Prompt Injection and Credential Exposure via Untrusted Analytics Data in Kong Konnect MCP
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.4epss 0.4%
exploitation probability
0.4%top 62% of all CVEs
observed exploitation
nono source reports it
A vulnerability exists in the Kong Konnect Model Context Protocol (MCP) server prior to version 1.0.0, which could allow a remote attacker to perform an indirect prompt injection attack and execute unintended API requests.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
Affected products
KongHQ · mcp-konnect