security
Security
Every MCP risk signal in one place — CVEs, tool safety, drift, naming, licenses. Heuristic: review signals, not verdicts.
45 CRITICAL
3647 HIGH
531 MEDIUM
1205 LOW
11 NONE
Risk: servers ranked by their composite exposure score — synthesised from CVEs, inferred permissions, drift, supply-chain and abandonment signals. Heuristic and banded; a high grade is a 'review this' signal, never a verdict.
A fix already ships upstream but the server still runs an older, vulnerable version — remediation lag, actionable today.
- @frontmcp/adapters HIGH CVE-2026-39885 1.4.1 → 2.3.0
- @frontmcp/sdk HIGH CVE-2026-39885 1.4.1 → 2.3.0
- 1 C @vpxa/aikit 59
- 2 C Arrayo/smart-context-mcp 59
- 3 C Azure/containerization-assist 59
- 4 C Boosted-Chat/BoostedTravel 59
- 5 C Chen-zexi/open-ptc-agent 59
- 6 C Chibey-max/Ethereum-Agentic 59
- 7 C Coff0xc/AutoRedTeam-Orchestrator 59
- 8 C Context7 59
- 9 C Decade-qiu/CookHero 59
- 10 C EchoingVesper/mcp-task-orchestrator 59
- 11 C Frihet-io/frihet-mcp 59
- 12 C GDM-Pixel/stellaris-code-search 59
- 13 C LeonMare/vozclara 59
- 14 C LuuOW/meridian-mcp 59
- 15 C OleksandrKucherenko/mcp-obsidian-via-rest 59