VulnWatch VulnWatch
← Back to dashboard
#

Agentic / MCP

435 entries

Every Agentic / MCP entry VulnWatch has indexed, sorted by publication date.

Subscribe to this tag's RSS feed

Medium github

PraisonAI: Coarse-Grained Tool Approval Cache Bypasses Per-Invocation Consent for Shell Commands

## Summary The approval system in PraisonAI Agents caches tool approval decisions by tool name only, not by invocation arguments. Once a user approves `execute_command` for any command (e.g., `ls -la...

Prompt Injection Agentic / MCP prompt injection llm agent openai llm
5.5
CVSS
3 months ago
High github

DNS Rebinding Protection Disabled by Default in Model Context Protocol Go SDK for Servers Running on Localhost

The Model Context Protocol (MCP) Go SDK does not enable DNS rebinding protection by default for HTTP-based servers. When an HTTP-based MCP server is run on localhost without authentication with `Strea...

Agentic / MCP model context protocol mcp server
8.1
CVSS
4 months ago
Critical github

nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover

### Summary The nginx-ui MCP (Model Context Protocol) integration exposes two HTTP endpoints: `/mcp` and `/mcp_message`. While `/mcp` requires both IP whitelisting and authentication (`AuthRequired()`...

Agentic / MCP model context protocol
9.8
CVSS
4 months ago
Critical github

Langflow has Authenticated Code Execution in Agentic Assistant Validation

## Description ### 1. Summary The Agentic Assistant feature in Langflow executes LLM-generated Python code during its **validation** phase. Although this phase appears intended to validate generated...

Agentic / MCP langflow agentic llm
0.0
CVSS
4 months ago
Medium github

SSRF in @aborruso/ckan-mcp-server via base_url allows access to internal networks

## Summary The `@aborruso/ckan-mcp-server` MCP server provides tools including `ckan_package_search` and `sparql_query` that accept a `base_url` parameter, making HTTP requests to arbitrary endpoints...

Prompt Injection SSRF Agentic / MCP prompt injection mcp server
5.7
CVSS
4 months ago
Medium github

AWS API MCP File Access Restriction Bypass

### Description The AWS API MCP Server is an open source Model Context Protocol (MCP) server that enables AI assistants to interact with AWS services and resources through AWS CLI commands. It provid...

Agentic / MCP model context protocol mcp server
5.5
CVSS
4 months ago
High github

Anthropic's MCP TypeScript SDK has a ReDoS vulnerability

### Impact A ReDoS vulnerability in the `UriTemplate` class allows attackers to cause denial of service. The `partToRegExp()` function generates a regex pattern with nested quantifiers (`([^/]+(?:,[^...

Agentic / MCP mcp server anthropic
0.0
CVSS
7 months ago
High github

Model Context Protocol (MCP) Python SDK does not enable DNS rebinding protection by default

### Description The Model Context Protocol (MCP) Python SDK does not enable DNS rebinding protection by default for HTTP-based servers. When an HTTP-based MCP server is run on localhost without authe...

Agentic / MCP model context protocol mcp server
0.0
CVSS
8 months ago