MCP-related CVE reference

This repository is a curated index of publicly disclosed Common Vulnerabilities and Exposures (CVEs) that touch the Model Context Protocol (MCP) ecosystem: official and third-party servers, SDKs, gateways, clients, and integrations where MCP is part of the attack surface or fix scope. Each linked note under [cves/](https://github.com/mcp-security-project/mcp-cve-project/blob/main/cves/) summarizes the affected component, weakness class, and pointers for defenders and maintainers.

Coverage: 313 indexed CVEs (indexed below, newest first by disclosure-related date).

Maintained and curated by Vandana Verma Sehgal.

OWASP MCP Top 10 (2025) mapping

Indexed CVEs are mapped to the primary category in the OWASP MCP Top 10 (2025). Mappings use NVD/CWE and index summaries where available. A CVE may relate to more than one MCP risk; only the primary mapping is shown in the tables below.

ID Category Count
MCP01 Token Mismanagement & Secret Exposure 18
MCP02 Privilege Escalation via Scope Creep 42
MCP03 Tool Poisoning 2
MCP04 Software Supply Chain Attacks & Dependency Tampering 12
MCP05 Command Injection & Execution 131
MCP06 Prompt Injection via Contextual Payloads 7
MCP07 Insufficient Authentication & Authorization 72
MCP08 Lack of Audit and Telemetry 3
MCP09 Shadow MCP Servers 21
MCP10 Context Injection & Over-Sharing 5

CVE Breakdown

2026

S.No Date CVE OWASP MCP Top 10 (2025) Affected product
1 2026‑07‑17 CVE‑2026‑50143 MCP01 — Token Mismanagement & Secret Exposure @apify/actors-mcp-server Actor webServerMcpPath authority injection / Apify token leak
2 2026‑07‑15 CVE‑2026‑59950 MCP07 — Insufficient Authentication & Authorization MCP Python SDK (mcp): deprecated WebSocket transport Host/Origin validation gap
3 2026‑07‑10 CVE‑2026‑61459 MCP02 — Privilege Escalation via Scope Creep mcp-server-kubernetes structured tools --server argument injection / bearer token exfiltration
4 2026‑07‑08 CVE‑2026‑63118 MCP07 — Insufficient Authentication & Authorization MCP Ruby SDK (modelcontextprotocol/ruby-sdk): Streamable HTTP DNS rebinding
5 2026‑07‑08 CVE‑2026‑63119 MCP07 — Insufficient Authentication & Authorization MCP Ruby SDK (modelcontextprotocol/ruby-sdk): stdio unbounded line buffer DoS
6 2026‑07‑03 CVE‑2026‑13341 MCP06 — Prompt Injection via Contextual Payloads Kong Konnect MCP server (mcp-konnect) indirect prompt injection
7 2026‑06‑30 CVE‑2026‑7663 MCP07 — Insufficient Authentication & Authorization IBM Langflow Streamable MCP authorization bypass
8 2026‑06‑30 CVE‑2026‑58446 MCP07 — Insufficient Authentication & Authorization Presenton bundled MCP server unauthenticated /mcp access
9 2026‑06‑30 CVE‑2026‑58171 MCP02 — Privilege Escalation via Scope Creep Vibe-Trading path traversal affecting MCP/agent workflow storage
10 2026‑06‑30 CVE‑2026‑58168 MCP07 — Insufficient Authentication & Authorization DeepTutor MCP tool authorization bypass
11 2026‑06‑29 CVE‑2026‑13524 MCP07 — Insufficient Authentication & Authorization Cherry Studio MCP OAuth local callback issue
12 2026‑06‑28 CVE‑2026‑58057 MCP05 — Command Injection & Execution Flowise Custom MCP Windows env-var denylist bypass
13 2026‑06‑28 CVE‑2026‑13489 MCP07 — Insufficient Authentication & Authorization xiaozhi-esp32 MCP response handler validation issue
14 2026‑06‑26 CVE‑2026‑57922 MCP01 — Token Mismanagement & Secret Exposure JetBrains YouTrack project settings disclosure via MCP
15 2026‑06‑26 CVE‑2026‑48529 MCP02 — Privilege Escalation via Scope Creep GitHub MCP Server HTTP lockdown-mode repo access cache issue
16 2026‑06‑26 CVE‑2026‑4339 MCP05 — Command Injection & Execution Mattermost Agents plugin MCP server internal/private IP validation issue
17 2026‑06‑25 CVE‑2026‑54842 MCP07 — Insufficient Authentication & Authorization Royal MCP missing authorization
18 2026‑06‑25 CVE‑2026‑54030 MCP07 — Insufficient Authentication & Authorization LibreChat MCP OAuth resource validation issue
19 2026‑06‑24 CVE‑2026‑57300 MCP07 — Insufficient Authentication & Authorization Jenkins MCP Server Plugin missing permission check
20 2026‑06‑24 CVE‑2026‑53766 MCP02 — Privilege Escalation via Scope Creep chrome-devtools-mcp workspace path validation issue
21 2026‑06‑24 CVE‑2026‑12958 MCP02 — Privilege Escalation via Scope Creep Amazon Q Developer / Language Servers for AWS (symlink write outside workspace trust boundary)
22 2026‑06‑24 CVE‑2026‑12957 MCP09 — Shadow MCP Servers Amazon Q Developer / Language Servers for AWS (.amazonq/mcp.json auto-execution)
23 2026‑06‑24 CVE‑2026‑12537 MCP09 — Shadow MCP Servers Google Gemini CLI / run-gemini-cli GitHub Action
24 2026‑06‑23 CVE‑2026‑56274 MCP05 — Command Injection & Execution Flowise Custom MCP Server command injection
25 2026‑06‑23 CVE‑2026‑54309 MCP07 — Insufficient Authentication & Authorization @n8n/mcp-browser unauthenticated HTTP transport
26 2026‑06‑23 CVE‑2026‑47388 MCP02 — Privilege Escalation via Scope Creep NocoDB MCP token attachment ownership bypass / file read
27 2026‑06‑23 CVE‑2026‑46549 MCP02 — Privilege Escalation via Scope Creep NocoDB MCP OAuth token scope bypass
28 2026‑06‑23 CVE‑2026‑12112 MCP07 — Insufficient Authentication & Authorization foreman-mcp-server session hijack via non-secret session IDs
29 2026‑06‑22 CVE‑2026‑7664 MCP07 — Insufficient Authentication & Authorization IBM Langflow Streamable MCP authorization bypass
30 2026‑06‑22 CVE‑2026‑10789 MCP05 — Command Injection & Execution Autodesk Fusion Desktop MCP extension arbitrary code execution
31 2026‑06‑21 CVE‑2026‑12798 MCP05 — Command Injection & Execution LiteLLM OpenAPI-to-MCP generator SSRF
32 2026‑06‑21 CVE‑2026‑12774 MCP05 — Command Injection & Execution LiteLLM MCP connection testing SSRF
33 2026‑06‑21 CVE‑2026‑12773 MCP07 — Insufficient Authentication & Authorization LiteLLM MCP Proxy improper authentication
34 2026‑06‑19 CVE‑2026‑49357 MCP07 — Insufficient Authentication & Authorization line-desktop-mcp unauthenticated HTTP mode chat access
35 2026‑06‑19 CVE‑2026‑49291 MCP02 — Privilege Escalation via Scope Creep mcp-memory-service OAuth read-scope tools/call bypass
36 2026‑06‑19 CVE‑2026‑48787 MCP05 — Command Injection & Execution gin-vue-admin MCP management code-generation command injection
37 2026‑06‑19 CVE‑2026‑48774 MCP02 — Privilege Escalation via Scope Creep ProxySQL GenAI/MCP run_sql_readonly multi-statement bypass
38 2026‑06‑18 CVE‑2026‑55887 MCP05 — Command Injection & Execution Docker MCP Gateway (github.com/docker/mcp-gateway)
39 2026‑06‑18 CVE‑2026‑49257 MCP07 — Insufficient Authentication & Authorization mcp-pinot unauthenticated 0.0.0.0 HTTP MCP server
40 2026‑06‑18 CVE‑2026‑11719 MCP02 — Privilege Escalation via Scope Creep MCP Toolbox for Databases protocol-version scope bypass
41 2026‑06‑17 CVE‑2026‑48989 MCP07 — Insufficient Authentication & Authorization Windows-MCP unauthenticated HTTP control plane / PowerShell execution
42 2026‑06‑17 CVE‑2026‑48814 MCP07 — Insufficient Authentication & Authorization Network-AI MCP SSE unauthenticated tool invocation
43 2026‑06‑16 CVE‑2026‑53840 MCP01 — Token Mismanagement & Secret Exposure OpenClaw Streamable HTTP MCP custom-header leak on redirects
44 2026‑06‑15 CVE‑2026‑40775 MCP07 — Insufficient Authentication & Authorization Royal MCP unauthenticated broken access control
45 2026‑06‑13 CVE‑2026‑11624 MCP07 — Insufficient Authentication & Authorization MCP Origin/Host validation gap for DNS rebinding controls
46 2026‑06‑12 CVE‑2026‑53820 MCP05 — Command Injection & Execution OpenClaw bundled MCP exec denylist bypass
47 2026‑06‑12 CVE‑2026‑50287 MCP07 — Insufficient Authentication & Authorization @agenticmail/mcp unauthenticated Streamable HTTP endpoint
48 2026‑06‑11 CVE‑2026‑53818 MCP07 — Insufficient Authentication & Authorization OpenClaw MCP loopback owner-only policy bypass
49 2026‑06‑11 CVE‑2026‑53814 MCP02 — Privilege Escalation via Scope Creep OpenClaw hook-triggered MCP loopback privilege escalation
50 2026‑06‑11 CVE‑2026‑47250 MCP02 — Privilege Escalation via Scope Creep mcp-server-kubernetes kubectl_generic unsafe flags / token exfiltration
51 2026‑06‑05 CVE‑2026‑52869 MCP07 — Insufficient Authentication & Authorization MCP Python SDK (mcp): HTTP session auth bypass (SseServerTransport / Streamable HTTP)
52 2026‑06‑05 CVE‑2026‑52870 MCP07 — Insufficient Authentication & Authorization MCP Python SDK (mcp): experimental task handlers cross-client access
53 2026‑06‑04 CVE‑2026‑54449 MCP09 — Shadow MCP Servers LangBot
54 2026‑06‑02 CVE‑2026‑44653 MCP07 — Insufficient Authentication & Authorization LibreChat — GET /api/mcp/servers returns plaintext apiKey.key and oauth.client_secret to VIEW-only users
55 2026‑06‑02 CVE‑2026‑42073 MCP07 — Insufficient Authentication & Authorization OpenClaude MCP OAuth callback CSRF state bypass / DoS
56 2026‑06‑02 CVE‑2026‑32625 MCP01 — Token Mismanagement & Secret Exposure LibreChat — MCP server URL ${VAR} interpolation exfiltrates JWT_SECRET, CREDS_KEY, CREDS_IV, MONGO_URI
57 2026‑06‑01 CVE‑2026‑10280 MCP05 — Command Injection & Execution mcpilot MCP API call endpoint SSRF via serverBaseUrl
58 2026‑06‑01 CVE‑2026‑10277 MCP02 — Privilege Escalation via Scope Creep mcp-google-workspace Gmail saveToDisk improper access controls
59 2026‑05‑29 CVE‑2026‑47751 MCP04 — Software Supply Chain Attacks & Dependency Tampering Anthropic Claude Code Action (claude-code-action)
60 2026‑05‑29 CVE‑2026‑45707 MCP07 — Insufficient Authentication & Authorization n8n-mcp multi-tenant HTTP transport authentication gap
61 2026‑05‑29 CVE‑2026‑45609 MCP05 — Command Injection & Execution Spring AI mcp-security missing MCP-spec SSRF mitigations
62 2026‑05‑29 CVE‑2026‑45582 MCP01 — Token Mismanagement & Secret Exposure n8n-MCP (czlonkowski/n8n-mcp)
63 2026‑05‑29 CVE‑2026‑45555 MCP05 — Command Injection & Execution Roslyn CodeLens MCP Server arbitrary DiagnosticAnalyzer load
64 2026‑05‑26 CVE‑2026‑48710 MCP07 — Insufficient Authentication & Authorization Starlette / FastAPI-based MCP and AI gateways
65 2026‑05‑19 CVE‑2026‑46341 MCP02 — Privilege Escalation via Scope Creep @apify/actors-mcp-server
66 2026‑05‑19 CVE‑2026‑46339 MCP07 — Insufficient Authentication & Authorization 9router MCP routes
67 2026‑05‑19 CVE‑2026‑45805 MCP07 — Insufficient Authentication & Authorization @penpot/mcp
68 2026‑05‑18 CVE‑2026‑46519 MCP02 — Privilege Escalation via Scope Creep mcp-server-kubernetes
69 2026‑05‑15 CVE‑2026‑44717 MCP05 — Command Injection & Execution MCP Calculate Server
70 2026‑05‑14 CVE‑2026‑44895 MCP07 — Insufficient Authentication & Authorization GitLab MCP Server (HTTP transport without authentication)
71 2026‑05‑14 CVE‑2026‑44830 MCP07 — Insufficient Authentication & Authorization Nocturne Memory MCP server (missing auth when token unset)
72 2026‑05‑14 CVE‑2026‑44284 MCP05 — Command Injection & Execution FastGPT (MCP tool URL SSRF gap)
73 2026‑05‑14 CVE‑2026‑42559 MCP07 — Insufficient Authentication & Authorization MCP Rust SDK (rmcp crate): Streamable HTTP server transport DNS rebinding
74 2026‑05‑14 CVE‑2026‑34163 MCP07 — Insufficient Authentication & Authorization FastGPT (MCP tools endpoint auth gap)
75 2026‑05‑12 CVE‑2026‑5029 MCP07 — Insufficient Authentication & Authorization Code Runner MCP Server
76 2026‑05‑12 CVE‑2026‑45781 MCP02 — Privilege Escalation via Scope Creep MCP Registry
77 2026‑05‑12 CVE‑2026‑43992 MCP01 — Token Mismanagement & Secret Exposure JunoClaw
78 2026‑05‑12 CVE‑2026‑42260 MCP05 — Command Injection & Execution Open-WebSearch MCP server
79 2026‑05‑11 CVE‑2026‑45001 MCP04 — Software Supply Chain Attacks & Dependency Tampering OpenClaw
80 2026‑05‑11 CVE‑2026‑44998 MCP03 — Tool Poisoning OpenClaw
81 2026‑05‑11 CVE‑2026‑44995 MCP05 — Command Injection & Execution OpenClaw
82 2026‑05‑11 CVE‑2026‑44450 MCP05 — Command Injection & Execution Lumiverse (MCP server command allowlist bypass)
83 2026‑05‑11 CVE‑2026‑44430 MCP05 — Command Injection & Execution MCP Registry
84 2026‑05‑11 CVE‑2026‑44429 MCP05 — Command Injection & Execution MCP Registry
85 2026‑05‑11 CVE‑2026‑44428 MCP07 — Insufficient Authentication & Authorization MCP Registry
86 2026‑05‑11 CVE‑2026‑44427 MCP07 — Insufficient Authentication & Authorization MCP Registry
87 2026‑05‑11 CVE‑2026‑43901 MCP02 — Privilege Escalation via Scope Creep Wireshark MCP (wireshark-mcp)
88 2026‑05‑10 CVE‑2026‑7738 MCP02 — Privilege Escalation via Scope Creep doc-tools-mcp
89 2026‑05‑09 CVE‑2026‑7729 MCP05 — Command Injection & Execution directus-mcp
90 2026‑05‑09 CVE‑2026‑7728 MCP02 — Privilege Escalation via Scope Creep mcp-rtfm
91 2026‑05‑09 CVE‑2026‑7715 MCP02 — Privilege Escalation via Scope Creep mcp-server-arangodb
92 2026‑05‑08 CVE‑2026‑7653 MCP05 — Command Injection & Execution mcp-server-rijksmuseum
93 2026‑05‑08 CVE‑2026‑7628 MCP05 — Command Injection & Execution mcp-code-review-server
94 2026‑05‑08 CVE‑2026‑7627 MCP02 — Privilege Escalation via Scope Creep metatrader-4-mcp
95 2026‑05‑08 CVE‑2026‑44694 MCP05 — Command Injection & Execution n8n-mcp
96 2026‑05‑08 CVE‑2026‑44336 MCP05 — Command Injection & Execution PraisonAI MCP tools/call path traversal to RCE via .pth injection
97 2026‑05‑08 CVE‑2026‑42282 MCP08 — Lack of Audit and Telemetry n8n-mcp
98 2026‑05‑08 CVE‑2026‑42271 MCP05 — Command Injection & Execution LiteLLM MCP server preview endpoints
99 2026‑05‑08 CVE‑2026‑41495 MCP08 — Lack of Audit and Telemetry n8n-mcp
100 2026‑05‑07 CVE‑2026‑7600 MCP05 — Command Injection & Execution mcp-server-yii2
101 2026‑05‑07 CVE‑2026‑7599 MCP05 — Command Injection & Execution terminalcraft
102 2026‑05‑07 CVE‑2026‑7594 MCP02 — Privilege Escalation via Scope Creep DungeonMind-MCP
103 2026‑05‑07 CVE‑2026‑7593 MCP05 — Command Injection & Execution command-executor-mcp-server
104 2026‑05‑07 CVE‑2026‑42449 MCP05 — Command Injection & Execution n8n-mcp
105 2026‑05‑06 CVE‑2026‑7446 MCP05 — Command Injection & Execution mcp-server-semgrep
106 2026‑05‑06 CVE‑2026‑7443 MCP05 — Command Injection & Execution mcp-dnstwist
107 2026‑05‑06 CVE‑2026‑44118 MCP07 — Insufficient Authentication & Authorization OpenClaw (loopback MCP owner-context spoofing)
108 2026‑05‑05 CVE‑2026‑7386 MCP05 — Command Injection & Execution mail-mcp-bridge
109 2026‑05‑05 CVE‑2026‑35228 MCP05 — Command Injection & Execution Oracle MCP Server Helper Tool (SQL injection)
110 2026‑05‑04 CVE‑2026‑7730 MCP05 — Command Injection & Execution privsim/mcp-test-runner
111 2026‑05‑04 CVE‑2026‑42236 MCP07 — Insufficient Authentication & Authorization n8n (MCP OAuth client registration DoS)