HashiCorp Tooling是美国HashiCorp公司的系统工具组件。 HashiCorp Tooling 1.1.0之前版本存在会话机制问题漏洞,该漏洞源于streamable-HTTP stateful transport模式存在授权绕过,可能允许用户获取其他用户的MCP session ID后使用该用户的Terraform凭据执行工具调用。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-16498 | 10.0 CRITICAL | terraform-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP statel |
| CVE-2026-14869 | 8.6 HIGH | terraform-mcp-server vulnerable to server side request forgery leading to token exposure |
No comments yet