Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
561 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2) | 0.35% | — | Maa-ai MaamcpAI | 28/8/2026 | 28/8/2026 | A vulnerability was found in MAA-AI MaaMCP up to 1.1.1.dev6+g2e4a41287. The affected element is the function save_pipeline/load_pipeline of the file pipeline_tools.py. Performing a manipulation results in path traversal. The attack can be initiated remotely. The exploit has been made public and could be used. The… | |
| Aplazada | Baja (2.1) | 0.50% | — | Arben-adm Mcp-sequential-thinkingAI | 28/8/2026 | 31/8/2026 | A vulnerability has been found in arben-adm mcp-sequential-thinking up to 0.5.0. Impacted is the function import_session/export_session of the file mcp_sequential_thinking/server.py of the component Import Session/Export Session. Such manipulation of the argument file_path leads to path traversal. It is possible to… | |
| Aplazada | Crítica (10) | 0.78% | — | Ui-tars-desktop Mcp-http-serverAIAgent-infra Mcp-server-commandsAIAgent-infra Mcp-server-filesystemAI | 27/8/2026 | 23/9/2026 | startServer.ts in the mcp-http-server package of UI-TARS-desktop defaulted its listen address to '::' when no host was given, so startSseAndStreamableHttpMcpServer bound the Streamable HTTP and SSE MCP transports to every interface, and its authentication middleware was optional: middlewares are applied only when a… | |
| Aplazada | Baja (2.3) | 0.18% | — | MCP Server DashAI | 27/8/2026 | 24/9/2026 | The Dash MCP server bound its listener to the loopback address but never checked the host a request named. src/mcp_server_dash.py constructed the server for its network mode with the interface restricted to loopback and no transport-security settings, so a name that had been pointed at the loopback address still… | |
| Aplazada | Alta (7.6) | 0.22% | — | Tiger-gh-mcp-serverAI | 27/8/2026 | 23/9/2026 | tiger-gh-mcp-server started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides. src/httpServer.ts called the shared httpServerFactory helper and never set the DNS-rebinding-protection option, so the transport accepted a request whatever host it named, making the locally reachable… | |
| Aplazada | Alta (7.6) | 0.22% | — | Tiger-slackAISlack MCPAI | 27/8/2026 | 23/9/2026 | tiger-slack started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides. mcp/src/httpServer.ts called the shared httpServerFactory helper and never set the DNS-rebinding-protection option, so the transport accepted a request whatever host it named, and a page in a browser could… | |
| Aplazada | Crítica (9.3) | 0.73% | — | Telnyx MCP ServerAI | 27/8/2026 | 24/9/2026 | The Telnyx MCP server exposed its HTTP transport on every interface and did not require a caller credential. packages/mcp-server/src/http.ts served MCP on the root path with a listener bound to all interfaces and parsed the caller's authentication headers in a mode that did not fail when they were absent, so a request… | |
| Aplazada | Crítica (9.3) | 0.61% | — | Mcp-routerAI | 27/8/2026 | 23/9/2026 | The mcp-router CLI served its MCP aggregator on every interface and enforced authentication only when the operator asked for it. The serve command in apps/cli/src/commands/serve.ts defaulted its host to the all-interfaces address on a fixed port, and required a token only when the corresponding flag was supplied, so a… | |
| Aplazada | Alta (7.6) | 0.22% | — | Mcp-goAI | 27/8/2026 | 23/9/2026 | mcp-go accepted requests on its HTTP transports without checking the Host header. StreamableHTTPServer.ServeHTTP in server/streamable_http.go and SSEServer.ServeHTTP in server/sse.go served any request arriving over a loopback connection regardless of the host it named, and the SSE transport's cross-origin default… | |
| Aplazada | Alta (8.7) | 0.47% | — | Mcp-use InspectorAI | 27/8/2026 | 23/9/2026 | The proxy middleware in mcp-use's inspector forwards requests to a destination the caller names. mountMcpProxy in libraries/typescript/packages/inspector/src/server/proxy/mcp-proxy.ts read the target from the X-Target-URL header or the __mcp_target parameter and proxied to it without inspecting the host, so loopback,… | |
| Aplazada | Media (5.5) | 0.59% | — | Boxpositron With-context-mcpAI | 27/8/2026 | 28/8/2026 | A flaw has been found in boxpositron with-context-mcp up to 3.0.7. This affects the function ingest_notes/teleport_notes/sync_notes/project_folder of the file src/index.ts. Executing a manipulation can lead to path traversal. It is possible to launch the attack remotely. The exploit has been published and may be used.… | |
| Aplazada | Media (5.5) | 0.69% | — | Mcp-file-context-serverAI | 27/8/2026 | 28/8/2026 | A vulnerability was detected in bsmi021 mcp-file-context-server 1.0.0. Affected by this issue is the function read_context of the file src/index.ts of the component Path Resolution. Performing a manipulation of the argument path results in path traversal. It is possible to initiate the attack remotely. The exploit is… | |
| Aplazada | Media (5.5) | 0.69% | — | Danielpopamd Linkedin-ads-mcpAI | 27/8/2026 | 28/8/2026 | A security vulnerability has been detected in danielpopamd linkedin-ads-mcp 1.0.0. Affected by this vulnerability is the function fs.readFileSync of the file src/tools/campaign-management.ts of the component Media Upload. Such manipulation of the argument filePath leads to path traversal. The attack may be performed… | |
| Aplazada | Media (5.5) | 0.50% | — | Ddfourtwo Sentry-selfhosted-mcpAI | 27/8/2026 | 28/8/2026 | A security flaw has been discovered in ddfourtwo sentry-selfhosted-mcp 0.4.0. The affected element is an unknown function of the component raw_sentry_api. The manipulation of the argument endpoint results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been released to the… | |
| Aplazada | Alta (8.7) | 0.35% | — | Mcp-fetchAI | 26/8/2026 | 24/9/2026 | mcp-fetch checks a fetch target against its SSRF guard without removing the brackets that surround an IPv6 literal. isSafeUrl reads the hostname from the parsed URL, which for a literal such as http://[::1]/ yields the bracketed string, and then tests it with net.isIP. That call returns zero for a bracketed value, so… | |
| Aplazada | Media (6.9) | 0.61% | — | Anthropic MCP SDKAI | 25/8/2026 | 9/9/2026 | The MCP PHP SDK (Composer package mcp/sdk) is the official Model Context Protocol SDK for PHP. In versions 0.5.0 through 0.7.0, the HTTP client transport reads a Server-Sent Events response stream incrementally and appends each chunk to an in-memory buffer with no upper bound. The buffer is only flushed when an SSE… | |
| Aplazada | Alta (8.8) | 0.26% | — | Genieacs-mcpAI | 25/8/2026 | 9/9/2026 | genieacs-mcp is an MCP server for GenieACS written in Go. Prior to 0.3.2, the Streamable HTTP transport in cmd/server/main.go creates an unauthenticated /mcp listener on the default MCP_LISTEN_ADDR value 127.0.0.1:8080 when MCP_AUTH_TOKEN is unset and the httpSrv.Start(addr) branch does not validate the Host or Origin… | |
| Aplazada | Alta (8.6) | 0.24% | — | Browse MCPAI | 25/8/2026 | 9/9/2026 | browse-mcp is a Playwright-based headless-browser MCP server for MCP-capable agents. Prior to 0.8.2, browser_download writes a fetched response body to join(save_dir, filename) without validating the caller-controlled save_dir, while browser_save_state and browser_load_state honor a caller-controlled path unchanged. A… | |
| Aplazada | Crítica (9.1) | 0.73% | — | Nextcloud MCP ServerAI | 25/8/2026 | 9/9/2026 | Nextcloud MCP Server is a production-ready MCP server that connects AI assistants to a Nextcloud instance. Prior to 0.117.2, the POST /webhooks/nextcloud endpoint in nextcloud_mcp_server/vector/webhook_receiver.py has no authentication by default because WEBHOOK_SECRET defaults to None and startup validation does not… | |
| Aplazada | Alta (8.4) | 0.27% | — | Git-scm GITAISonirico Mcp-shellAI | 25/8/2026 | 9/9/2026 | mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, the default security.yaml allows /usr/bin/git, while security.go omits ! from containsShellMetacharacters and containsDangerousShellConstructs and applies no per-executable argument policy. A caller of the… | |
| Aplazada | Alta (8.4) | 0.45% | — | Sonirico Mcp-shellAI | 25/8/2026 | 9/9/2026 | mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, the default Docker security.yaml includes /bin/bash in allowed_executables, while security.go validates only the first token and checkBlockedPatternsAndCommands does not reject the shell command-mode flag -c. A… | |
| Aplazada | Alta (8.6) | 0.20% | — | Sonirico Mcp-shellAI | 25/8/2026 | 9/9/2026 | mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, config.go initializes Security.Enabled to false, and when MCP_SHELL_SEC_CONFIG_FILE is unset, main.go starts the documented bare-binary deployment without a security policy. SecurityValidator.validateCommand in… | |
| Aplazada | Crítica (9.8) | 0.73% | — | Qwed MCPAISympyAI | 25/8/2026 | 9/9/2026 | QWED-MCP is a deterministic verification gateway for MCP. Prior to 0.2.1, verify_math_expression() in src/qwed_mcp/engines/math_engine.py passes attacker-controlled expression and claimed_result strings directly to SymPy's parse_expr() after only normalizing caret syntax to Python exponent syntax, without restricting… | |
| Aplazada | Media (5.5) | 0.61% | — | Dekdee Adobe-xd-mcpAI | 25/8/2026 | 26/8/2026 | A weakness has been identified in dekdee adobe-xd-mcp 1.0.0. Impacted is an unknown function of the file src/parsers/xd-parser.ts of the component file-access-from-request Endpoint. Executing a manipulation of the argument outputFile/outputDir can lead to path traversal. It is possible to launch the attack remotely.… | |
| Aplazada | Baja (1.9) | 1.1% | — | Sworddut Mcp-ffmpeg-helperAI | 24/8/2026 | 26/8/2026 | A vulnerability was detected in sworddut mcp-ffmpeg-helper 0.1.0/0.1.1/0.2.1. This affects the function handleToolCall of the file src/tools/handlers.ts of the component Tool Handler. The manipulation of the argument format results in os command injection. Attacking locally is a requirement. The exploit is now public… |