Technical writeups for vulnerabilities I've discovered, primarily in MCP (Model Context Protocol) server implementations. Each writeup includes root cause analysis, proof-of-concept code, and remediation guidance.
| CVE ID | Product | Severity | Type | Status |
|---|---|---|---|---|
| CVE-2026-47427 | github-mcp-server | Nil Pointer Dereference DoS | ✅ Fixed | |
| CVE-2026-6942 | radare2-mcp | RCE via Shell Escape | ✅ Fixed | |
| CVE-2026-42449 | n8n-mcp | SSRF via IPv6 Bypass | ✅ Fixed | |
| CVE-2026-35394 | mobile-mcp | Prompt Injection → Android Intent | ✅ Fixed |
MCP (Model Context Protocol) is Anthropic's open standard for connecting AI agents to external tools and data sources. As AI assistants gain access to filesystems, databases, and APIs through MCP servers, the attack surface expands dramatically.
Key findings from my research:
- 🔴 Trust boundary violations - MCP servers often trust client input without validation
- 🔴 Prompt injection via tools - Malicious content in files/data can manipulate AI behavior
- 🔴 Missing input sanitization - Shell escapes, path traversals, and SSRF are common
- 🔴 SDK-level vulnerabilities - Bugs in official SDKs affect all downstream servers
All vulnerabilities in this repo were discovered using mcpsec, an open-source security scanner I built for MCP server implementations.
# Install
pip install mcpsec
# Scan an MCP server
mcpsec scan --stdio "npx @modelcontextprotocol/server-filesystem /tmp"
# Fuzz for crashes
mcpsec fuzz --stdio "python my_server.py" --intensity high
# Static analysis
mcpsec audit --github https://github.com/org/mcp-serverwriteups/
├── README.md # This file
├── CVE-2026-47427/ # github-mcp-server DoS
│ ├── README.md # Full writeup
│ ├── poc.py # Proof of concept
│ └── images/ # Screenshots
├── CVE-2026-6942/ # radare2-mcp RCE
│ ├── README.md # Full writeup
│ ├── poc.py # Proof of concept
│ └── images/ # Screenshots
├── CVE-2026-42449/ # n8n-mcp SSRF
│ ├── README.md # Full writeup
│ ├── poc/ # PoC scripts
│ └── images/ # Screenshots
└── ...
I follow coordinated disclosure practices:
- Report - Contact maintainer via security advisory or private channel
- Collaborate - Work with maintainer on fix and timeline
- Publish - Release writeup after patch is available
All vulnerabilities listed here have been patched. Please update to the latest versions.
- mcpsec: github.com/manthanghasadiya/mcpsec
- LinkedIn: man-ghasadiya
- Twitter/X: @g_m_j_2703
- Medium: @manthan27ghasadiya
Found a bug in an MCP server? Try mcpsec