MCP-related CVE reference
This repository is a curated index of publicly disclosed Common Vulnerabilities and Exposures (CVEs) that touch the Model Context Protocol (MCP) ecosystem: official and third-party servers, SDKs, gateways, clients, and integrations where MCP is part of the attack surface or fix scope. Each linked note under [cves/](https://github.com/mcp-security-project/mcp-cve-project/blob/main/cves/) summarizes the affected component, weakness class, and pointers for defenders and maintainers.
Coverage: 313 indexed CVEs (indexed below, newest first by disclosure-related date).
Maintained and curated by Vandana Verma Sehgal.
OWASP MCP Top 10 (2025) mapping
Indexed CVEs are mapped to the primary category in the OWASP MCP Top 10 (2025). Mappings use NVD/CWE and index summaries where available. A CVE may relate to more than one MCP risk; only the primary mapping is shown in the tables below.
| ID | Category | Count |
|---|---|---|
| MCP01 | Token Mismanagement & Secret Exposure | 18 |
| MCP02 | Privilege Escalation via Scope Creep | 42 |
| MCP03 | Tool Poisoning | 2 |
| MCP04 | Software Supply Chain Attacks & Dependency Tampering | 12 |
| MCP05 | Command Injection & Execution | 131 |
| MCP06 | Prompt Injection via Contextual Payloads | 7 |
| MCP07 | Insufficient Authentication & Authorization | 72 |
| MCP08 | Lack of Audit and Telemetry | 3 |
| MCP09 | Shadow MCP Servers | 21 |
| MCP10 | Context Injection & Over-Sharing | 5 |
CVE Breakdown
2026
| S.No | Date | CVE | OWASP MCP Top 10 (2025) | Affected product |
|---|---|---|---|---|
| 1 | 2026‑07‑17 | CVE‑2026‑50143 | MCP01 — Token Mismanagement & Secret Exposure | @apify/actors-mcp-server Actor webServerMcpPath authority injection / Apify token leak |
| 2 | 2026‑07‑15 | CVE‑2026‑59950 | MCP07 — Insufficient Authentication & Authorization | MCP Python SDK (mcp): deprecated WebSocket transport Host/Origin validation gap |
| 3 | 2026‑07‑10 | CVE‑2026‑61459 | MCP02 — Privilege Escalation via Scope Creep | mcp-server-kubernetes structured tools --server argument injection / bearer token exfiltration |
| 4 | 2026‑07‑08 | CVE‑2026‑63118 | MCP07 — Insufficient Authentication & Authorization | MCP Ruby SDK (modelcontextprotocol/ruby-sdk): Streamable HTTP DNS rebinding |
| 5 | 2026‑07‑08 | CVE‑2026‑63119 | MCP07 — Insufficient Authentication & Authorization | MCP Ruby SDK (modelcontextprotocol/ruby-sdk): stdio unbounded line buffer DoS |
| 6 | 2026‑07‑03 | CVE‑2026‑13341 | MCP06 — Prompt Injection via Contextual Payloads | Kong Konnect MCP server (mcp-konnect) indirect prompt injection |
| 7 | 2026‑06‑30 | CVE‑2026‑7663 | MCP07 — Insufficient Authentication & Authorization | IBM Langflow Streamable MCP authorization bypass |
| 8 | 2026‑06‑30 | CVE‑2026‑58446 | MCP07 — Insufficient Authentication & Authorization | Presenton bundled MCP server unauthenticated /mcp access |
| 9 | 2026‑06‑30 | CVE‑2026‑58171 | MCP02 — Privilege Escalation via Scope Creep | Vibe-Trading path traversal affecting MCP/agent workflow storage |
| 10 | 2026‑06‑30 | CVE‑2026‑58168 | MCP07 — Insufficient Authentication & Authorization | DeepTutor MCP tool authorization bypass |
| 11 | 2026‑06‑29 | CVE‑2026‑13524 | MCP07 — Insufficient Authentication & Authorization | Cherry Studio MCP OAuth local callback issue |
| 12 | 2026‑06‑28 | CVE‑2026‑58057 | MCP05 — Command Injection & Execution | Flowise Custom MCP Windows env-var denylist bypass |
| 13 | 2026‑06‑28 | CVE‑2026‑13489 | MCP07 — Insufficient Authentication & Authorization | xiaozhi-esp32 MCP response handler validation issue |
| 14 | 2026‑06‑26 | CVE‑2026‑57922 | MCP01 — Token Mismanagement & Secret Exposure | JetBrains YouTrack project settings disclosure via MCP |
| 15 | 2026‑06‑26 | CVE‑2026‑48529 | MCP02 — Privilege Escalation via Scope Creep | GitHub MCP Server HTTP lockdown-mode repo access cache issue |
| 16 | 2026‑06‑26 | CVE‑2026‑4339 | MCP05 — Command Injection & Execution | Mattermost Agents plugin MCP server internal/private IP validation issue |
| 17 | 2026‑06‑25 | CVE‑2026‑54842 | MCP07 — Insufficient Authentication & Authorization | Royal MCP missing authorization |
| 18 | 2026‑06‑25 | CVE‑2026‑54030 | MCP07 — Insufficient Authentication & Authorization | LibreChat MCP OAuth resource validation issue |
| 19 | 2026‑06‑24 | CVE‑2026‑57300 | MCP07 — Insufficient Authentication & Authorization | Jenkins MCP Server Plugin missing permission check |
| 20 | 2026‑06‑24 | CVE‑2026‑53766 | MCP02 — Privilege Escalation via Scope Creep | chrome-devtools-mcp workspace path validation issue |
| 21 | 2026‑06‑24 | CVE‑2026‑12958 | MCP02 — Privilege Escalation via Scope Creep | Amazon Q Developer / Language Servers for AWS (symlink write outside workspace trust boundary) |
| 22 | 2026‑06‑24 | CVE‑2026‑12957 | MCP09 — Shadow MCP Servers | Amazon Q Developer / Language Servers for AWS (.amazonq/mcp.json auto-execution) |
| 23 | 2026‑06‑24 | CVE‑2026‑12537 | MCP09 — Shadow MCP Servers | Google Gemini CLI / run-gemini-cli GitHub Action |
| 24 | 2026‑06‑23 | CVE‑2026‑56274 | MCP05 — Command Injection & Execution | Flowise Custom MCP Server command injection |
| 25 | 2026‑06‑23 | CVE‑2026‑54309 | MCP07 — Insufficient Authentication & Authorization | @n8n/mcp-browser unauthenticated HTTP transport |
| 26 | 2026‑06‑23 | CVE‑2026‑47388 | MCP02 — Privilege Escalation via Scope Creep | NocoDB MCP token attachment ownership bypass / file read |
| 27 | 2026‑06‑23 | CVE‑2026‑46549 | MCP02 — Privilege Escalation via Scope Creep | NocoDB MCP OAuth token scope bypass |
| 28 | 2026‑06‑23 | CVE‑2026‑12112 | MCP07 — Insufficient Authentication & Authorization | foreman-mcp-server session hijack via non-secret session IDs |
| 29 | 2026‑06‑22 | CVE‑2026‑7664 | MCP07 — Insufficient Authentication & Authorization | IBM Langflow Streamable MCP authorization bypass |
| 30 | 2026‑06‑22 | CVE‑2026‑10789 | MCP05 — Command Injection & Execution | Autodesk Fusion Desktop MCP extension arbitrary code execution |
| 31 | 2026‑06‑21 | CVE‑2026‑12798 | MCP05 — Command Injection & Execution | LiteLLM OpenAPI-to-MCP generator SSRF |
| 32 | 2026‑06‑21 | CVE‑2026‑12774 | MCP05 — Command Injection & Execution | LiteLLM MCP connection testing SSRF |
| 33 | 2026‑06‑21 | CVE‑2026‑12773 | MCP07 — Insufficient Authentication & Authorization | LiteLLM MCP Proxy improper authentication |
| 34 | 2026‑06‑19 | CVE‑2026‑49357 | MCP07 — Insufficient Authentication & Authorization | line-desktop-mcp unauthenticated HTTP mode chat access |
| 35 | 2026‑06‑19 | CVE‑2026‑49291 | MCP02 — Privilege Escalation via Scope Creep | mcp-memory-service OAuth read-scope tools/call bypass |
| 36 | 2026‑06‑19 | CVE‑2026‑48787 | MCP05 — Command Injection & Execution | gin-vue-admin MCP management code-generation command injection |
| 37 | 2026‑06‑19 | CVE‑2026‑48774 | MCP02 — Privilege Escalation via Scope Creep | ProxySQL GenAI/MCP run_sql_readonly multi-statement bypass |
| 38 | 2026‑06‑18 | CVE‑2026‑55887 | MCP05 — Command Injection & Execution | Docker MCP Gateway (github.com/docker/mcp-gateway) |
| 39 | 2026‑06‑18 | CVE‑2026‑49257 | MCP07 — Insufficient Authentication & Authorization | mcp-pinot unauthenticated 0.0.0.0 HTTP MCP server |
| 40 | 2026‑06‑18 | CVE‑2026‑11719 | MCP02 — Privilege Escalation via Scope Creep | MCP Toolbox for Databases protocol-version scope bypass |
| 41 | 2026‑06‑17 | CVE‑2026‑48989 | MCP07 — Insufficient Authentication & Authorization | Windows-MCP unauthenticated HTTP control plane / PowerShell execution |
| 42 | 2026‑06‑17 | CVE‑2026‑48814 | MCP07 — Insufficient Authentication & Authorization | Network-AI MCP SSE unauthenticated tool invocation |
| 43 | 2026‑06‑16 | CVE‑2026‑53840 | MCP01 — Token Mismanagement & Secret Exposure | OpenClaw Streamable HTTP MCP custom-header leak on redirects |
| 44 | 2026‑06‑15 | CVE‑2026‑40775 | MCP07 — Insufficient Authentication & Authorization | Royal MCP unauthenticated broken access control |
| 45 | 2026‑06‑13 | CVE‑2026‑11624 | MCP07 — Insufficient Authentication & Authorization | MCP Origin/Host validation gap for DNS rebinding controls |
| 46 | 2026‑06‑12 | CVE‑2026‑53820 | MCP05 — Command Injection & Execution | OpenClaw bundled MCP exec denylist bypass |
| 47 | 2026‑06‑12 | CVE‑2026‑50287 | MCP07 — Insufficient Authentication & Authorization | @agenticmail/mcp unauthenticated Streamable HTTP endpoint |
| 48 | 2026‑06‑11 | CVE‑2026‑53818 | MCP07 — Insufficient Authentication & Authorization | OpenClaw MCP loopback owner-only policy bypass |
| 49 | 2026‑06‑11 | CVE‑2026‑53814 | MCP02 — Privilege Escalation via Scope Creep | OpenClaw hook-triggered MCP loopback privilege escalation |
| 50 | 2026‑06‑11 | CVE‑2026‑47250 | MCP02 — Privilege Escalation via Scope Creep | mcp-server-kubernetes kubectl_generic unsafe flags / token exfiltration |
| 51 | 2026‑06‑05 | CVE‑2026‑52869 | MCP07 — Insufficient Authentication & Authorization | MCP Python SDK (mcp): HTTP session auth bypass (SseServerTransport / Streamable HTTP) |
| 52 | 2026‑06‑05 | CVE‑2026‑52870 | MCP07 — Insufficient Authentication & Authorization | MCP Python SDK (mcp): experimental task handlers cross-client access |
| 53 | 2026‑06‑04 | CVE‑2026‑54449 | MCP09 — Shadow MCP Servers | LangBot |
| 54 | 2026‑06‑02 | CVE‑2026‑44653 | MCP07 — Insufficient Authentication & Authorization | LibreChat — GET /api/mcp/servers returns plaintext apiKey.key and oauth.client_secret to VIEW-only users |
| 55 | 2026‑06‑02 | CVE‑2026‑42073 | MCP07 — Insufficient Authentication & Authorization | OpenClaude MCP OAuth callback CSRF state bypass / DoS |
| 56 | 2026‑06‑02 | CVE‑2026‑32625 | MCP01 — Token Mismanagement & Secret Exposure | LibreChat — MCP server URL ${VAR} interpolation exfiltrates JWT_SECRET, CREDS_KEY, CREDS_IV, MONGO_URI |
| 57 | 2026‑06‑01 | CVE‑2026‑10280 | MCP05 — Command Injection & Execution | mcpilot MCP API call endpoint SSRF via serverBaseUrl |
| 58 | 2026‑06‑01 | CVE‑2026‑10277 | MCP02 — Privilege Escalation via Scope Creep | mcp-google-workspace Gmail saveToDisk improper access controls |
| 59 | 2026‑05‑29 | CVE‑2026‑47751 | MCP04 — Software Supply Chain Attacks & Dependency Tampering | Anthropic Claude Code Action (claude-code-action) |
| 60 | 2026‑05‑29 | CVE‑2026‑45707 | MCP07 — Insufficient Authentication & Authorization | n8n-mcp multi-tenant HTTP transport authentication gap |
| 61 | 2026‑05‑29 | CVE‑2026‑45609 | MCP05 — Command Injection & Execution | Spring AI mcp-security missing MCP-spec SSRF mitigations |
| 62 | 2026‑05‑29 | CVE‑2026‑45582 | MCP01 — Token Mismanagement & Secret Exposure | n8n-MCP (czlonkowski/n8n-mcp) |
| 63 | 2026‑05‑29 | CVE‑2026‑45555 | MCP05 — Command Injection & Execution | Roslyn CodeLens MCP Server arbitrary DiagnosticAnalyzer load |
| 64 | 2026‑05‑26 | CVE‑2026‑48710 | MCP07 — Insufficient Authentication & Authorization | Starlette / FastAPI-based MCP and AI gateways |
| 65 | 2026‑05‑19 | CVE‑2026‑46341 | MCP02 — Privilege Escalation via Scope Creep | @apify/actors-mcp-server |
| 66 | 2026‑05‑19 | CVE‑2026‑46339 | MCP07 — Insufficient Authentication & Authorization | 9router MCP routes |
| 67 | 2026‑05‑19 | CVE‑2026‑45805 | MCP07 — Insufficient Authentication & Authorization | @penpot/mcp |
| 68 | 2026‑05‑18 | CVE‑2026‑46519 | MCP02 — Privilege Escalation via Scope Creep | mcp-server-kubernetes |
| 69 | 2026‑05‑15 | CVE‑2026‑44717 | MCP05 — Command Injection & Execution | MCP Calculate Server |
| 70 | 2026‑05‑14 | CVE‑2026‑44895 | MCP07 — Insufficient Authentication & Authorization | GitLab MCP Server (HTTP transport without authentication) |
| 71 | 2026‑05‑14 | CVE‑2026‑44830 | MCP07 — Insufficient Authentication & Authorization | Nocturne Memory MCP server (missing auth when token unset) |
| 72 | 2026‑05‑14 | CVE‑2026‑44284 | MCP05 — Command Injection & Execution | FastGPT (MCP tool URL SSRF gap) |
| 73 | 2026‑05‑14 | CVE‑2026‑42559 | MCP07 — Insufficient Authentication & Authorization | MCP Rust SDK (rmcp crate): Streamable HTTP server transport DNS rebinding |
| 74 | 2026‑05‑14 | CVE‑2026‑34163 | MCP07 — Insufficient Authentication & Authorization | FastGPT (MCP tools endpoint auth gap) |
| 75 | 2026‑05‑12 | CVE‑2026‑5029 | MCP07 — Insufficient Authentication & Authorization | Code Runner MCP Server |
| 76 | 2026‑05‑12 | CVE‑2026‑45781 | MCP02 — Privilege Escalation via Scope Creep | MCP Registry |
| 77 | 2026‑05‑12 | CVE‑2026‑43992 | MCP01 — Token Mismanagement & Secret Exposure | JunoClaw |
| 78 | 2026‑05‑12 | CVE‑2026‑42260 | MCP05 — Command Injection & Execution | Open-WebSearch MCP server |
| 79 | 2026‑05‑11 | CVE‑2026‑45001 | MCP04 — Software Supply Chain Attacks & Dependency Tampering | OpenClaw |
| 80 | 2026‑05‑11 | CVE‑2026‑44998 | MCP03 — Tool Poisoning | OpenClaw |
| 81 | 2026‑05‑11 | CVE‑2026‑44995 | MCP05 — Command Injection & Execution | OpenClaw |
| 82 | 2026‑05‑11 | CVE‑2026‑44450 | MCP05 — Command Injection & Execution | Lumiverse (MCP server command allowlist bypass) |
| 83 | 2026‑05‑11 | CVE‑2026‑44430 | MCP05 — Command Injection & Execution | MCP Registry |
| 84 | 2026‑05‑11 | CVE‑2026‑44429 | MCP05 — Command Injection & Execution | MCP Registry |
| 85 | 2026‑05‑11 | CVE‑2026‑44428 | MCP07 — Insufficient Authentication & Authorization | MCP Registry |
| 86 | 2026‑05‑11 | CVE‑2026‑44427 | MCP07 — Insufficient Authentication & Authorization | MCP Registry |
| 87 | 2026‑05‑11 | CVE‑2026‑43901 | MCP02 — Privilege Escalation via Scope Creep | Wireshark MCP (wireshark-mcp) |
| 88 | 2026‑05‑10 | CVE‑2026‑7738 | MCP02 — Privilege Escalation via Scope Creep | doc-tools-mcp |
| 89 | 2026‑05‑09 | CVE‑2026‑7729 | MCP05 — Command Injection & Execution | directus-mcp |
| 90 | 2026‑05‑09 | CVE‑2026‑7728 | MCP02 — Privilege Escalation via Scope Creep | mcp-rtfm |
| 91 | 2026‑05‑09 | CVE‑2026‑7715 | MCP02 — Privilege Escalation via Scope Creep | mcp-server-arangodb |
| 92 | 2026‑05‑08 | CVE‑2026‑7653 | MCP05 — Command Injection & Execution | mcp-server-rijksmuseum |
| 93 | 2026‑05‑08 | CVE‑2026‑7628 | MCP05 — Command Injection & Execution | mcp-code-review-server |
| 94 | 2026‑05‑08 | CVE‑2026‑7627 | MCP02 — Privilege Escalation via Scope Creep | metatrader-4-mcp |
| 95 | 2026‑05‑08 | CVE‑2026‑44694 | MCP05 — Command Injection & Execution | n8n-mcp |
| 96 | 2026‑05‑08 | CVE‑2026‑44336 | MCP05 — Command Injection & Execution | PraisonAI MCP tools/call path traversal to RCE via .pth injection |
| 97 | 2026‑05‑08 | CVE‑2026‑42282 | MCP08 — Lack of Audit and Telemetry | n8n-mcp |
| 98 | 2026‑05‑08 | CVE‑2026‑42271 | MCP05 — Command Injection & Execution | LiteLLM MCP server preview endpoints |
| 99 | 2026‑05‑08 | CVE‑2026‑41495 | MCP08 — Lack of Audit and Telemetry | n8n-mcp |
| 100 | 2026‑05‑07 | CVE‑2026‑7600 | MCP05 — Command Injection & Execution | mcp-server-yii2 |
| 101 | 2026‑05‑07 | CVE‑2026‑7599 | MCP05 — Command Injection & Execution | terminalcraft |
| 102 | 2026‑05‑07 | CVE‑2026‑7594 | MCP02 — Privilege Escalation via Scope Creep | DungeonMind-MCP |
| 103 | 2026‑05‑07 | CVE‑2026‑7593 | MCP05 — Command Injection & Execution | command-executor-mcp-server |
| 104 | 2026‑05‑07 | CVE‑2026‑42449 | MCP05 — Command Injection & Execution | n8n-mcp |
| 105 | 2026‑05‑06 | CVE‑2026‑7446 | MCP05 — Command Injection & Execution | mcp-server-semgrep |
| 106 | 2026‑05‑06 | CVE‑2026‑7443 | MCP05 — Command Injection & Execution | mcp-dnstwist |
| 107 | 2026‑05‑06 | CVE‑2026‑44118 | MCP07 — Insufficient Authentication & Authorization | OpenClaw (loopback MCP owner-context spoofing) |
| 108 | 2026‑05‑05 | CVE‑2026‑7386 | MCP05 — Command Injection & Execution | mail-mcp-bridge |
| 109 | 2026‑05‑05 | CVE‑2026‑35228 | MCP05 — Command Injection & Execution | Oracle MCP Server Helper Tool (SQL injection) |
| 110 | 2026‑05‑04 | CVE‑2026‑7730 | MCP05 — Command Injection & Execution | privsim/mcp-test-runner |
| 111 | 2026‑05‑04 | CVE‑2026‑42236 | MCP07 — Insufficient Authentication & Authorization | n8n (MCP OAuth client registration DoS) |
No comments yet
Be the first to share your take.