Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-54547— Meta Ads MCP: X-Pipeboard-Token Header Auth Bypass Reuses Operator Meta Token

Quick assessment

Affected
pipeboard-co meta-ads-mcp
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Meta Ads MCP 是一个模型上下文协议(MCP)服务器,允许 AI 助手操作 Meta 广告。在版本 1.0.115 之前, 中的 仅在 和 同时缺失时才拒绝 HTTP MCP 请求;而 并不将 视为主要凭证。因此,使用 streamable-http 传输的网络调用方可以发送任意值的 ,从而绕过鉴权守卫而未建立认证上下文,导致 回退到服务器操作员的 。随后执行的 MCP 工具会以操作员的 Meta 凭证运行,能够读取或修改操作员的 Meta 广告数据。使用默认 stdio 传输或未配置 的部署不受此问题影

CVSS 7.4 · High

Affected Version Matrix 1

VendorProduct Version RangeStatus
pipeboard-co meta-ads-mcp < 1.0.115 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-54547

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Meta Ads MCP: X-Pipeboard-Token Header Auth Bypass Reuses Operator Meta Token
Source: CVE Program / CVE List V5
Vulnerability Description
Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.115, AuthInjectionMiddleware in meta_ads_mcp/core/http_auth_integration.py rejects HTTP MCP requests only when both auth_token and pipeboard_token are absent, while extract_token_from_headers() does not recognize X-Pipeboard-Token as a primary credential. A network caller using the streamable-http transport can therefore send any X-Pipeboard-Token value, pass the guard without establishing authentication context, and cause get_auth_token() to fall back to the server operator's META_ACCESS_TOKEN. Subsequent MCP tools execute with the operator's Meta credentials and can read or modify the operator's Meta Ads data. Deployments using the default stdio transport or without META_ACCESS_TOKEN are not affected. This issue is fixed in version 1.0.115.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
认证机制不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
pipeboard-co meta-ads-mcp < 1.0.115 -

II. Public POCs for CVE-2026-54547

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-54547

登录查看更多情报信息。

Patches & Fixes for CVE-2026-54547 (2)

Vendor Advisories for CVE-2026-54547 (1)

Vendor Pages for CVE-2026-54547 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-54547

No comments yet


Leave a comment