security
Security
Every MCP risk signal in one place — CVEs, tool safety, drift, naming, licenses. Heuristic: review signals, not verdicts. New here? The Risk tab gives an at-a-glance composite grade per server; the Code Analysis tab shows what the static scanner found in published source.
91 CRITICAL
7932 HIGH
2846 MEDIUM
4763 LOW
16 NONE
Known CVE vulnerabilities mapped to tracked servers via OSV.dev, newest disclosures first; switch to the severity worklist to triage by impact — a review signal, not a verdict. CVE feed as of 2h ago · next check in 1h.
- n8n-io/n8n 135
- siyuan-note/siyuan 78
- sooperset/mcp-atlassian 35
- labring/FastGPT 33
- langgenius/dify 20
- lobehub/lobehub 14
- ondata/ckan-mcp-server 13
- mcp 12
- n8n-mcp 11
- PrefectHQ/fastmcp 8
- 021-mcp
- 12306-mcp
- 1up-mcp
- 3tears-mcp
- CSOAI-ORG/a2a-governance-bridge-mcp
- CSOAI-ORG/agent-content-watermark-mcp
- CSOAI-ORG/agent-cost-allocator-mcp
- CSOAI-ORG/agent-incident-relay-mcp
- CSOAI-ORG/agent-replay-debugger-mcp
- CSOAI-ORG/agent-token-budget-mcp
Scope: only dependencies that are themselves tracked MCP servers. A CVE in an untracked package (a general npm/PyPI library) does not flow here — this is partial supply-chain visibility, not a full transitive audit.
- CRITICAL danielealbano/android-remote-control-mcp Improper Access Control and Missing Authorization and Improper Export of Android Application Components in com.danielealbano.androidremotecontrolmcp
- MEDIUM john-broadway/pacioli A submit consent marker licensed cancellation of caller-named pre-existing documents
- MEDIUM john-broadway/pacioli Broker re-sends its ERPNext Authorization header when following an HTTP redirect
- HIGH john-broadway/pacioli An empty resource allowlist granted every DocType (incorrect authorization)
- HIGH aaif-goose/goose Arbitrary command execution in goose CLI via `goose review` via git core.fsmonitor
- HIGH awslabs/mcp AWS API MCP Server Security Policy Bypass via Startup Initialization Failure EPSS 0%
- NONE mcp MCP Python SDK: WebSocket server transport does not support Host/Origin validation EPSS 0%
- HIGH mcp MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal EPSS 0%
- HIGH mcp MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks EPSS 0%
- HIGH netlicensing-mcp NetLicensing-MCP: Unauthenticated Use of Server-Side NetLicensing API Key in HTTP Mode
- CRITICAL netlicensing-mcp netlicensing-mcp: REST Path Traversal Bypasses Token Redaction
- MEDIUM evalstate/fast-agent `fast-agent serve` binds HTTP to 0.0.0.0 with no authentication by default; with --shell this is unauthenticated remote command execution
- MEDIUM n8n-io/n8n Path-Confinement Bypass in computer-use search_files Allows Reading Files Outside the Base Directory
- MEDIUM n8n-io/n8n PostgresTrigger Node SQL Injection Allows Authenticated Users to Execute Arbitrary SQL on Connected PostgreSQL Instances
- MEDIUM n8n-io/n8n Snowflake Node executeQuery Operation Allows SQL Injection via Unparameterized Expression Interpolation
- MEDIUM n8n-io/n8n Cross-Tenant Module-Cache Poisoning in the JS Task Runner
- MEDIUM n8n-io/n8n SSRF Protection Bypass via MCP Client Node
- MEDIUM n8n-io/n8n Prototype Pollution via VM Expression Engine Sandbox Escape Leads to Denial of Service
- HIGH n8n-io/n8n Send Email Node Arbitrary File Read and SSRF via Nodemailer Content-Object Type Confusion
- HIGH n8n-io/n8n Prototype Pollution via Dot-Notation Field Names Leads To Instance-Wide Denial of Service
- HIGH n8n-io/n8n Edit Image Node Format Injection Allows Arbitrary File Write
- HIGH n8n-io/n8n Shared-Workflow Editor Can Exfiltrate Credentials via Inline Sub-Workflow JSON
- HIGH n8n-io/n8n Expression sandbox escape via arrow-function bodies enabling command execution
- HIGH n8n-io/n8n Git Node fetch/pull/pushTags Operations Bypass Sandbox Path Restriction
- HIGH n8n-io/n8n Bypass "Allowed HTTP Request Domains" Credential Restriction in Multiple AI and LLM Nodes