Known CVEs

OSV.dev advisories attested

Known CVE vulnerabilities mapped to tracked servers via OSV.dev, newest disclosures first; switch to the severity worklist to triage by impact — a review signal, not a verdict. CVE feed as of 3h ago · next check in 27m. New here? The Risk tab gives an at-a-glance composite grade per server; the Code Analysis tab shows what the static scanner found in published source.

All advisories, every tracked server

most-affected 30d · 16 new
inherited CVEs via tracked dependencies

Scope: only dependencies that are themselves tracked MCP servers. A CVE in an untracked package (a general npm/PyPI library) does not flow here — this is partial supply-chain visibility, not a full transitive audit.

cve feed 25 shown · newest first
sort recent severity
  1. HIGH CakeRepository/1Password-MCP op_run tool leaks OP_SERVICE_ACCOUNT_TOKEN master credential to subprocesses and model context
    GHSA-q3gg-rgxh-gh64
  2. HIGH jnotsknab/mux-swarm Unauthenticated Path Traversal in ServeMode File APIs via SafeJoin() Boundary Bypass
    GHSA-vxmx-253h-48pr
  3. HIGH bvisible/mcp-ssh-manager Remote code execution (RCE) via command injection in the backup subsystem (`ssh_backup_create` / `ssh_backup_list` / `ssh_backup_restore` / `ssh_backup_schedule`)
    GHSA-qwwm-vrm9-4mw8
  4. CRITICAL bvisible/mcp-ssh-manager Remote Command Injection via ssh_db_dump outputFile (and ssh_backup_create MongoDB builder) in mcp-ssh-manager
    GHSA-796j-h5q5-jx6p
  5. CRITICAL bvisible/mcp-ssh-manager Command injection in read-only monitoring tools (ssh_service_status, ssh_tail) bypasses the readonly/restricted security-mode allowlist → RCE
    GHSA-m793-whw6-f537
  6. MEDIUM duty1g/x64dbg-mcp-server Unauthenticated pre-auth integer-overflow denial of service via Content-Length in the MCP HTTP receive path
    GHSA-jgj3-97w2-9v9r
  7. MEDIUM dcostenco/prism-coder Missing Host/Origin validation on Prism's local dashboard allows DNS rebinding to read and export all session memory
    GHSA-9cvx-7x8q-3g6m
  8. CRITICAL duty1g/x64dbg-mcp-server Unauthenticated MCP transport gives any network client remote control of x64dbg, including arbitrary command execution and process attach
    GHSA-4478-h5jv-647m
  9. HIGH Agenxy/dibs A local agent can impersonate the operator and can be promoted through their browser
    GHSA-72hq-r6x6-mjwf
  10. MEDIUM sonirico/mcp-shell find -fls bypasses the find escape-hatch policy → arbitrary file overwrite (default config) (CWE-693/CWE-73)
    GHSA-qp2m-x9hp-cj5p
  11. LOW Coding-Dev-Tools/engraphis Path disclosure in vault import error responses
    GHSA-rhrw-rg5c-4q76
  12. MEDIUM fabionfsc/nuzo-memory Restricted sessions can disclose or be denied by cross-scope relation metadata
    GHSA-cvcw-gqcj-398w
  13. LOW fabionfsc/nuzo-memory CLI, JSON, and Markdown inspection surfaces insufficiently neutralize untrusted memory structure
    GHSA-qfv8-fjq7-36g2
  14. MEDIUM SethGammon/Citadel Path traversal / arbitrary file read in the context-compress MCP server (smart_read) bypasses protect-files.js confinement
    GHSA-h697-vwxm-fj4v
  15. HIGH AiondaDotCom/mcp-ssh SSH config poisoning via downloadFile turns remote command execution into local RCE
    GHSA-pj6m-cx2p-44gh
  16. HIGH AiondaDotCom/mcp-ssh SCP Remote-Spec Host Allowlist Bypass via `localPath` in `downloadFile`
    GHSA-gpr2-2wqr-7rgp
  17. CRITICAL opena2a-org/hackmyagent A scanned file could suppress its own findings by forging the analysis prompt frame (partial fix; reply reader still affected)
    GHSA-jmq8-2mfr-49mh
  18. CRITICAL opena2a-org/hackmyagent MCP server reads any file and writes to any directory (unconfined filesystem access)
    GHSA-44f3-xgp9-pvp2
  19. MEDIUM tumf/mcp-shell-server Duplicate report: literal pipe characters in argv could be reinterpreted as pipeline operators
    GHSA-q8pm-q3r2-q7cg
  20. MEDIUM tumf/mcp-shell-server Literal pipe characters in argv could be reinterpreted as pipeline operators
    GHSA-7wg7-jj87-qp4c
  21. HIGH yantrikos/yantrikdb Record content stored in plaintext in oplog.payload on encrypted databases
    GHSA-84vx-5fgq-5p59
  22. CRITICAL sayak-sarkar/contextlake Stored cross-site scripting in generated graph pages, escalating to dashboard token theft
    GHSA-fwx4-9qvg-98qc
  23. HIGH fu351/Doberman-Core Trailing space or dot in a path bypasses protected-path BLOCK and AUTH decisions on Windows
    GHSA-4vvj-9m89-648r
  24. HIGH strands-agents/tools Insecure direct object reference in Strands Agents Tools memory tool namespace isolation EPSS 0%
  25. LOW julien040/anyquery Dev-mode UDFs bypass server sandbox denylist enabling unauthenticated filesystem oracle (conditional RCE)
    GHSA-4rr9-66j6-r74m