漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Meta Ads MCP: Unauthenticated HTTP MCP Tool Execution Leaks Operator Meta Access Token
Vulnerability Description
Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.109, `AuthInjectionMiddleware.dispatch()` at `http_auth_integration.py:272` unconditionally forwards unauthenticated Streamable HTTP requests to downstream MCP tool handlers without issuing a `401` response, allowing any network-reachable caller to invoke MCP tools without authentication. When no per-request credential is present, tool handlers fall back to the `META_ACCESS_TOKEN` environment variable, and when the downstream Meta Graph API call fails, `api.py:263–269` serialises the raw `httpx` request URL—including the operator's `access_token` as a query parameter—into the JSON-RPC response body, delivering the credential to the unauthenticated caller. Version 1.0.109 fixes the issue.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Vulnerability Type
认证机制不恰当
Vulnerability Title
pipeboard-co Meta Ads MCP 授权问题漏洞
Vulnerability Description
pipeboard-co Meta Ads MCP是pipeboard-co组织的一款整合广告投放与办公流程的智能连接组件。 pipeboard-co Meta Ads MCP 1.0.109之前版本存在授权问题漏洞,该漏洞源于AuthInjectionMiddleware.dispatch()无条件转发未认证的Streamable HTTP请求且未返回401响应,导致任意网络可达调用者无需认证即可调用MCP工具;当无请求凭证时工具处理器回退到META_ACCESS_TOKEN环境变量,且下游Meta G
CVSS Information
N/A
Vulnerability Type
N/A