MCP Registry是Model Context Protocol开源的一个MCP服务器应用商店。 MCP Registry 1.1.0至1.7.4版本存在输入验证错误漏洞,该漏洞源于TrailingSlashMiddleware存在开放重定向攻击,攻击者可构造协议相对路径的URL,在移除尾部斜杠后生成Location头为//evil.com,浏览器将其解释为外部域绝对URL。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| modelcontextprotocol | registry | >= 1.1.0, < 1.7.5 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| modelcontextprotocol | registry | >= 1.1.0, < 1.7.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-42559 | 8.8 HIGH | RMCP: DNS rebinding vulnerability in rmcp Streamable HTTP server transport |
| CVE-2026-45781 | 3.5 LOW | MCP Registry: OCI ownership validation fails open on upstream rate limits, allowing attack |
| CVE-2026-44429 | MCP Registry: Stored XSS in catalogue UI via attribute-quote breakout in publisher-control | |
| CVE-2026-44430 | MCP Registry: Unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site- | |
| CVE-2026-44428 | MCP Registry: GitHub OIDC tokens replayable across registry deployments due to shared audi |
No comments yet