Known CVEs

OSV.dev advisories attested

Known CVE vulnerabilities mapped to tracked servers via OSV.dev, newest disclosures first; switch to the severity worklist to triage by impact — a review signal, not a verdict. CVE feed as of 1h ago · next check in 2h. New here? The Risk tab gives an at-a-glance composite grade per server; the Code Analysis tab shows what the static scanner found in published source.

All advisories, every tracked server

most-affected 30d · 9 new
inherited CVEs via tracked dependencies

Scope: only dependencies that are themselves tracked MCP servers. A CVE in an untracked package (a general npm/PyPI library) does not flow here — this is partial supply-chain visibility, not a full transitive audit.

cve feed 25 shown · newest first
sort recent severity
  1. HIGH CakeRepository/1Password-MCP op_run tool leaks OP_SERVICE_ACCOUNT_TOKEN master credential to subprocesses and model context
    GHSA-q3gg-rgxh-gh64
  2. HIGH jnotsknab/mux-swarm Unauthenticated Path Traversal in ServeMode File APIs via SafeJoin() Boundary Bypass
    GHSA-vxmx-253h-48pr
  3. HIGH bvisible/mcp-ssh-manager Remote code execution (RCE) via command injection in the backup subsystem (`ssh_backup_create` / `ssh_backup_list` / `ssh_backup_restore` / `ssh_backup_schedule`)
    GHSA-qwwm-vrm9-4mw8
  4. CRITICAL bvisible/mcp-ssh-manager Remote Command Injection via ssh_db_dump outputFile (and ssh_backup_create MongoDB builder) in mcp-ssh-manager
    GHSA-796j-h5q5-jx6p
  5. CRITICAL bvisible/mcp-ssh-manager Command injection in read-only monitoring tools (ssh_service_status, ssh_tail) bypasses the readonly/restricted security-mode allowlist → RCE
    GHSA-m793-whw6-f537
  6. MEDIUM duty1g/x64dbg-mcp-server Unauthenticated pre-auth integer-overflow denial of service via Content-Length in the MCP HTTP receive path
    GHSA-jgj3-97w2-9v9r
  7. MEDIUM dcostenco/prism-coder Missing Host/Origin validation on Prism's local dashboard allows DNS rebinding to read and export all session memory
    GHSA-9cvx-7x8q-3g6m
  8. CRITICAL duty1g/x64dbg-mcp-server Unauthenticated MCP transport gives any network client remote control of x64dbg, including arbitrary command execution and process attach
    GHSA-4478-h5jv-647m
  9. HIGH Agenxy/dibs A local agent can impersonate the operator and can be promoted through their browser
    GHSA-72hq-r6x6-mjwf
  10. MEDIUM sonirico/mcp-shell find -fls bypasses the find escape-hatch policy → arbitrary file overwrite (default config) (CWE-693/CWE-73)
    GHSA-qp2m-x9hp-cj5p
  11. LOW Coding-Dev-Tools/engraphis Path disclosure in vault import error responses
    GHSA-rhrw-rg5c-4q76
  12. MEDIUM fabionfsc/nuzo-memory Restricted sessions can disclose or be denied by cross-scope relation metadata
    GHSA-cvcw-gqcj-398w
  13. LOW fabionfsc/nuzo-memory CLI, JSON, and Markdown inspection surfaces insufficiently neutralize untrusted memory structure
    GHSA-qfv8-fjq7-36g2
  14. MEDIUM SethGammon/Citadel Path traversal / arbitrary file read in the context-compress MCP server (smart_read) bypasses protect-files.js confinement
    GHSA-h697-vwxm-fj4v
  15. HIGH AiondaDotCom/mcp-ssh SSH config poisoning via downloadFile turns remote command execution into local RCE
    GHSA-pj6m-cx2p-44gh
  16. HIGH AiondaDotCom/mcp-ssh SCP Remote-Spec Host Allowlist Bypass via `localPath` in `downloadFile`
    GHSA-gpr2-2wqr-7rgp
  17. CRITICAL opena2a-org/hackmyagent A scanned file could suppress its own findings by forging the analysis prompt frame (partial fix; reply reader still affected)
    GHSA-jmq8-2mfr-49mh
  18. CRITICAL opena2a-org/hackmyagent MCP server reads any file and writes to any directory (unconfined filesystem access)
    GHSA-44f3-xgp9-pvp2
  19. MEDIUM tumf/mcp-shell-server Duplicate report: literal pipe characters in argv could be reinterpreted as pipeline operators
    GHSA-q8pm-q3r2-q7cg
  20. MEDIUM tumf/mcp-shell-server Literal pipe characters in argv could be reinterpreted as pipeline operators
    GHSA-7wg7-jj87-qp4c
  21. HIGH yantrikos/yantrikdb Record content stored in plaintext in oplog.payload on encrypted databases
    GHSA-84vx-5fgq-5p59
  22. CRITICAL sayak-sarkar/contextlake Stored cross-site scripting in generated graph pages, escalating to dashboard token theft
    GHSA-fwx4-9qvg-98qc
  23. HIGH fu351/Doberman-Core Trailing space or dot in a path bypasses protected-path BLOCK and AUTH decisions on Windows
    GHSA-4vvj-9m89-648r
  24. HIGH strands-agents/tools Insecure direct object reference in Strands Agents Tools memory tool namespace isolation EPSS 0%
  25. LOW julien040/anyquery Dev-mode UDFs bypass server sandbox denylist enabling unauthenticated filesystem oracle (conditional RCE)
    GHSA-4rr9-66j6-r74m

How MCP Observatory reviews MCP server security

An MCP server runs with the access you give your agent: files, a shell, the network, your credentials. Before you install one, it helps to know what it can reach and what is already known about it. MCP Observatory checks every tracked server against public vulnerability data and against a static analysis of its published source.

This page lists known CVEs mapped to tracked servers through OSV.dev, including CVEs a server inherits from dependencies that are themselves tracked servers. The other tabs cover the rest of the review. Risk combines the signals into one grade per server. Code analysis shows what a static scan of the published package found, such as hidden prompt content or committed secrets, without running any code. Tool safety infers risky capabilities and permission surface from tool definitions. Capability drift marks servers whose tools or permissions changed between releases. Supply chain, Name lookalikes and Abandonment cover dependencies, possible typosquats and unmaintained servers.

Every grade and flag is an inferred review prompt, not a verdict. Each one is tagged by what backs it (attested, reported or inferred), and the methodology explains how each signal is collected and scored.

The dated report Known vulnerabilities in MCP servers, 2026 Q3 summarises these numbers in a frozen, citable edition.