MCP05 — Command Injection & Execution | A flaw has been found in AIAnytime Awesome-MCP-Server up to a884bb51bcd99e08e14fd712c749d55d9d9a13ab |
| 2026-07-02 | CVE-2026-52830 | MCP01 — Token Mismanagement & Secret Exposure | fast-mcp-telegram is a Telegram MCP Server |
| 2026-07-01 | CVE-2026-10750 | MCP01 — Token Mismanagement & Secret Exposure | The Royal MCP WordPress plugin before 1.4.26 does not perform capability checks on the majority of its MCP tools after token authentication, allowing |
CVE Information schema (template)
| Field | Value |
|---|---|
| CVE / NVD | CVE-YYYY-NNNNN |
| Date (index) | YYYY-MM-DD |
| Affected product (index) | |
| GHSA ID | |
| OWASP MCP Top 10 (2025) | MCP0X — … |
| Published / disclosed | YYYY-MM-DD |
| Ecosystem | <e.g. npm, PyPI — or omit row> |
| Component | <specific component — or omit row> |
| EPSS score | |
| CVSS score | <score + version — or omit row> |
| CWE | CWE-… |
| Affected versions | |
| Fixed versions | |
| Fix status | <Patched / Unfixed / unknown / …> |
| Exploit status | <Public advisory / PoC / …> |
| Notes | <optional — or omit row> |
Contribution Rules for This Section
Use these rules in your repository contribution guide:
A vulnerability entry must include:
- CVE ID and GHSA ID, if available.
- Affected component and version.
- Fixed version or mitigation.
- Severity and source.
- Root cause category.
- Exploit / PoC safety label.
- At least one official reference.
- Defensive notes.
Do not submit:
- Unverified rumors as confirmed CVEs.
- Working exploit payloads in the README.
- Duplicate advisories without linking aliases.
- Vulnerabilities that merely mention “MCP” but have no MCP security relevance.
Установка Cve Project
У этого сервера нет опубликованного пакета — он собирается из исходников. Открой репозиторий и следуй инструкции в README.
▸ github.com/mcp-security-project/mcp-cve-projectFAQ
Cve Project MCP бесплатный?
Да, Cve Project MCP бесплатный — установка в пару кликов через Unyly без оплаты.
Нужен ли API-ключ для Cve Project?
Нет, Cve Project работает без API-ключей и переменных окружения.
Cve Project — hosted или self-hosted?
Self-hosted: сервер запускается локально на твоей машине командой из раздела установки.
Как установить Cve Project в Claude Desktop, Claude Code или Cursor?
Открой Cve Project на unyly.org, выбери вкладку своего клиента (Claude Desktop, Claude Code, Cursor) и нажми Install — конфиг сгенерируется автоматически, без правки JSON.
Похожие MCP
Fetch
Web content fetching and conversion for efficient LLM usage.
Roblox Studio
Enables AI coding tools to control Roblox Studio for workspace exploration, instance manipulation, and script management. It provides tools for playtesting, sce
автор: paralovAWS KB Retrieval
Retrieval from AWS Knowledge Base using Bedrock Agent Runtime.
автор: modelcontextprotocolSpring AI MCP Server
Provides auto-configuration for setting up an MCP server in Spring Boot applications.
llm-analysis-assistant
A very streamlined mcp client that supports calling and monitoring stdio/sse/streamableHttp, and can also view request responses through the /logs page. It also
автор: xuzexin-hzMCP-Agent
A simple, composable framework to build agents using Model Context Protocol by [LastMile AI](https://www.lastmileai.dev)
автор: lastmile-aiSpring AI MCP Client
Provides auto-configuration for MCP client functionality in Spring Boot applications.
mcp.natoma.ai
A Hosted MCP Platform to discover, install, manage and deploy MCP servers by [Natoma Labs](https://www.natoma.ai)
MCPHub
Website to list high quality MCP servers and reviews by real users. Also provide online chatbot for popular LLM models with MCP server support.
MCP Servers Rating and User Reviews
Website to rate MCP servers, write authentic user reviews, and [search engine for agent & mcp](http://www.deepnlp.org/search/agent)
Compare Cve Project with
Не уверен что выбрать?
Найди свой стек за 60 секунд
Автор?
Embed-бейдж для README
Похожее
Все в категории ai
