security

Security

Every MCP risk signal in one place — CVEs, tool safety, drift, naming, licenses. Heuristic: review signals, not verdicts.

Risk: servers ranked by their composite exposure score — synthesised from CVEs, inferred permissions, drift, supply-chain and abandonment signals. Heuristic and banded; a high grade is a 'review this' signal, never a verdict.

patchable now2 servers · fix published, not adopted

A fix already ships upstream but the server still runs an older, vulnerable version — remediation lag, actionable today.

  1. @frontmcp/adapters HIGH CVE-2026-39885 1.4.1 → 2.3.0
  2. @frontmcp/sdk HIGH CVE-2026-39885 1.4.1 → 2.3.0
  1. 16 D pvliesdonk/markdown-vault-mcp 76
    • exposure 35
    • drift 20
    • safety 24
  2. 17 D frsorrentino/chrome-bridge 73
    • exposure 28
    • drift 20
    • safety 25
  3. 18 D @diskd-ai/email-mcp 72
    • exposure 35
    • inherited 15
    • safety 25
  4. 19 D aiwg 72
    • exposure 35
    • drift 12
    • inherited 15
    • safety 24
  5. 20 D alibabacloud-devops-mcp-server 72
    • exposure 28
    • drift 12
    • inherited 15
    • safety 25
  6. 21 D juspay/neurolink 72
    • exposure 35
    • drift 12
    • inherited 15
    • safety 24
  7. 22 D warunacds/apple-asc-mcp 72
    • exposure 35
    • drift 12
    • safety 25
  8. 23 D @mcp-guardian/server 71
    • exposure 35
    • drift 12
    • inherited 15
    • safety 12
  9. 24 D IgorGanapolsky/mcp-memory-gateway 71
    • exposure 35
    • drift 20
    • safety 24
  10. 25 D fxspeiser/crosscheck-agent 71
    • exposure 26
    • drift 20
    • safety 25
  11. 26 D gitnexus 71
    • exposure 35
    • drift 12
    • inherited 15
    • safety 12
    • supply-chain 6
  12. 27 D pulsemcp/mcp-servers 71
    • exposure 35
    • drift 20
    • safety 24
  13. 28 D kadam-official/mcp-server 70
    • exposure 28
    • drift 20
    • safety 25
  14. 29 D mcp-server-kubernetes 70
    • vuln 34
    • exposure 35
    • inherited 15
  15. 30 D AvivAvital2/Ariadne 69
    • exposure 35
    • drift 20
    • safety 14