CVE-2026-104634
Vulnerabilidad de conversión o cast de tipos incorrecto en BeamMCP.Server en ScriptKittyOS beam_mcp que permite que los argumentos de herramienta JSON true, false y null de un cliente MCP lleguen a la función de despacho del host como las cadenas "true", "false" y "nil". Después de que BeamMCP.Schema.validate/2 aceptara un valor como booleano, normalize_arguments/2 pasaba cada argumento por to_json_value/1, cuya cláusula para átomos convierte true, false y nil en cadenas. Una cadena es verdadera (truthy) en Elixir, por lo que un host que evalúa un argumento booleano, por ejemplo if args.dry_run, toma la rama opuesta para false, y una protección como confirm: false se interpreta como activada.
Leer descripción completaMostrar menos
El cliente controla el argumento y podría enviar true directamente, por lo que el impacto práctico se limita a los hosts cuyo comportamiento ante false difiere de su comportamiento ante true, y a cualquier capa de políticas situada delante del servidor que permita false pero rechace true. La misma normalización se aplica a los argumentos de prompts/get, que existen desde 0.5.0.
Este problema afecta a beam_mcp: desde 0.1.0 antes de 0.10.1.
Traducción automática del texto original de NVD (en inglés).
CVSS
- Versión: 4.0
- Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Puntuación base: 2.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.34%
- Percentil entre todas las CVEs puntuadas: 26
- Fecha de la puntuación: 9/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1210Exploitation of Remote Serviceslateral movement75 % - Impacto principal
T1565.002Transmitted Data Manipulationimpact60 %
Acceso de red con PR:L permite explotación remota de servicio (MCP). El tipo casting incorrecto permite manipular argumentos booleanos para alterar el comportamiento de funciones host, constituyendo manipulación de datos.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-704
Referencias
- https://cna.erlef.org/cves/CVE-2026-104634.html
- https://github.com/ScriptKittyOS/beam_mcp/commit/083838eb8e17fe5f6fcaf761bdbe203110288b0b
- https://github.com/ScriptKittyOS/beam_mcp/commit/289dbdbad641943b29a3b8d1eb36506cc8cec10a
- https://github.com/ScriptKittyOS/beam_mcp/security/advisories/GHSA-wv7p-j6qh-3hj4
- https://osv.dev/vulnerability/EEF-CVE-2026-104634
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-104634",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-104634",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-10-08T13:58:26.222349Z"
}
}
],
"cvssMetricV40": [
{
"type": "Secondary",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
"cvssData": {
"Safety": "NOT_DEFINED",
"version": "4.0",
"Recovery": "NOT_DEFINED",
"baseScore": 2.3,
"Automatable": "NOT_DEFINED",
"attackVector": "NETWORK",
"baseSeverity": "LOW",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"exploitMaturity": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"privilegesRequired": "LOW",
"subIntegrityImpact": "NONE",
"vulnIntegrityImpact": "LOW",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"vulnAvailabilityImpact": "NONE",
"availabilityRequirement": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"subConfidentialityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"confidentialityRequirement": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED"
}
}
]
},
"affected": [
{
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:scriptkittyos:beam_mcp:*:*:*:*:*:*:*:*"
],
"repo": "https://github.com/ScriptKittyOS/beam_mcp",
"vendor": "ScriptKittyOS",
"modules": [
"'Elixir.BeamMCP.Server'"
],
"product": "beam_mcp",
"versions": [
{
"status": "affected",
"version": "0.1.0",
"lessThan": "0.10.1",
"versionType": "semver"
}
],
"packageURL": "pkg:hex/beam_mcp",
"packageName": "beam_mcp",
"programFiles": [
"lib/beam_mcp/server.ex"
],
"collectionURL": "https://repo.hex.pm",
"defaultStatus": "unaffected",
"programRoutines": [
{
"name": "'Elixir.BeamMCP.Server':handle_message/2"
},
{
"name": "'Elixir.BeamMCP.Server':normalize_arguments/2"
},
{
"name": "'Elixir.BeamMCP.Server':to_json_value/1"
}
]
},
{
"cpes": [
"cpe:2.3:a:scriptkittyos:beam_mcp:*:*:*:*:*:*:*:*"
],
"repo": "https://github.com/ScriptKittyOS/beam_mcp",
"vendor": "ScriptKittyOS",
"modules": [
"'Elixir.BeamMCP.Server'"
],
"product": "beam_mcp",
"versions": [
{
"status": "affected",
"version": "083838eb8e17fe5f6fcaf761bdbe203110288b0b",
"lessThan": "289dbdbad641943b29a3b8d1eb36506cc8cec10a",
"versionType": "git"
}
],
"packageURL": "pkg:github/scriptkittyos/beam_mcp",
"packageName": "scriptkittyos/beam_mcp",
"programFiles": [
"lib/beam_mcp/server.ex"
],
"collectionURL": "https://github.com",
"defaultStatus": "unaffected",
"programRoutines": [
{
"name": "'Elixir.BeamMCP.Server':handle_message/2"
},
{
"name": "'Elixir.BeamMCP.Server':normalize_arguments/2"
},
{
"name": "'Elixir.BeamMCP.Server':to_json_value/1"
}
]
}
]
}
],
"published": "2026-10-08T14:16:46.370",
"references": [
{
"url": "https://cna.erlef.org/cves/CVE-2026-104634.html",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
},
{
"url": "https://github.com/ScriptKittyOS/beam_mcp/commit/083838eb8e17fe5f6fcaf761bdbe203110288b0b",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
},
{
"url": "https://github.com/ScriptKittyOS/beam_mcp/commit/289dbdbad641943b29a3b8d1eb36506cc8cec10a",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
},
{
"url": "https://github.com/ScriptKittyOS/beam_mcp/security/advisories/GHSA-wv7p-j6qh-3hj4",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
},
{
"url": "https://osv.dev/vulnerability/EEF-CVE-2026-104634",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
"description": [
{
"lang": "en",
"value": "CWE-704"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Incorrect Type Conversion or Cast vulnerability in BeamMCP.Server in ScriptKittyOS beam_mcp allows an MCP client's JSON true, false and null tool arguments to reach the host's dispatch function as the strings \"true\", \"false\" and \"nil\". After BeamMCP.Schema.validate/2 accepted a value as a boolean, normalize_arguments/2 passed every argument through to_json_value/1, whose atom clause converts true, false and nil to strings. A string is truthy in Elixir, so a host that tests a boolean argument, for example if args.dry_run, takes the opposite branch for false, and a guard such as confirm: false reads as set.\n\nThe client controls the argument and could send true directly, so the practical impact is limited to hosts whose behaviour on false differs from their behaviour on true, and to any policy layer in front of the server that permits false but refuses true. The same normalisation applies to prompts/get arguments, which exist from 0.5.0.\n\nThis issue affects beam_mcp: from 0.1.0 before 0.10.1."
}
],
"lastModified": "2026-10-08T21:01:07.830",
"sourceIdentifier": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
}