Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

modelcontextprotocol — Vulnerabilities & Security Advisories 33

Browse all 33 CVE security advisories affecting modelcontextprotocol. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Modelcontextprotocol serves as an interface for AI model interactions, enabling secure data exchange between applications and language models. Historically, it has been susceptible to remote code execution, cross-site scripting, and privilege escalation vulnerabilities, often stemming from improper input validation and insecure API endpoints. The protocol's security posture has been challenged by multiple critical flaws, including several that allowed unauthorized access to sensitive data or system compromise. With 19 CVEs documented, the implementation has faced recurring issues around authentication and authorization, highlighting challenges in securing complex AI integrations. While no major public incidents have been widely reported, the volume of reported vulnerabilities indicates ongoing security concerns that require rigorous patch management and secure coding practices.

CVE ID Title CVSS Severity Published
CVE-2026-67432 MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransport — ruby-sdk CWE-770 7.5 High 2026-07-29
CVE-2026-67431 MCP Ruby SDK: Ruby SSE Session Poisoning — ruby-sdk CWE-284 8.3 High 2026-07-29
CVE-2026-63119 MCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhaustion (DoS) — ruby-sdk CWE-400 6.2 Medium 2026-07-29
CVE-2026-67430 MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize flood — ruby-sdk CWE-401 5.3 Medium 2026-07-29
CVE-2026-63118 MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protection — ruby-sdk CWE-346 6.9 Medium 2026-07-29
CVE-2026-59950 MCP Python SDK: WebSocket server transport does not support Host/Origin validation — python-sdk CWE-346 - - 2026-07-15
CVE-2026-52870 MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks — python-sdk CWE-862 7.6 High 2026-07-15
CVE-2026-52869 MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal — python-sdk CWE-639 7.1 High 2026-07-15
CVE-2026-44428 MCP Registry: GitHub OIDC tokens replayable across registry deployments due to shared audience — registry CWE-918 - - 2026-05-14
CVE-2026-44427 MCP Registry: Open Redirect — registry CWE-601 - - 2026-05-14
CVE-2026-44429 MCP Registry: Stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled `websiteUrl` — registry CWE-79 - - 2026-05-14
CVE-2026-44430 MCP Registry: Unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist — registry CWE-918 - - 2026-05-14
CVE-2026-45781 MCP Registry: OCI ownership validation fails open on upstream rate limits, allowing attacker-controlled package claims — registry CWE-636 3.5 Low 2026-05-14
CVE-2026-42559 RMCP: DNS rebinding vulnerability in rmcp Streamable HTTP server transport — rust-sdk CWE-346 8.8 High 2026-05-14
CVE-2026-35568 MCP Java-SDK has a DNS Rebinding Vulnerability — java-sdk CWE-346 6.3AI Medium AI 2026-04-07
CVE-2026-34742 Model Context Protocol Go SDK: DNS Rebinding Protection Disabled by Default for Servers Running on Localhost — go-sdk CWE-1188 7.1AI High AI 2026-04-02
CVE-2026-34237 MCP Java SDK has a Hardcoded Wildcard CORS (Access-Control-Allow-Origin: *) — java-sdk CWE-942 6.1 Medium 2026-03-31
CVE-2026-33946 MCP Ruby SDK: Insufficient Session Binding Allows SSE Stream Hijacking via Session ID Replay — ruby-sdk CWE-384 8.2 - 2026-03-27
CVE-2026-33252 MCP Go SDK Allows Cross-Site Tool Execution for HTTP Servers without Authorizatrion — go-sdk CWE-352 7.1 High 2026-03-23
CVE-2026-27896 MCP Go SDK Vulnerable to Improper Handling of Case Sensitivity — go-sdk CWE-178 9.1AI Critical AI 2026-02-26
CVE-2026-27735 mcp-server-git : Path traversal in git_add allows staging files outside repository boundaries — servers CWE-22 8.6AI High AI 2026-02-25
CVE-2026-25536 @modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse — typescript-sdk CWE-362 7.1 High 2026-02-04
CVE-2025-68145 mcp-server-git has missing path validation when using --repository flag — servers CWE-22 9.8AI Critical AI 2025-12-17
CVE-2025-68144 mcp-server-git argument injection in git_diff and git_checkout functions allows overwriting local files — servers CWE-88 9.1AI Critical AI 2025-12-17
CVE-2025-68143 mcp-server-git's unrestricted git_init tool allows repository creation at arbitrary filesystem locations — servers CWE-22 9.1AI Critical AI 2025-12-17
CVE-2025-66416 DNS Rebinding Protection Disabled by Default in Model Context Protocol Python SDK for Servers Running on Localhost — python-sdk CWE-1188 7.1 - 2025-12-02
CVE-2025-66414 DNS Rebinding Protection Disabled by Default in Model Context Protocol TypeScript SDK for Servers Running on Localhost — typescript-sdk CWE-1188 7.5AI High AI 2025-12-02
CVE-2025-58444 MCP Inspector is Vulnerable to Potential Command Execution via XSS When Connecting to an Untrusted MCP Server — inspector CWE-84 6.1AI Medium AI 2025-09-08
CVE-2025-53366 MCP SDK Vulnerable to FastMCP Server Validation Error, Leading to Denial of Service — python-sdk CWE-248 7.5 - 2025-07-04
CVE-2025-53365 MCP Python SDK has Unhandled Exception in Streamable HTTP Transport ,Leading to Denial of Service — python-sdk CWE-248 7.5 - 2025-07-04

This page lists every published CVE security advisory associated with modelcontextprotocol. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.