← 홈

취약점 제보

11 posts
001
취약점 제보
CVE-2026-18482 : neo.mjs

OS command injection in the neo.mjs file-system MCP server (check_syntax / run_playwright_test)

2026.08.20
002
취약점 제보
kubeshark — CWE-22

MCP download_file writes fetched bytes to an unvalidated destination path

2026.08.13
003
취약점 제보
kubeshark — CWE-88

MCP start_kubeshark argument injection allows redirecting deployed images to an attacker-controlled registry

2026.08.13
004
취약점 제보
nginx-ui — CWE-494

Self-upgrade runs an unsigned binary verified only by a same-origin digest (CWE-494) → RCE via a compromised mirror or MITM

2026.08.12
005
취약점 제보
CVE-2026-57441 : mcpvault

PathFilter restricted-directory deny-list bypass via case and trailing dot/space equivalence

2026.08.03
006
취약점 제보
fast-agent — CWE-78/306

fast-agent serve binds HTTP to 0.0.0.0 with no authentication by default; with --shell this is unauthenticated remote command execution

2026.07.22
007
취약점 제보
nginx-ui — CWE-20

MCP nginx_config_add skips config directive validation → authenticated nginx directive injection (RCE on the official image)

2026.07.17
008
취약점 제보
nginx-ui — CWE-20/184

nginx config directive denylist (ValidateConfigFile) is bypassable via same-line ";" separation → authenticated directive injection (RCE on the official image)

2026.07.17
009
취약점 제보
CVE-2026-63129 : mssql-mcp-core

SQL injection in mssql-mcp write tools via unparameterized table names and WHERE clauses (CWE-89)

2026.07.08
010
취약점 제보
CVE-2026-62264 : pdf-reader-mcp

pdf-reader-mcp: configured MCP_API_KEY / X-API-Key auth is silently not enforced -> unauthenticated PDF disclosure (HTTP mode)

2026.06.25
011
취약점 제보
CVE-2026-55557 : browse-mcp

Arbitrary file write via unconfined download and state paths (CWE-22)

2026.06.13