Skip to content
manthanghasadiyaPublic

About

No description, website, or topics provided.

Resources

Stars

1 star

Watchers

0 watching

Forks

Latest commit

 

History

17 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 

Repository files navigation

CVEs

Security Research & CVE Writeups

Technical writeups for vulnerabilities I've discovered, primarily in MCP (Model Context Protocol) server implementations. Each writeup includes root cause analysis, proof-of-concept code, and remediation guidance.


CVE Index

CVE ID Product Severity Type Status
CVE-2026-47427 github-mcp-server High Nil Pointer Dereference DoS ✅ Fixed
CVE-2026-6942 radare2-mcp Critical RCE via Shell Escape ✅ Fixed
CVE-2026-42449 n8n-mcp High SSRF via IPv6 Bypass ✅ Fixed
CVE-2026-35394 mobile-mcp High Prompt Injection → Android Intent ✅ Fixed

Research Focus: MCP Security

MCP (Model Context Protocol) is Anthropic's open standard for connecting AI agents to external tools and data sources. As AI assistants gain access to filesystems, databases, and APIs through MCP servers, the attack surface expands dramatically.

Key findings from my research:

  • 🔴 Trust boundary violations - MCP servers often trust client input without validation
  • 🔴 Prompt injection via tools - Malicious content in files/data can manipulate AI behavior
  • 🔴 Missing input sanitization - Shell escapes, path traversals, and SSRF are common
  • 🔴 SDK-level vulnerabilities - Bugs in official SDKs affect all downstream servers

Discovery Tool

All vulnerabilities in this repo were discovered using mcpsec, an open-source security scanner I built for MCP server implementations.

# Install
pip install mcpsec

# Scan an MCP server
mcpsec scan --stdio "npx @modelcontextprotocol/server-filesystem /tmp"

# Fuzz for crashes
mcpsec fuzz --stdio "python my_server.py" --intensity high

# Static analysis
mcpsec audit --github https://github.com/org/mcp-server

Repository Structure

writeups/
├── README.md                    # This file
├── CVE-2026-47427/             # github-mcp-server DoS
│   ├── README.md               # Full writeup
│   ├── poc.py                  # Proof of concept
│   └── images/                 # Screenshots
├── CVE-2026-6942/              # radare2-mcp RCE
│   ├── README.md               # Full writeup
│   ├── poc.py                  # Proof of concept
│   └── images/                 # Screenshots
├── CVE-2026-42449/             # n8n-mcp SSRF
│   ├── README.md               # Full writeup
│   ├── poc/                    # PoC scripts
│   └── images/                 # Screenshots
└── ...

Responsible Disclosure

I follow coordinated disclosure practices:

  1. Report - Contact maintainer via security advisory or private channel
  2. Collaborate - Work with maintainer on fix and timeline
  3. Publish - Release writeup after patch is available

All vulnerabilities listed here have been patched. Please update to the latest versions.


Links


Found a bug in an MCP server? Try mcpsec

About

No description, website, or topics provided.

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages