EEF-CVE-2026-88257

Source
https://cna.erlef.org/osv/EEF-CVE-2026-88257.html
Import Source
https://cna.erlef.org/osv/EEF-CVE-2026-88257.json
JSON Data
https://api.osv.dev/v1/vulns/EEF-CVE-2026-88257
Aliases
  • CVE-2026-88257
  • GHSA-mrg2-4747-fmpw
Published
2026-10-08T13:40:55Z
Modified
2026-10-08T14:15:02Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
beam_mcp: nested tool argument constraints advertised but not enforced
Details

Summary

Improper Input Validation vulnerability in BeamMCP.Schema in ScriptKittyOS beam_mcp allows an MCP client to reach a tool's dispatch function with arguments that violate the input schema the server advertised. BeamMCP.Schema.validate/2 checked type, required, additionalProperties, enum and numeric bounds on the top-level arguments object only. Constraints inside nested objects and on array items (items, minItems, maxItems, minLength, maxLength, pattern, nested required, enum and additionalProperties: false) were advertised by tools/list and never checked at tools/call or prompts/get, and keywords outside the enforced subset (oneOf, anyOf, $ref) were advertised and ignored.

A host whose dispatch code relies on the schema it declared receives values the schema forbids, such as an out-of-range number or an undeclared key inside a nested object. What the host does with such a value decides the impact.

This issue affects beam_mcp: from 0.1.0 before 0.10.1.

Details

1. Advertising. tools/list returns each tool's input_schema verbatim, including nested properties, items and constraint keywords.

2. Validation. BeamMCP.Schema.validate/2 in lib/beam_mcp/schema.ex walks only the first level: check_required/2 and check_additional/3 run on the top-level object, and check_properties/2 applies check_type, check_enum and check_range to each top-level value. A value of type object or array is accepted once its own type matches, and its contents are not visited. Keywords the validator does not know are ignored.

3. Dispatch. BeamMCP.Server.validate_and_dispatch/3 passes the accepted arguments to normalize_arguments/2 and then to the host's dispatch function, so an undeclared key inside a nested object, an out-of-range nested number, or an array item of the wrong type reaches host code that believed the schema excluded it. The same validator runs on prompts/get arguments. The fix in 0.10.1 enforces every keyword of the documented subset at every depth and refuses a schema that uses any other keyword when the catalog is loaded.

Proof of concept

  1. Declare a tool whose input_schema has a nested object property opts with "properties": {"level": {"type": "integer", "maximum": 3}}, "required": ["level"] and "additionalProperties": false, and an array property tags with "items": {"type": "string"} and "maxItems": 2.
  2. Send tools/call with "arguments": {"opts": {"level": 99, "extra": "x"}}.
  3. On beam_mcp 0.10.0 the dispatch function receives %{opts: %{"extra" => "x", "level" => 99}}. On 0.10.1 the call is refused with invalid arguments: unknown property: opts.extra.
  4. Send "arguments": {"tags": [1, 2, 3]}. On 0.10.0 the dispatch function receives tags: [1, 2, 3]. On 0.10.1 the call is refused with tags must have at most 2 items.

Impact

An MCP client can hand a host's tool values the host's declared schema forbids, such as an out-of-range number or an undeclared key inside a nested object. The consequence depends on what the host's dispatch code does with a value it never expected to receive.

Workarounds

Re-validate the arguments inside the host's dispatch function against every constraint the schema declares below the top level, or move each constraint to a top-level property, which the affected versions do enforce.

Database specific
{
    "capec_ids": [
        "CAPEC-153"
    ],
    "cpe_ids": [
        "cpe:2.3:a:scriptkittyos:beam_mcp:*:*:*:*:*:*:*:*"
    ],
    "cwe_ids": [
        "CWE-20"
    ]
}
References
Credits
    • Ayla Croft / Script Kitty OS - FINDER
    • Ayla Croft / Script Kitty OS - REPORTER
    • Ayla Croft / Script Kitty OS - REMEDIATION_DEVELOPER
    • Jonatan Männchen / EEF - COORDINATOR

Affected packages

Hex / beam_mcp

Package

Name
beam_mcp
Purl
pkg:hex/beam_mcp

Affected ranges

Type
SEMVER
Events
Introduced
0.1.0
Fixed
0.10.1

Affected versions

0.*
0.1.0
0.2.0
0.3.0
0.3.1
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.10.0

Database specific

source
"https://cna.erlef.org/osv/EEF-CVE-2026-88257.json"

Git / github.com/ScriptKittyOS/beam_mcp

Affected ranges

Type
GIT
Repo
https://github.com/ScriptKittyOS/beam_mcp
Events

Affected versions

v0.*
v0.1.0
v0.10.0
v0.2.0
v0.3.0
v0.3.1
v0.4.0
v0.5.0
v0.6.0
v0.7.0
v0.8.0
v0.9.0

Database specific

source
"https://cna.erlef.org/osv/EEF-CVE-2026-88257.json"