MCP Registry是Model Context Protocol开源的一个MCP服务器应用商店。 MCP Registry 1.7.6之前版本存在代码问题漏洞,该漏洞源于客户端和服务器端GitHub OIDC流程仅绑定到全局受众字符串而非特定注册表实例,导致从一个注册表部署合法获取的令牌可被其他共享相同代码和受众字符串的部署接受。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| modelcontextprotocol | registry | < 1.7.6 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| modelcontextprotocol | registry | < 1.7.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-42559 | 8.8 HIGH | RMCP: DNS rebinding vulnerability in rmcp Streamable HTTP server transport |
| CVE-2026-45781 | 3.5 LOW | MCP Registry: OCI ownership validation fails open on upstream rate limits, allowing attack |
| CVE-2026-44429 | MCP Registry: Stored XSS in catalogue UI via attribute-quote breakout in publisher-control | |
| CVE-2026-44430 | MCP Registry: Unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site- | |
| CVE-2026-44427 | MCP Registry: Open Redirect |
No comments yet