security

Security

Every MCP risk signal in one place — CVEs, tool safety, drift, naming, licenses. Heuristic: review signals, not verdicts. New here? The Risk tab gives an at-a-glance composite grade per server; the Code Analysis tab shows what the static scanner found in published source.

Known CVE vulnerabilities mapped to tracked servers via OSV.dev, newest disclosures first; switch to the severity worklist to triage by impact — a review signal, not a verdict. CVE feed as of 2h ago · next check in 1h.

most-affected 30d · 125 new
inherited CVEs via tracked dependencies

Scope: only dependencies that are themselves tracked MCP servers. A CVE in an untracked package (a general npm/PyPI library) does not flow here — this is partial supply-chain visibility, not a full transitive audit.

sort recent severity
  1. CRITICAL danielealbano/android-remote-control-mcp Improper Access Control and Missing Authorization and Improper Export of Android Application Components in com.danielealbano.androidremotecontrolmcp
    GHSA-v82h-m32h-3j39
  2. MEDIUM john-broadway/pacioli A submit consent marker licensed cancellation of caller-named pre-existing documents
    GHSA-3hj7-6vmj-h8v4
  3. MEDIUM john-broadway/pacioli Broker re-sends its ERPNext Authorization header when following an HTTP redirect
    GHSA-w599-8w2q-cj3w
  4. HIGH john-broadway/pacioli An empty resource allowlist granted every DocType (incorrect authorization)
    GHSA-hm86-xvfq-hc58
  5. HIGH aaif-goose/goose Arbitrary command execution in goose CLI via `goose review` via git core.fsmonitor
    GHSA-r5pp-p5r8-466r
  6. HIGH awslabs/mcp AWS API MCP Server Security Policy Bypass via Startup Initialization Failure EPSS 0%
  7. NONE mcp MCP Python SDK: WebSocket server transport does not support Host/Origin validation EPSS 0%
  8. HIGH mcp MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal EPSS 0%
  9. HIGH mcp MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks EPSS 0%
  10. HIGH netlicensing-mcp NetLicensing-MCP: Unauthenticated Use of Server-Side NetLicensing API Key in HTTP Mode
  11. CRITICAL netlicensing-mcp netlicensing-mcp: REST Path Traversal Bypasses Token Redaction
  12. MEDIUM evalstate/fast-agent `fast-agent serve` binds HTTP to 0.0.0.0 with no authentication by default; with --shell this is unauthenticated remote command execution
    GHSA-9vhv-g5hf-m7m7
  13. MEDIUM n8n-io/n8n Path-Confinement Bypass in computer-use search_files Allows Reading Files Outside the Base Directory
    GHSA-pf2q-pxhf-hgmw
  14. MEDIUM n8n-io/n8n PostgresTrigger Node SQL Injection Allows Authenticated Users to Execute Arbitrary SQL on Connected PostgreSQL Instances
    GHSA-jqwr-vx3p-r266
  15. MEDIUM n8n-io/n8n Snowflake Node executeQuery Operation Allows SQL Injection via Unparameterized Expression Interpolation
    GHSA-652q-gvq3-74qv
  16. MEDIUM n8n-io/n8n Cross-Tenant Module-Cache Poisoning in the JS Task Runner
    GHSA-9cmh-xcqm-5hqr
  17. MEDIUM n8n-io/n8n SSRF Protection Bypass via MCP Client Node
    GHSA-vhf8-cg2h-cg3p
  18. MEDIUM n8n-io/n8n Prototype Pollution via VM Expression Engine Sandbox Escape Leads to Denial of Service
    GHSA-hx4h-vr3m-45vh
  19. HIGH n8n-io/n8n Send Email Node Arbitrary File Read and SSRF via Nodemailer Content-Object Type Confusion
    GHSA-2x35-3fw4-9jr4
  20. HIGH n8n-io/n8n Prototype Pollution via Dot-Notation Field Names Leads To Instance-Wide Denial of Service
    GHSA-xwx6-jjhv-84p8
  21. HIGH n8n-io/n8n Edit Image Node Format Injection Allows Arbitrary File Write
    GHSA-xmc9-4f2h-jf9c
  22. HIGH n8n-io/n8n Shared-Workflow Editor Can Exfiltrate Credentials via Inline Sub-Workflow JSON
    GHSA-cj9h-qx8g-pq2g
  23. HIGH n8n-io/n8n Expression sandbox escape via arrow-function bodies enabling command execution
    GHSA-gv7g-jm28-cr3m
  24. HIGH n8n-io/n8n Git Node fetch/pull/pushTags Operations Bypass Sandbox Path Restriction
    GHSA-gf29-4f56-r2jf
  25. HIGH n8n-io/n8n Bypass "Allowed HTTP Request Domains" Credential Restriction in Multiple AI and LLM Nodes
    GHSA-64xh-79j6-r5v8