MCP Registry是Model Context Protocol开源的一个MCP服务器应用商店。 MCP Registry 1.7.7之前版本存在跨站脚本漏洞,该漏洞源于公共目录UI,服务器端验证仅检查URL是否可解析、绝对且使用https方案,未拒绝引号字符,客户端通过innerHTML将值插值到双引号href属性中,escapeHtml助手未编码引号,导致攻击者可注入任意事件处理程序。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| modelcontextprotocol | registry | < 1.7.7 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| modelcontextprotocol | registry | < 1.7.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-42559 | 8.8 HIGH | RMCP: DNS rebinding vulnerability in rmcp Streamable HTTP server transport |
| CVE-2026-45781 | 3.5 LOW | MCP Registry: OCI ownership validation fails open on upstream rate limits, allowing attack |
| CVE-2026-44430 | MCP Registry: Unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site- | |
| CVE-2026-44427 | MCP Registry: Open Redirect | |
| CVE-2026-44428 | MCP Registry: GitHub OIDC tokens replayable across registry deployments due to shared audi |
No comments yet