security

Security

Every MCP risk signal in one place — CVEs, tool safety, drift, naming, licenses. Heuristic: review signals, not verdicts.

Risk: servers ranked by their composite exposure score — synthesised from CVEs, inferred permissions, drift, supply-chain and abandonment signals. Heuristic and banded; a high grade is a 'review this' signal, never a verdict.

patchable now2 servers · fix published, not adopted

A fix already ships upstream but the server still runs an older, vulnerable version — remediation lag, actionable today.

  1. @frontmcp/adapters HIGH CVE-2026-39885 1.4.1 → 2.3.0
  2. @frontmcp/sdk HIGH CVE-2026-39885 1.4.1 → 2.3.0
  1. 1 B 9ninety/mcpnotes 34
    • exposure 28
    • abandonment 6
  2. 2 B @aisuite/chub 34
    • exposure 22
    • inherited 15
  3. 3 B @atlisp/mcp 34
    • exposure 22
    • inherited 15
  4. 4 B @hubspot/mcp-server 34
    • exposure 24
    • inherited 15
  5. 5 B @sellable/mcp 34
    • exposure 22
    • inherited 15
  6. 6 B @skanda-yutori/mcp-send-email 34
    • exposure 12
    • drift 12
    • inherited 15
  7. 7 B @wcag-checkr/mcp 34
    • exposure 22
    • inherited 15
  8. 8 B @xrpl-utilities/mcp 34
    • exposure 28
    • inherited 15
  9. 9 B Christianye/postline 34
    • exposure 35
    • safety 2
  10. 10 B Custodia-Admin/pagebolt-mcp 34
    • exposure 28
    • drift 12
    • safety 2
  11. 11 B Driftya/code-meridian 34
    • exposure 35
    • safety 2
  12. 12 B EOX-A/EOxElements 34
    • exposure 10
    • drift 20
    • safety 12
  13. 13 B Gammell53/clawwork-mcp 34
    • exposure 28
    • safety 14
  14. 14 B IIQ-Community/mcp-incidentiq 34
    • exposure 28
    • safety 14
  15. 15 B KultMember6Banger/kloakt 34
    • exposure 18
    • drift 12
    • safety 12