Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

562 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (1.9)0.17%—Aktsmm Skill-ninja-mcp-serverAI9/8/202612/8/2026
A vulnerability has been found in aktsmm skill-ninja-mcp-server 0.1.0. Impacted is the function getInstalledSkills/installSkill/updateAgentsMd/uninstallSkill of the file src/installer.ts. The manipulation of the argument workspacePath leads to path traversal. The attack needs to be performed locally. Upgrading to…
AplazadaBaja (1.9)0.17%—Incomestreamsurfer ROO Code Memory Bank MCP ServerAI9/8/202614/8/2026
A security vulnerability has been detected in IncomeStreamSurfer roo-code-memory-bank-mcp-server up to 9dcb2fb5e6b65a35ac1983885a6d4e5621a0081e. This affects the function readMemoryBankFile/appendMemoryBankEntry of the file src/index.ts of the component read_memory_bank_file/append_memory_bank_entry. Such manipulation…
AplazadaBaja (1.9)0.18%—Helloggx Shadcn VUE MCPAI9/8/202612/8/2026
A weakness has been identified in HelloGGX shadcn-vue-mcp up to e170e277b94235cde627803277fc8c41103a4d38. Affected by this issue is the function fs.promises.readFile of the file src/server/callback-server.ts. This manipulation of the argument filepath causes path traversal. The attack is restricted to local execution.…
AplazadaBaja (1.9)0.17%—Azer React Analyzer MCPAI9/8/202612/8/2026
A security flaw has been discovered in azer react-analyzer-mcp up to 335f2a3585f265e2e88352b59b10d3b478d678b0. Affected by this vulnerability is the function generateProjectDocs of the file src/index.ts of the component analyze-projec. The manipulation of the argument projectName results in path traversal. The attack…
AplazadaBaja (1.9)0.17%—Astralisone Rive-mcp-server-coreAI8/8/202612/8/2026
A vulnerability has been found in astralisone rive-mcp-server-core up to db1d0cc4cd52589116360428b7504fd0ca748b3e. This affects an unknown part of the file packages/mcp-server/src/tools/importRiveFile.ts of the component importRiveFile Flow. Such manipulation of the argument libraryId leads to path traversal. The…
AplazadaBaja (1.9)0.17%—Abrinsmead Mindpilot-mcpAI8/8/202612/8/2026
A flaw has been found in abrinsmead mindpilot-mcp 0.5.0. Affected by this issue is some unknown functionality of the component HistoryService. This manipulation of the argument ID causes path traversal. The attack needs to be launched locally. The project was informed of the problem early through an issue report but…
AplazadaBaja (1.9)1.1%—Andreahaku LLM Memory MCPAI8/8/202612/8/2026
A weakness has been identified in andreahaku llm_memory_mcp up to f11dc8bcff3ff8cf943a2945f99ff3b0bdc8a6d0. This impacts the function auto.capture of the file src/autolearn/GitHooksManager.ts of the component llm_memory_mcp. Executing a manipulation of the argument hash can lead to command injection. The attack is…
AplazadaBaja (1.9)1.1%—Adolfosalasgomez3011 Slidev-builder-mcpAI8/8/202612/8/2026
A security flaw has been discovered in adolfosalasgomez3011 slidev-builder-mcp 2.1.0. This affects the function generateChart of the file src/tools/generateAssets.ts of the component generateAssets Tool. Performing a manipulation of the argument outputDir results in command injection. The attack is only possible with…
AplazadaBaja (1.9)1.1%—Mimiclab Mcp-pdf-visionAI8/8/202612/8/2026
A vulnerability was identified in MIMICLab mcp-pdf-vision 1.1.0. The impacted element is the function load_pdf of the file src/index.ts. Such manipulation of the argument pdfPath/sessionId leads to command injection. The attack can only be performed from a local environment. The project was informed of the problem…
AplazadaBaja (1.9)0.17%—Hulupeep Mcp-ui-probeAI8/8/202614/8/2026
A security flaw has been discovered in Hulupeep mcp-ui-probe up to 0.2.0. Affected is the function get_journey/delete_journey/analyze_journey/usage_stats of the file src/journey/JourneyStorage.ts of the component Journey/Usage. The manipulation of the argument journeyId/filename results in path traversal. The attack…
AplazadaBaja (2.1)1.8%—Abdullah1854 McpgatewayAI8/8/202612/8/2026
A vulnerability was identified in abdullah1854 MCPGateway up to 549f494a9e363f40530149de324b8097de424230. This impacts the function getUsageByDateRange of the file src/services/claude-usage.ts of the component Claude Usage Range Endpoint. The manipulation of the argument since leads to command injection. The attack…
AplazadaMedia (6.9)2.1%—Inquirelab Mcp-bridge-apiAI8/8/202612/8/2026
A vulnerability was found in INQUIRELAB mcp-bridge-api up to b30a82aa1d1d1139e0de846c41c8aadee6e06114. The impacted element is an unknown function of the file mcp-bridge.js of the component Servers Endpoint. Performing a manipulation of the argument command/args results in command injection. It is possible to initiate…
AplazadaCrítica (9.1)0.59%—Meta ADS MCPAI7/8/202610/9/2026
Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.109, `AuthInjectionMiddleware.dispatch()` at `http_auth_integration.py:272` unconditionally forwards unauthenticated Streamable HTTP requests to downstream MCP tool handlers without issuing a `401`…
AplazadaBaja (1.9)1.1%—Noctedefensor LudusmcpAI6/8/202612/8/2026
A vulnerability was detected in NocteDefensor LudusMCP up to 1.0.24. This affects the function executeArbitraryCommand/executeCommand of the file src/ludusMCP/cliWrapper.ts of the component ludus_cli_execute. Performing a manipulation of the argument command/args results in command injection. The attack needs to be…
AplazadaMedia (4.8)0.17%—Noctedefensor Ludus MCPAI6/8/202612/8/2026
A security vulnerability has been detected in NocteDefensor LudusMCP up to 1.0.24. The impacted element is an unknown function of the file src/tools/ludusEnvironmentGuidesSearch.ts of the component ludus_environment_guides_search. Such manipulation of the argument guide_name leads to path traversal. Local access is…
AplazadaBaja (1.9)1.1%—Noctedefensor Ludus MCPAI6/8/202612/8/2026
A weakness has been identified in NocteDefensor LudusMCP up to 1.0.24. The affected element is the function SecretDialog.showSecretDialog of the file src/utils/secretDialog.ts of the component get_credential_from_user. This manipulation of the argument Description causes command injection. It is possible to launch the…
AplazadaBaja (1.9)1.1%—Leesinliang Godot-mcpAI6/8/202612/8/2026
A flaw has been found in LeeSinLiang godot-mcp 0.1.0. Affected by this vulnerability is the function executeOperation of the file src/index.ts of the component create_scene/add_node. This manipulation of the argument projectPath causes command injection. The attack needs to be launched locally. The project was…
AplazadaBaja (2.1)2.1%—Missionsquad Mcp-apiAI6/8/202612/8/2026
A vulnerability has been found in MissionSquad mcp-api up to 1.11.8. The impacted element is the function this.packageService.installPackage of the file src/controllers/packages.ts of the component NPM Package Version Handler. The manipulation leads to command injection. It is possible to initiate the attack remotely.…
AplazadaBaja (2.1)0.43%—Missionsquad Mcp-apiAI6/8/202612/8/2026
A flaw has been found in MissionSquad mcp-api up to 1.11.9. The affected element is an unknown function of the file src/services/dcrClients.ts. Executing a manipulation can lead to server-side request forgery. The attack may be performed from remote. Upgrading to version 1.11.10 is sufficient to fix this issue. This…
AplazadaBaja (1.9)1.2%—Kino-kafkaesque Ssh-mcp-serverAI6/8/202612/8/2026
A vulnerability was detected in Kino-Kafkaesque ssh-mcp-server up to 8ebbbb99b26f80ff6162fe00957c6dec73fbc5a5. Impacted is the function ssh_exec of the file src/index.ts of the component SSH Command Handler. Performing a manipulation of the argument host/username results in command injection. The attack requires a…
AplazadaBaja (2.1)0.50%—Monomythdevelopment La-forge-mcpAI6/8/202612/8/2026
A security vulnerability has been detected in MonomythDevelopment la-forge-mcp 1.0.0. This issue affects the function screenshotElement of the file src/index.ts of the component screenshot_element Tool. Such manipulation of the argument output_name leads to path traversal. The attack can be executed remotely.…
AplazadaCrítica (9.3)0.73%—FrontmcpAIZODAI6/8/202610/9/2026
FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). Prior to 1.5.7, the sandboxed codecall:execute tool exposes live host Zod schema instances to the script via getTool(), and because Zod v4 defines _zod as a non-configurable, non-writable own property, the ECMAScript Proxy invariants force…
AnalizadaMedia (5.7)0.16%—Amazon Documentdb MCP Server5/8/202610/8/2026
Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server before 1.0.12 might allow an authenticated MCP client to perform inappropriate write operations on the connected database via write-capable aggregation pipeline stages that bypass the read-only mode enforcement logic. To…
AnalizadaMedia (6.3)0.18%💥 PoCAmazon AWS Transform MCP Server5/8/202610/8/2026
Improper limitation of a pathname to a restricted directory in the get_resource tool in Amazon awslabs.aws-transform-mcp-server 0.1.0 through 0.1.4 might allow a context-dependent actor to write arbitrary files outside the intended working directory via the savePath parameter. To remediate this issue, users should…
Pendiente de análisisAlta (7.1)0.42%—Awslabs Amazon MQ MCP ServerAIAmazon MQAI3/8/20264/8/2026
Improper restriction of intended endpoints in the RabbitMQ broker connection tools of the Amazon MQ MCP Server (awslabs.amazon-mq-mcp-server) before 2.0.24 may allow a remote unauthenticated actor (via prompt injection) to obtain Amazon MQ for RabbitMQ broker credentials or OAuth access tokens sent to a crafted…
Orbitaley — Vulnerabilidades