Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2614▼ 473 respecto a la semana anterior
Críticas / altas1270▼ 74 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)243▼ 274 respecto a la semana anterior
67 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 1.1% | — | 0xshariq Github-mcp-serverAI | 30/9/2026 | 2/10/2026 | A vulnerability was identified in 0xshariq github-mcp-server up to 52e764a7d66eac1726fce02ca7bb5a638571801a. This issue affects the function child_process.exec of the file src/github.ts of the component Git Remove MCP Tool. Such manipulation of the argument File leads to os command injection. The attack can be… | |
| Aplazada | Crítica (9) | 1.7% | — | Amazon Awslabs Postgres-mcp-serverAI | 9/9/2026 | 10/9/2026 | An OS command injection weakness in the read-only enforcement of the SQL validation component in Amazon awslabs postgres-mcp-server before 1.1.7 might allow an unauthenticated actor to execute operating system commands on the host of a self-managed PostgreSQL server by placing a crafted COPY ... TO PROGRAM statement… | |
| Pendiente de análisis | Media (5.7) | 0.18% | — | Amazon Awslabs Mysql-mcp-serverAI | 9/9/2026 | 9/9/2026 | Incomplete list of disallowed inputs in the mutable SQL detector component in Amazon awslabs mysql-mcp-server might allow context-dependent actors to bypass the read-only enforcement gate and reach file-read and file-write SQL sinks via SQL inline comments that the regex engine does not treat as whitespace. To… | |
| Pendiente de análisis | Alta (7.1) | 0.34% | — | Amazon Postgres-mcp-serverAI | 4/9/2026 | 8/9/2026 | An incomplete list of disallowed inputs in the SQL validation component in Amazon awslabs postgres-mcp-server before version 1.1.7 might allow an unauthenticated actor to modify data beyond the read-only scope by placing crafted SQL into the content that is submitted when an authenticated user interacts with the MCP… | |
| Pendiente de análisis | Alta (7.1) | 0.21% | — | Amazon Awslabs.dynamodb-mcp-serverAI | 4/9/2026 | 8/9/2026 | Improper neutralization of special elements used in a template engine in the CDK generator in Amazon awslabs.dynamodb-mcp-server before 2.1.6 might allow a context-dependent actor to execute arbitrary code on the host that deploys the generated application via crafted table, index, or attribute names in a data model… | |
| Aplazada | Crítica (9.3) | 0.69% | — | Excel-mcp-serverAI | 4/9/2026 | 23/9/2026 | excel-mcp-server 0.1.8 fails to enforce path confinement in stdio mode when EXCEL_FILES_PATH is unset, allowing attackers to read and write arbitrary files. Attackers can supply unchecked file paths to read and write tools to access any file accessible to the process. | |
| Aplazada | Crítica (9.2) | 0.62% | — | Cli-mcp-serverAI | 4/9/2026 | 24/9/2026 | cli-mcp-server 0.2.5 contains a command allowlist bypass vulnerability in the _validate_command_with_operators function when ALLOW_SHELL_OPERATORS is enabled. Attackers can use shell command substitution syntax like $(...) or backticks to execute non-allowlisted commands that bypass the ALLOWED_COMMANDS validation… | |
| Aplazada | Alta (8.7) | 0.48% | — | Git-mcp-serverAI | 4/9/2026 | 23/9/2026 | git-mcp-server 2.15.1 contains an argument injection vulnerability in the ref and object parameters of git_log, git_diff, and git_show tools that lack leading-dash validation. Attackers can inject git command-line options like --output= to write files outside the repository to arbitrary paths accessible by the process. | |
| Aplazada | Alta (8.7) | 0.90% | — | Firecrawl-mcp-serverAI | 4/9/2026 | 23/9/2026 | firecrawl-mcp-server 3.20.2 contains an arbitrary local file read vulnerability in the firecrawl_parse tool that accepts unconstrained filePath arguments without directory containment validation. Attackers can supply absolute paths or directory traversal sequences to read sensitive files like credentials and… | |
| Aplazada | Media (6.9) | 0.19% | — | Appium-mcp-serverAI | 1/9/2026 | 8/9/2026 | appium-mcp-server through 0.1.61 fails to validate or normalize file paths in the write_file and write_files_batch tools, allowing attackers to write files outside the intended PROJECT_ROOT directory. Attackers can supply absolute paths or relative paths with parent directory segments to overwrite arbitrary files with… | |
| Aplazada | Crítica (10) | 0.78% | — | Ui-tars-desktop Mcp-http-serverAIAgent-infra Mcp-server-commandsAIAgent-infra Mcp-server-filesystemAI | 27/8/2026 | 23/9/2026 | startServer.ts in the mcp-http-server package of UI-TARS-desktop defaulted its listen address to '::' when no host was given, so startSseAndStreamableHttpMcpServer bound the Streamable HTTP and SSE MCP transports to every interface, and its authentication middleware was optional: middlewares are applied only when a… | |
| Aplazada | Alta (7.6) | 0.22% | — | Tiger-gh-mcp-serverAI | 27/8/2026 | 23/9/2026 | tiger-gh-mcp-server started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides. src/httpServer.ts called the shared httpServerFactory helper and never set the DNS-rebinding-protection option, so the transport accepted a request whatever host it named, making the locally reachable… | |
| Aplazada | Baja (1.9) | 1.2% | — | Jiantao88 Android-mcp-serverAI | 17/8/2026 | 20/8/2026 | A flaw has been found in jiantao88 android-mcp-server up to cfb872b2446794193b58edd63f4dbf6af48a6292. The impacted element is the function child_process.exec of the file build/index.js of the component Command Execution. Executing a manipulation of the argument… | |
| Aplazada | Baja (2) | 0.30% | — | Jij-inc Jij-mcp-serverAI | 17/8/2026 | 20/8/2026 | A vulnerability was found in Jij-Inc Jij-MCP-Server 0.1.0. This affects the function PythonREPL.run of the file jij_mcp/python_repr.py of the component jm_check. The manipulation of the argument code results in code injection. It is possible to launch the attack remotely. The exploit has been made public and could be… | |
| Aplazada | Baja (2.1) | 0.37% | — | Graphlit-mcp-serverAI | 16/8/2026 | 20/8/2026 | A vulnerability was identified in graphlit graphlit-mcp-server 1.0.1. This affects the function fetch of the file src/tools.ts of the component ssrf-test Endpoint. Such manipulation of the argument url leads to server-side request forgery. The attack may be launched remotely. The exploit is publicly available and… | |
| Aplazada | Media (5.3) | 0.37% | — | Gomarble-ai Facebook-ads-mcp-serverAI | 16/8/2026 | 20/8/2026 | A vulnerability has been found in gomarble-ai facebook-ads-mcp-server 0.1.0. The impacted element is the function fetch_pagination_url of the file server.py. Such manipulation leads to server-side request forgery. The attack can be launched remotely. The name of the patch is 4e53875aa22e8991c2fa4a7660d86e1caba66659.… | |
| Aplazada | Baja (1.9) | 0.14% | — | Feedmob Fm-mcp-serversAI | 14/8/2026 | 14/8/2026 | A vulnerability was identified in feedmob fm-mcp-servers 0.0.3. Affected by this vulnerability is the function downloadReport of the file src/smadex-reporting/src/index.ts of the component Download Endpoint. The manipulation of the argument downloadUrl leads to server-side request forgery. The attack can only be… | |
| Aplazada | Baja (1.9) | 0.15% | — | Phialsbasement Koboldcpp-mcp-serverAI | 9/8/2026 | 12/8/2026 | A weakness has been identified in PhialsBasement KoboldCPP-MCP-Server 1.0.0. Affected by this issue is the function makeRequest of the file src/index.ts of the component BaseConfigSchema. Executing a manipulation of the argument apiUrl can lead to server-side request forgery. It is possible to launch the attack on the… | |
| Aplazada | Baja (1.9) | 0.17% | — | Handwriting-ocr-mcp-serverAI | 9/8/2026 | 12/8/2026 | A security flaw has been discovered in Handwriting-OCR handwriting-ocr-mcp-server 0.1.0. Affected by this vulnerability is the function fs.readFileSync of the file src/index.ts of the component upload_document. Performing a manipulation of the argument File results in path traversal. Attacking locally is a… | |
| Aplazada | Baja (1.9) | 0.15% | — | Ks-gen-ai Jira-mcp-serverAI | 9/8/2026 | 12/8/2026 | A vulnerability was found in KS-GEN-AI jira-mcp-server 0.2.0. This affects the function axios.get of the file src/index.ts of the component add_attachment_from_public_url. The manipulation of the argument imageUrl results in server-side request forgery. The attack requires a local approach. The project was informed of… | |
| Aplazada | Baja (2.1) | 0.37% | — | Aliyun Alibabacloud-dataworks-mcp-serverAI | 9/8/2026 | 12/8/2026 | A security flaw has been discovered in aliyun alibabacloud-dataworks-mcp-server up to 1.0.43. The impacted element is the function ReadResourceRequestSchema of the file src/resources/initResources.ts. The manipulation of the argument request.params.uri results in server-side request forgery. The attack may be launched… | |
| Aplazada | Baja (1.9) | 0.17% | — | Bazylhorsey Obsidian-mcp-serverAI | 9/8/2026 | 12/8/2026 | A vulnerability was identified in bazylhorsey obsidian-mcp-server 1.0.0. This affects the function readCanvas/writeCanvas of the file src/services/CanvasService.ts. Such manipulation leads to path traversal. An attack has to be approached locally. The project was informed of the problem early through an issue report… | |
| Aplazada | Baja (1.9) | 0.17% | — | Aktsmm Skill-ninja-mcp-serverAI | 9/8/2026 | 12/8/2026 | A vulnerability has been found in aktsmm skill-ninja-mcp-server 0.1.0. Impacted is the function getInstalledSkills/installSkill/updateAgentsMd/uninstallSkill of the file src/installer.ts. The manipulation of the argument workspacePath leads to path traversal. The attack needs to be performed locally. Upgrading to… | |
| Aplazada | Baja (1.9) | 0.17% | — | Astralisone Rive-mcp-server-coreAI | 8/8/2026 | 12/8/2026 | A vulnerability has been found in astralisone rive-mcp-server-core up to db1d0cc4cd52589116360428b7504fd0ca748b3e. This affects an unknown part of the file packages/mcp-server/src/tools/importRiveFile.ts of the component importRiveFile Flow. Such manipulation of the argument libraryId leads to path traversal. The… | |
| Aplazada | Baja (1.9) | 1.2% | — | Kino-kafkaesque Ssh-mcp-serverAI | 6/8/2026 | 12/8/2026 | A vulnerability was detected in Kino-Kafkaesque ssh-mcp-server up to 8ebbbb99b26f80ff6162fe00957c6dec73fbc5a5. Impacted is the function ssh_exec of the file src/index.ts of the component SSH Command Handler. Performing a manipulation of the argument host/username results in command injection. The attack requires a… |