Vulnerabilidades en modelcontextprotocol

38 resultados
Análisis Vexday

O Model Context Protocol apresenta 28 vulnerabilidades catalogadas, com 9 publicadas nos últimos 90 dias, indicando atividade de descoberta contínua. Nenhuma vulnerabilidade está sob ataque ativo no momento, mas a fraqueza dominante em path traversal (CWE-22) merece monitoramento, especialmente dado o volume recente de divulgações. O risco atual é moderado, com apenas 1 vulnerabilidade crítica na base.

CVE-2025-49596CRITICALMCP Inspector proxy server lacks authentication between the Inspector client and proxyEPSS 44.5%CVE-2025-68143MEDIUMmcp-server-git's unrestricted git_init tool allows repository creation at arbitrary filesystem locationsEPSS 8.1%CVE-2025-53366HIGHMCP SDK Vulnerable to FastMCP Server Validation Error, Leading to Denial of ServiceEPSS 7.3%CVE-2025-68144MEDIUMmcp-server-git argument injection in git_diff and git_checkout functions allows overwriting local filesEPSS 7.2%CVE-2025-68145MEDIUMmcp-server-git has missing path validation when using --repository flagEPSS 7.0%CVE-2025-53109HIGHModel Context Protocol Servers Vulnerable to Path Validation Bypass via Prefix Matching and Symlink HandlingEPSS 0.7%CVE-2025-58444HIGHMCP Inspector is Vulnerable to Potential Command Execution via XSS When Connecting to an Untrusted MCP ServerEPSS 0.7%CVE-2025-53110HIGHModel Context Protocol Servers Vulnerable to Path Validation Bypass via Colliding Path PrefixEPSS 0.6%CVE-2026-63128HIGHRMCP: Unauthenticated permanent session-table leak in rmcp Streamable HTTP server transport leads to remote denial-of-serviceEPSS 0.5%CVE-2026-52869HIGHMCP Python SDK: HTTP transports serve session requests without verifying the authenticated principalEPSS 0.5%CVE-2025-66416HIGHDNS Rebinding Protection Disabled by Default in Model Context Protocol Python SDK for Servers Running on LocalhostEPSS 0.5%CVE-2025-66414HIGHDNS Rebinding Protection Disabled by Default in Model Context Protocol TypeScript SDK for Servers Running on LocalhostEPSS 0.5%CVE-2026-33946HIGHMCP Ruby SDK: Insufficient Session Binding Allows SSE Stream Hijacking via Session ID ReplayEPSS 0.5%CVE-2026-34742HIGHModel Context Protocol Go SDK: DNS Rebinding Protection Disabled by Default for Servers Running on LocalhostEPSS 0.5%CVE-2026-67432HIGHMCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransportEPSS 0.4%CVE-2026-44427NONEMCP Registry: Open RedirectEPSS 0.4%CVE-2026-64684MEDIUMRMCP: Custom HTTP headers leak to cross-origin redirect targetsEPSS 0.4%CVE-2026-52870HIGHMCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasksEPSS 0.4%CVE-2025-53365HIGHMCP Python SDK has Unhandled Exception in Streamable HTTP Transport ,Leading to Denial of ServiceEPSS 0.4%CVE-2026-53965MEDIUMMCP PHP SDK: Unbounded SSE buffer in HttpTransport enables client-side denial of serviceEPSS 0.4%