Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
MAL-2026-16422
  • npm/@httttt/mcp-npx-fetch-1
Malicious code in @httttt/mcp-npx-fetch-1 (npm) 11 hours ago
  • No fix available
MAL-2026-16409
  • npm/ubiquiti-agents-link-mcp
Malicious code in ubiquiti-agents-link-mcp (npm) 15 hours ago
  • No fix available
GHSA-798p-78g2-v556
  • npm/@aborruso/ckan-mcp-server
@aborruso/ckan-mcp-server has SSRF via DNS-name → internal IP — incomplete fix of CVE-2026-53509 20 hours ago
  • Fix available
  • Severity - 5.7 (Medium)
GHSA-jjhp-8crj-mppq
  • npm/@roomi-fields/notebooklm-mcp
@roomi-fields/notebooklm-mcp has a path traversal in vault.batch tool that allows arbitrary file write outside intended vault directory 20 hours ago
  • Fix available
  • Severity - 7.1 (High)
GHSA-cv3r-c5h8-f4g5
  • npm/@zereight/mcp-gitlab
@zereight/mcp-gitlab: Unauthenticated arbitrary file read via `upload_markdown` enables PAT exfiltration and full account takeover 6 days ago
  • Fix available
  • Severity - 9.8 (Critical)
GHSA-2h44-8472-frjj
  • npm/@zereight/mcp-gitlab
@zereight/mcp-gitlab Vulnerable to Server-Side Request Forgery 15 Sep
  • Fix available
  • Severity - 9.6 (Critical)
GHSA-vmp7-252j-cwp7
  • npm/@zereight/mcp-gitlab
@zereight/mcp-gitlab: DNS rebinding reaches local Streamable HTTP MCP transport 15 Sep
  • Fix available
  • Severity - 9.6 (Critical)
GHSA-5648-rgj9-v224
  • npm/@zereight/mcp-gitlab
@zereight/mcp-gitlab has multiple safety-control bypasses: execute_graphql read-only + allow-list bypass, unauthenticated transports, session-exhaustion DoS 15 Sep
  • Fix available
  • Severity - 8.1 (High)
GHSA-65h7-9wrw-629c
  • npm/@frontmcp/adapters
  • npm/frontmcp
  • npm/mcp-from-openapi
FrontMCP and mcp-from-openapi have bypass of OpenAPI external $ref SSRF fix 11 Sep
  • Fix available
  • Severity - 8.5 (High)
GHSA-wcjj-9m6g-2fr2
  • npm/functype-mcp-server
functype-mcp-server: MCP `set_functype_version` Package Alias RCE via Unsanitized pnpm install + Dynamic Import 09 Sep
  • Fix available
  • Severity - 7.8 (High)
MAL-2026-16061
  • npm/@yongot/canary-mcp-isolation
Malicious code in @yongot/canary-mcp-isolation (npm) 09 Sep
  • No fix available
MAL-2026-16062
  • npm/@yongot/canary-mcp-test
Malicious code in @yongot/canary-mcp-test (npm) 09 Sep
  • No fix available
MAL-2026-16032
  • npm/feishu-docx-mcp
Malicious code in feishu-docx-mcp (npm) 07 Sep
  • No fix available
MAL-2026-15869
  • npm/mcp-consultasdeveiculos-client
Malicious code in mcp-consultasdeveiculos-client (npm) 04 Sep
  • No fix available
GHSA-78x9-fhhx-v2g6
  • npm/@aborruso/ckan-mcp-server
CKAN MCP Server: Cache-key canonicalization collision enables cache confusion / poisoning 03 Sep
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-6f9w-9hf2-5rg3
  • npm/@aborruso/ckan-mcp-server
CKAN MCP Server: Information disclosure via verbose error reflection 03 Sep
  • Fix available
  • Severity - 3.7 (Low)