Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Meta Ads MCP: Unauthenticated HTTP MCP Tool Execution Leaks Operator Meta Access Token
Vulnerability Description
Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.109, `AuthInjectionMiddleware.dispatch()` at `http_auth_integration.py:272` unconditionally forwards unauthenticated Streamable HTTP requests to downstream MCP tool handlers without issuing a `401` response, allowing any network-reachable caller to invoke MCP tools without authentication. When no per-request credential is present, tool handlers fall back to the `META_ACCESS_TOKEN` environment variable, and when the downstream Meta Graph API call fails, `api.py:263–269` serialises the raw `httpx` request URL—including the operator's `access_token` as a query parameter—into the JSON-RPC response body, delivering the credential to the unauthenticated caller. Version 1.0.109 fixes the issue.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Vulnerability Type
认证机制不恰当
Vulnerability Title
pipeboard-co Meta Ads MCP 授权问题漏洞
Vulnerability Description
pipeboard-co Meta Ads MCP是pipeboard-co组织的一款整合广告投放与办公流程的智能连接组件。 pipeboard-co Meta Ads MCP 1.0.109之前版本存在授权问题漏洞,该漏洞源于AuthInjectionMiddleware.dispatch()无条件转发未认证的Streamable HTTP请求且未返回401响应,导致任意网络可达调用者无需认证即可调用MCP工具;当无请求凭证时工具处理器回退到META_ACCESS_TOKEN环境变量,且下游Meta G
CVSS Information
N/A
Vulnerability Type
N/A