Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
562 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (1.9) | 1.1% | — | Elgentos Magento2-dev-mcpAI | 5/4/2026 | 24/7/2026 | A vulnerability was identified in elgentos magento2-dev-mcp up to 1.0.2. The affected element is the function executeMagerun2Command of the file src/index.ts. Such manipulation leads to os command injection. An attack has to be approached locally. The exploit is publicly available and might be used. The name of the… | |
| Aplazada | Baja (1.9) | 1.1% | — | Nor2-io Heim-mcpAI | 5/4/2026 | 24/7/2026 | A vulnerability was determined in Nor2-io heim-mcp up to 0.1.3. Impacted is the function registerTools of the file src/tools.ts of the component new_heim_application/deploy_heim_application/deploy_heim_application_to_cloud. This manipulation causes os command injection. The attack requires local access. The exploit… | |
| Aplazada | Baja (2.1) | 2.4% | — | Moussaabbadla Code-screenshot-mcpAI | 5/4/2026 | 24/7/2026 | A security vulnerability has been detected in MoussaabBadla code-screenshot-mcp up to 0.1.0. This affects an unknown part of the component HTTP Interface. Such manipulation leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. The vendor… | |
| Aplazada | Baja (2.1) | 0.35% | — | Mixelpixx Google Research MCPAI | 3/4/2026 | 24/7/2026 | A security vulnerability has been detected in mixelpixx Google-Research-MCP 1e062d7bd887bfe5f6e582b6cc288bb897b35cf2/ca613b736ab787bc926932f59cddc69457185a83. This issue affects the function extractContent of the file src/services/content-extractor.service.ts of the component Model Context Protocol Handler. The… | |
| Analizada | Alta (8.2) | 0.30% | — | Jlowin Fastmcp | 3/4/2026 | 24/7/2026 | FastMCP is the standard framework for building MCP applications. Prior to version 3.2.0, while testing the GitHubProvider OAuth integration, which allows authentication to a FastMCP MCP server via a FastMCP OAuthProxy using GitHub OAuth, it was discovered that the FastMCP OAuthProxy does not properly validate the… | |
| Analizada | Alta (7.8) | 0.73% | — | Jlowin Fastmcp | 3/4/2026 | 24/7/2026 | FastMCP is the standard framework for building MCP applications. Prior to version 3.2.0, server names containing shell metacharacters (e.g., &) can cause command injection on Windows when passed to fastmcp install claude-code or fastmcp install gemini-cli. These install paths use subprocess.run() with a list argument,… | |
| Modificada | Alta (7.6) | 0.66% | — | Lfprojects MCP GO SDK | 2/4/2026 | 24/7/2026 | The Go MCP SDK used Go's standard encoding/json. Prior to version 1.4.0, the Model Context Protocol (MCP) Go SDK does not enable DNS rebinding protection by default for HTTP-based servers. When an HTTP-based MCP server is run on localhost without authentication with StreamableHTTPHandler or SSEHandler, a malicious… | |
| Modificada | Crítica (10) | 1.4% | — | Jlowin Fastmcp | 2/4/2026 | 15/7/2026 | FastMCP is a Pythonic way to build MCP servers and clients. Prior to version 3.2.0, the OpenAPIProvider in FastMCP exposes internal APIs to MCP clients by parsing OpenAPI specifications. The RequestDirector class is responsible for constructing HTTP requests to the backend service. A vulnerability exists in the… | |
| Aplazada | Baja (2.1) | 1.8% | — | Efforthye Fast-filesystem-mcpAI | 2/4/2026 | 17/6/2026 | A security flaw has been discovered in efforthye fast-filesystem-mcp up to 3.5.1. The affected element is the function handleGetDiskUsage of the file src/index.ts. Performing a manipulation results in command injection. The attack is possible to be carried out remotely. The exploit has been released to the public and… | |
| Aplazada | Baja (1.9) | 0.14% | — | Priyankark A11y-mcpAI | 2/4/2026 | 17/6/2026 | A vulnerability was found in priyankark a11y-mcp up to 1.0.5. This vulnerability affects the function A11yServer of the file src/index.js. The manipulation results in server-side request forgery. The attack must be initiated from a local position. The exploit has been made public and could be used. This product… | |
| Aplazada | Media (5.5) | 0.41% | — | Alejandroarciniegas Mcp-data-visAI | 2/4/2026 | 17/6/2026 | A vulnerability has been found in AlejandroArciniegas mcp-data-vis bc597e391f184d2187062fd567599a3cb72adf51/de5a51525a69822290eaee569a1ab447b490746d. This affects the function Request of the file src/servers/database/server.js of the component MCP Handler. The manipulation leads to sql injection. The attack may be… | |
| Modificada | Media (6.1) | 0.31% | — | Lfprojects MCP Java SDK | 31/3/2026 | 24/7/2026 | MCP Java SDK is the official Java SDK for Model Context Protocol servers and clients. Prior to versions 0.83.0, 1.0.1, and 1.1.1, there is a hardcoded wildcard CORS vulnerability. This issue has been patched in versions 0.83.0, 1.0.1, and 1.1.1. | |
| Aplazada | Baja (1.9) | 1.1% | — | Raine Consult Consult LLM MCPAI | 30/3/2026 | 17/6/2026 | A vulnerability was detected in raine consult-llm-mcp up to 2.5.3. Affected by this vulnerability is the function child_process.execSync of the file src/server.ts. The manipulation of the argument git_diff.base_ref/git_diff.files results in os command injection. The attack is only possible with local access. The… | |
| Aplazada | Baja (1.9) | 1.1% | — | Dedeveloper23 Codebase-mcpAI | 29/3/2026 | 17/6/2026 | A vulnerability has been found in DeDeveloper23 codebase-mcp up to 3ec749d237dd8eabbeef48657cf917275792fde6. This vulnerability affects the function getCodebase/getRemoteCodebase/saveCodebase of the file src/tools/codebase.ts of the component RepoMix Command Handler. Such manipulation leads to os command injection.… | |
| Aplazada | Baja (1.9) | 1.1% | — | Kazuph Mcp-docs-ragAI | 28/3/2026 | 17/6/2026 | A vulnerability was identified in kazuph mcp-docs-rag up to 0.5.0. Affected is the function cloneRepository of the file src/index.ts of the component add_git_repository/add_text_file. The manipulation leads to os command injection. The attack needs to be performed locally. The exploit is publicly available and might… | |
| Analizada | Media (6.5) | 0.52% | — | Mobilenexthq Mobile MCP | 27/3/2026 | 17/6/2026 | Mobile Next is an MCP server for mobile development and automation. Prior to version 0.0.49, the `@mobilenext/mobile-mcp` server contains a Path Traversal vulnerability in the `mobile_save_screenshot` and `mobile_start_screen_recording` tools. The `saveTo` and `output` parameters were passed directly to filesystem… | |
| Analizada | Alta (8.1) | 0.43% | 💥 PoC | Pab1it0 Azure Data Explorer MCP Server | 27/3/2026 | 17/6/2026 | Azure Data Explorer MCP Server is a Model Context Protocol (MCP) server that enables AI assistants to execute KQL queries and explore Azure Data Explorer (ADX/Kusto) databases through standardized interfaces. Versions up to and including 0.1.1 contain KQL (Kusto Query Language) injection vulnerabilities in three MCP… | |
| Analizada | Alta (8.2) | 0.54% | — | Lfprojects MCP Ruby SDK | 27/3/2026 | 17/6/2026 | MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to version 0.9.2, the Ruby SDK's streamable_http_transport.rb implementation contains a session hijacking vulnerability. An attacker who obtains a valid session ID can completely hijack the victim's Server-Sent Events (SSE)… | |
| Analizada | Media (6.5) | 0.21% | — | Lfprojects MCP GO SDK | 24/3/2026 | 17/6/2026 | The Go MCP SDK used Go's standard encoding/json. Prior to version 1.4.1, the Go SDK's Streamable HTTP transport accepted browser-generated cross-site `POST` requests without validating the `Origin` header and without requiring `Content-Type: application/json`. In deployments without Authorization, especially stateless… | |
| Aplazada | Baja (1.9) | 1.4% | — | Sigmade Git-mcp-serverAI | 20/3/2026 | 17/6/2026 | A vulnerability was found in sigmade Git-MCP-Server up to 785aa159f262a02d5791a5d8a8e13c507ac42880. Affected by this vulnerability is the function child_process.exec of the file src/gitUtils.ts of the component show_merge_diff/quick_merge_summary/show_file_diff. The manipulation results in os command injection. The… | |
| Analizada | Alta (8.8) | 0.46% | — | Doobidoo Mcp-memory-service | 20/3/2026 | 17/6/2026 | mcp-memory-service is an open-source memory backend for multi-agent systems. Prior to version 10.25.1, when the HTTP server is enabled (MCP_HTTP_ENABLED=true), the application configures FastAPI's CORSMiddleware with allow_origins=['*'], allow_credentials=True, allow_methods=["*"], and allow_headers=["*"]. The… | |
| Analizada | Media (5.7) | 0.30% | — | Ondata Ckan MCP Server | 20/3/2026 | 17/6/2026 | CKAN MCP Server is a tool for querying CKAN open data portals. Versions prior to 0.4.85 provide tools including ckan_package_search and sparql_query that accept a base_url parameter, making HTTP requests to arbitrary endpoints without restriction. A CKAN portal client has no legitimate reason to contact cloud metadata… | |
| Aplazada | Crítica (9.8) | 2.1% | — | Kubectl-mcp-serverAI | 16/3/2026 | 17/6/2026 | A command injection vulnerability in the minimal_wrapper.py component of kubectl-mcp-server v1.2.0 allows attackers to execute arbitrary commands via injecting arbitrary shell metacharacters. | |
| Modificada | Alta (7.4) | 0.36% | — | Jlowin Fastmcp | 16/3/2026 | 15/7/2026 | FastMCP is the standard framework for building MCP applications. Prior to version 2.14.2, the server does not properly respect the resource parameter submitted by the client in the authorization and token request. Instead of issuing the token explicitly for the MCP server, the token is issued for the base_url passed… | |
| Analizada | Media (6.8) | 0.18% | — | Amazon AWS API MCP Server | 16/3/2026 | 17/6/2026 | Improper Protection of Alternate Path exists in the no-access and workdir feature of the AWS API MCP Server versions >= 0.2.14 and < 1.3.9 on all platforms may allow the bypass of intended file access restriction and expose arbitrary local file contents in the MCP client application context. To remediate this issue,… |