目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2026-104634— Beam MCP JSON布尔和空值参数被解析为字符串漏洞

一分钟漏洞结论

影响对象
ScriptKittyOS beam_mcp
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

漏洞描述:BeamMCP.Server 中存在不正确的类型转换或强制转换漏洞 在 ScriptKittyOS 的 项目中,存在一个“不正确的类型转换或强制转换”(Incorrect Type Conversion or Cast)漏洞。该漏洞允许 MCP 客户端发送的 JSON 类型参数 、 和 ,在传递到主机(host)的分发函数时,被错误地转换为字符串 、 和 。 具体来说,在 函数验证某个值为布尔类型后, 函数会将所有参数逐一通过 函数处理。该函数中的原子(atom)条款会将 、 和 转换为字符串。在 Eli

CVSS 2.3 · Low

影响版本矩阵 2

厂商产品 版本范围状态
ScriptKittyOS beam_mcp 0.1.0< 0.10.1 affected
083838eb8e17fe5f6fcaf761bdbe203110288b0b< 289dbdbad641943b29a3b8d1eb36506cc8cec10a affected
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-104634 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
beam_mcp: JSON boolean and null tool arguments reach dispatch as strings
来源: CVE Program / CVE List V5
Vulnerability Description
Incorrect Type Conversion or Cast vulnerability in BeamMCP.Server in ScriptKittyOS beam_mcp allows an MCP client's JSON true, false and null tool arguments to reach the host's dispatch function as the strings "true", "false" and "nil". After BeamMCP.Schema.validate/2 accepted a value as a boolean, normalize_arguments/2 passed every argument through to_json_value/1, whose atom clause converts true, false and nil to strings. A string is truthy in Elixir, so a host that tests a boolean argument, for example if args.dry_run, takes the opposite branch for false, and a guard such as confirm: false reads as set. The client controls the argument and could send true directly, so the practical impact is limited to hosts whose behaviour on false differs from their behaviour on true, and to any policy layer in front of the server that permits false but refuses true. The same normalisation applies to prompts/get arguments, which exist from 0.5.0. This issue affects beam_mcp: from 0.1.0 before 0.10.1.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
来源: CVE Program / CVE List V5
Vulnerability Type
不正确的类型转换
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
ScriptKittyOS beam_mcp 0.1.0 ~ 0.10.1 cpe:2.3:a:scriptkittyos:beam_mcp:*:*:*:*:*:*:*:*
ScriptKittyOS beam_mcp 083838eb8e17fe5f6fcaf761bdbe203110288b0b ~ 289dbdbad641943b29a3b8d1eb36506cc8cec10a cpe:2.3:a:scriptkittyos:beam_mcp:*:*:*:*:*:*:*:*

二、漏洞 CVE-2026-104634 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-104634 的情报信息

请登录查看更多情报信息。

CVE-2026-104634 厂商安全公告 (2)

CVE-2026-104634 其他参考 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-104634

暂无评论


发表评论