Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

modelcontextprotocol — Vulnerabilities & Security Advisories 33

Browse all 33 CVE security advisories affecting modelcontextprotocol. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Modelcontextprotocol serves as an interface for AI model interactions, enabling secure data exchange between applications and language models. Historically, it has been susceptible to remote code execution, cross-site scripting, and privilege escalation vulnerabilities, often stemming from improper input validation and insecure API endpoints. The protocol's security posture has been challenged by multiple critical flaws, including several that allowed unauthorized access to sensitive data or system compromise. With 19 CVEs documented, the implementation has faced recurring issues around authentication and authorization, highlighting challenges in securing complex AI integrations. While no major public incidents have been widely reported, the volume of reported vulnerabilities indicates ongoing security concerns that require rigorous patch management and secure coding practices.

High2026-07-30
Bound Request Body and Frame Reads to Prevent Memory-Exhaustion DoS · modelcontextprotocol/ruby-sdk@772e0cb · GitHub
HighCVE-2026-674312026-07-30
Ruby SSE Session Poisoning · Advisory · modelcontextprotocol/ruby-sdk · GitHub
HighCVE-2025-674302026-07-30
Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize flood · Advisory · modelc
Medium2026-07-30
Bound Stateful Session Retention to Prevent an Initialize-Flood DoS · modelcontextprotocol/ruby-sdk@afb968c · GitHub
Medium2026-07-30
Unbounded line buffer in stdio transports leads to memory exhaustion (DoS) · Advisory · modelcontextprotocol/ruby-sdk ·
High2026-07-30
Bound stdio frame reads with max_line_bytes · modelcontextprotocol/ruby-sdk@267b8fa · GitHub
HighCVE-2026-599502026-07-16
WebSocket server transport does not support Host/Origin validation · Advisory · modelcontextprotocol/python-sdk · GitHub
MediumCVE-2024-343372026-04-02
Hardcoded Wildcard CORS (Access-Control-Allow-Origin: *) · Advisory · modelcontextprotocol/java-sdk · GitHub
HighCVE-2025-584442025-09-10
Potential Command Execution in MCP Inspector via XSS When Connecting to an Untrusted MCP Server · Advisory · modelcontex
HighCVE-2025-533652025-07-06
Unhandled Exception in Streamable HTTP Transport Leading to Denial of Service · Advisory · modelcontextprotocol/python-s
HighCVE-2025-531092025-07-06
Path validation bypass via symlink handling · Advisory · modelcontextprotocol/servers · GitHub

Showing up to 20 recent security advisories. View all →

This page lists every published CVE security advisory associated with modelcontextprotocol. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.