Known CVEs
OSV.dev advisories attested
Known CVE vulnerabilities mapped to tracked servers via OSV.dev, newest disclosures first; switch to the severity worklist to triage by impact — a review signal, not a verdict. CVE feed as of 1h ago · next check in 2h. New here? The Risk tab gives an at-a-glance composite grade per server; the Code Analysis tab shows what the static scanner found in published source.
All advisories, every tracked server
- 222wcnm/BiliStalkerMCP 8
- AKShare One MCP Server 8
- AKzar1el/mcp-trendpulse 8
- AnnasMazhar/pyspark_mcp 8
- Anselmoo/mcp-server-analyzer 8
- Anselmoo/mcp-zen-of-languages 8
- AnthonyPuggs/ausecon-mcp-server 8
- Artexis10/exomem 8
- AuthPlane/python-sdk 8
- BV-Venky/excalidraw-architect-mcp 8
Scope: only dependencies that are themselves tracked MCP servers. A CVE in an untracked package (a general npm/PyPI library) does not flow here — this is partial supply-chain visibility, not a full transitive audit.
- HIGH CakeRepository/1Password-MCP op_run tool leaks OP_SERVICE_ACCOUNT_TOKEN master credential to subprocesses and model context
- HIGH jnotsknab/mux-swarm Unauthenticated Path Traversal in ServeMode File APIs via SafeJoin() Boundary Bypass
- HIGH bvisible/mcp-ssh-manager Remote code execution (RCE) via command injection in the backup subsystem (`ssh_backup_create` / `ssh_backup_list` / `ssh_backup_restore` / `ssh_backup_schedule`)
- CRITICAL bvisible/mcp-ssh-manager Remote Command Injection via ssh_db_dump outputFile (and ssh_backup_create MongoDB builder) in mcp-ssh-manager
- CRITICAL bvisible/mcp-ssh-manager Command injection in read-only monitoring tools (ssh_service_status, ssh_tail) bypasses the readonly/restricted security-mode allowlist → RCE
- MEDIUM duty1g/x64dbg-mcp-server Unauthenticated pre-auth integer-overflow denial of service via Content-Length in the MCP HTTP receive path
- MEDIUM dcostenco/prism-coder Missing Host/Origin validation on Prism's local dashboard allows DNS rebinding to read and export all session memory
- CRITICAL duty1g/x64dbg-mcp-server Unauthenticated MCP transport gives any network client remote control of x64dbg, including arbitrary command execution and process attach
- HIGH Agenxy/dibs A local agent can impersonate the operator and can be promoted through their browser
- MEDIUM sonirico/mcp-shell find -fls bypasses the find escape-hatch policy → arbitrary file overwrite (default config) (CWE-693/CWE-73)
- LOW Coding-Dev-Tools/engraphis Path disclosure in vault import error responses
- MEDIUM fabionfsc/nuzo-memory Restricted sessions can disclose or be denied by cross-scope relation metadata
- LOW fabionfsc/nuzo-memory CLI, JSON, and Markdown inspection surfaces insufficiently neutralize untrusted memory structure
- MEDIUM SethGammon/Citadel Path traversal / arbitrary file read in the context-compress MCP server (smart_read) bypasses protect-files.js confinement
- HIGH AiondaDotCom/mcp-ssh SSH config poisoning via downloadFile turns remote command execution into local RCE
- HIGH AiondaDotCom/mcp-ssh SCP Remote-Spec Host Allowlist Bypass via `localPath` in `downloadFile`
- CRITICAL opena2a-org/hackmyagent A scanned file could suppress its own findings by forging the analysis prompt frame (partial fix; reply reader still affected)
- CRITICAL opena2a-org/hackmyagent MCP server reads any file and writes to any directory (unconfined filesystem access)
- MEDIUM tumf/mcp-shell-server Duplicate report: literal pipe characters in argv could be reinterpreted as pipeline operators
- MEDIUM tumf/mcp-shell-server Literal pipe characters in argv could be reinterpreted as pipeline operators
- HIGH yantrikos/yantrikdb Record content stored in plaintext in oplog.payload on encrypted databases
- CRITICAL sayak-sarkar/contextlake Stored cross-site scripting in generated graph pages, escalating to dashboard token theft
- HIGH fu351/Doberman-Core Trailing space or dot in a path bypasses protected-path BLOCK and AUTH decisions on Windows
- HIGH strands-agents/tools Insecure direct object reference in Strands Agents Tools memory tool namespace isolation EPSS 0%
- LOW julien040/anyquery Dev-mode UDFs bypass server sandbox denylist enabling unauthenticated filesystem oracle (conditional RCE)
How MCP Observatory reviews MCP server security
An MCP server runs with the access you give your agent: files, a shell, the network, your credentials. Before you install one, it helps to know what it can reach and what is already known about it. MCP Observatory checks every tracked server against public vulnerability data and against a static analysis of its published source.
This page lists known CVEs mapped to tracked servers through OSV.dev, including CVEs a server inherits from dependencies that are themselves tracked servers. The other tabs cover the rest of the review. Risk combines the signals into one grade per server. Code analysis shows what a static scan of the published package found, such as hidden prompt content or committed secrets, without running any code. Tool safety infers risky capabilities and permission surface from tool definitions. Capability drift marks servers whose tools or permissions changed between releases. Supply chain, Name lookalikes and Abandonment cover dependencies, possible typosquats and unmaintained servers.
Every grade and flag is an inferred review prompt, not a verdict. Each one is tagged by what backs it (attested, reported or inferred), and the methodology explains how each signal is collected and scored.
The dated report Known vulnerabilities in MCP servers, 2026 Q3 summarises these numbers in a frozen, citable edition.