{
  "title": "MCP Security — Vulnerability and Advisory Timeline",
  "schemaVersion": "1.0",
  "researchFreeze": "2026-08-25",
  "protocolRevision": "2026-07-28",
  "temporalCoverage": "2025-06-13/2026-08-07",
  "displayOrder": "Chronological by disclosure date; packageRecordId preserves the supplied VULN046–VULN093 grouping order.",
  "caution": "This is a package-bounded advisory dataset, not a prevalence estimate or a count of universal protocol flaws. Every affected and fixed version is live-check required.",
  "count": 48,
  "records": [
    {
      "recordId": "R4-VULN046",
      "packageRecordId": "VULN046",
      "disclosureDate": "2025-06-13",
      "cve": "CVE-2025-49596",
      "advisory": "GHSA-7f8r-222p-6f5g",
      "component": "MCP Inspector",
      "affectedLayer": "Host/developer tool",
      "issueClass": "Remote code execution due to unauthenticated Inspector proxy",
      "affectedVersions": "<0.14.1",
      "patchedOrFixed": "0.14.1",
      "primaryUrl": "https://github.com/advisories/GHSA-7f8r-222p-6f5g",
      "packageSourceId": "SEC046",
      "sourceId": "S109",
      "protocolRelevance": "Implementation/ecosystem issue; not automatically a core-protocol flaw",
      "currentStatus": "LIVE-CHECK REQUIRED",
      "notes": "Affected/fixed ranges must be re-opened immediately before publication."
    },
    {
      "recordId": "R4-VULN048",
      "packageRecordId": "VULN048",
      "disclosureDate": "2025-07-04",
      "cve": "CVE-2025-53366",
      "advisory": "GHSA-3qhf-m339-9g5v",
      "component": "MCP Python SDK",
      "affectedLayer": "SDK",
      "issueClass": "Validation error amplification / denial of service",
      "affectedVersions": "<1.9.4",
      "patchedOrFixed": "1.9.4",
      "primaryUrl": "https://github.com/advisories/GHSA-3qhf-m339-9g5v",
      "packageSourceId": "SEC048",
      "sourceId": "S205",
      "protocolRelevance": "Implementation/ecosystem issue; not automatically a core-protocol flaw",
      "currentStatus": "LIVE-CHECK REQUIRED",
      "notes": "Affected/fixed ranges must be re-opened immediately before publication."
    },
    {
      "recordId": "R4-VULN049",
      "packageRecordId": "VULN049",
      "disclosureDate": "2025-07-04",
      "cve": "CVE-2025-53365",
      "advisory": "GHSA-j975-95f5-7wqh",
      "component": "MCP Python SDK",
      "affectedLayer": "SDK",
      "issueClass": "Closed-resource handling denial of service",
      "affectedVersions": "<1.10.0",
      "patchedOrFixed": "1.10.0",
      "primaryUrl": "https://github.com/advisories/GHSA-j975-95f5-7wqh",
      "packageSourceId": "SEC049",
      "sourceId": "S206",
      "protocolRelevance": "Implementation/ecosystem issue; not automatically a core-protocol flaw",
      "currentStatus": "LIVE-CHECK REQUIRED",
      "notes": "Affected/fixed ranges must be re-opened immediately before publication."
    },
    {
      "recordId": "R4-VULN089",
      "packageRecordId": "VULN089",
      "disclosureDate": "2025-07-09",
      "cve": "CVE-2025-6514",
      "advisory": "CVE-2025-6514",
      "component": "mcp-remote",
      "affectedLayer": "Launcher/supply chain",
      "issueClass": "Command injection in remote-server launcher",
      "affectedVersions": "LIVE-CHECK REQUIRED",
      "patchedOrFixed": "LIVE-CHECK REQUIRED",
      "primaryUrl": "https://nvd.nist.gov/vuln/detail/CVE-2025-6514",
      "packageSourceId": "SEC089",
      "sourceId": "S243",
      "protocolRelevance": "Implementation/ecosystem issue; not automatically a core-protocol flaw",
      "currentStatus": "LIVE-CHECK REQUIRED",
      "notes": "Affected/fixed ranges must be re-opened immediately before publication."
    },
    {
      "recordId": "R4-VULN067",
      "packageRecordId": "VULN067",
      "disclosureDate": "2025-08-29",
      "cve": "CVE-2025-9611",
      "advisory": "GHSA-6fg3-hvw7-2fwq",
      "component": "Microsoft Playwright MCP",
      "affectedLayer": "Server/transport",
      "issueClass": "DNS rebinding against localhost HTTP mode",
      "affectedVersions": "<0.0.40",
      "patchedOrFixed": "0.0.40",
      "primaryUrl": "https://github.com/advisories/GHSA-6fg3-hvw7-2fwq",
      "packageSourceId": "SEC067",
      "sourceId": "S221",
      "protocolRelevance": "Implementation/ecosystem issue; not automatically a core-protocol flaw",
      "currentStatus": "LIVE-CHECK REQUIRED",
      "notes": "Affected/fixed ranges must be re-opened immediately before publication."
    },
    {
      "recordId": "R4-VULN047",
      "packageRecordId": "VULN047",
      "disclosureDate": "2025-09-05",
      "cve": "CVE-2025-58444",
      "advisory": "GHSA-g9hg-qhmf-q45m",
      "component": "MCP Inspector",
      "affectedLayer": "Host/developer tool",
      "issueClass": "Cross-site scripting in Inspector",
      "affectedVersions": "<0.16.6",
      "patchedOrFixed": "0.16.6",
      "primaryUrl": "https://github.com/advisories/GHSA-g9hg-qhmf-q45m",
      "packageSourceId": "SEC047",
      "sourceId": "S110",
      "protocolRelevance": "Implementation/ecosystem issue; not automatically a core-protocol flaw",
      "currentStatus": "LIVE-CHECK REQUIRED",
      "notes": "Affected/fixed ranges must be re-opened immediately before publication."
    },
    {
      "recordId": "R4-VULN091",
      "packageRecordId": "VULN091",
      "disclosureDate": "2025-09-17",
      "cve": "CVE-2025-64109",
      "advisory": "CVE-2025-64109",
      "component": "Cursor",
      "affectedLayer": "Host/project config",
      "issueClass": "Malicious project MCP configuration can trigger code execution",
      "affectedVersions": "Before 2025.09.17-25b418f",
      "patchedOrFixed": "2025.09.17-25b418f",
      "primaryUrl": "https://nvd.nist.gov/vuln/detail/CVE-2025-64109",
      "packageSourceId": "SEC091",
      "sourceId": "S245",
      "protocolRelevance": "Implementation/ecosystem issue; not automatically a core-protocol flaw",
      "currentStatus": "LIVE-CHECK REQUIRED",
      "notes": "Affected/fixed ranges must be re-opened immediately before publication."
    },
    {
      "recordId": "R4-VULN061",
      "packageRecordId": "VULN061",
      "disclosureDate": "2025-10-16",
      "cve": "CVE-2025-68143",
      "advisory": "GHSA-5cgr-j3jf-jw3v",
      "component": "MCP reference Git server",
      "affectedLayer": "Server implementation",
      "issueClass": "Repository path validation weakness",
      "affectedVersions": "<2025.9.25",
      "patchedOrFixed": "2025.9.25 / server removed",
      "primaryUrl": "https://github.com/advisories/GHSA-5cgr-j3jf-jw3v",
      "packageSourceId": "SEC061",
      "sourceId": "S215",
      "protocolRelevance": "Implementation/ecosystem issue; not automatically a core-protocol flaw",
      "currentStatus": "LIVE-CHECK REQUIRED",
      "notes": "Affected/fixed ranges must be re-opened immediately before publication."
    },
    {
      "recordId": "R4-VULN050",
      "packageRecordId": "VULN050",
      "disclosureDate": "2025-12-02",
      "cve": "CVE-2025-66414",
      "advisory": "GHSA-w48q-cv73-mx4w",
      "component": "MCP TypeScript SDK",
      "affectedLayer": "SDK/transport",
      "issueClass": "DNS rebinding protection disabled by default for unauthenticated localhost HTTP servers",
      "affectedVersions": "<1.24.0",
      "patchedOrFixed": "1.24.0",
      "primaryUrl": "https://github.com/advisories/GHSA-w48q-cv73-mx4w",
      "packageSourceId": "SEC050",
      "sourceId": "S111",
      "protocolRelevance": "Implementation/ecosystem issue; not automatically a core-protocol flaw",
      "currentStatus": "LIVE-CHECK REQUIRED",
      "notes": "Affected/fixed ranges must be re-opened immediately before publication."
    },
    {
      "recordId": "R4-VULN051",
      "packageRecordId": "VULN051",
      "disclosureDate": "2025-12-02",
      "cve": "CVE-2025-66416",
      "advisory": "GHSA-9h52-p55h-vw2f",
      "component": "MCP Python SDK",
      "affectedLayer": "SDK/transport",
      "issueClass": "DNS rebinding protection disabled by default for localhost HTTP servers",
      "affectedVersions": "<1.23.0",
      "patchedOrFixed": "1.23.0",
      "primaryUrl": "https://github.com/advisories/GHSA-9h52-p55h-vw2f",
      "packageSourceId": "SEC051",
      "sourceId": "S112",
      "protocolRelevance": "Implementation/ecosystem issue; not automatically a core-protocol flaw",
      "currentStatus": "LIVE-CHECK REQUIRED",
      "notes": "Affected/fixed ranges must be re-opened immediately before publication."
    },
    {
      "recordId": "R4-VULN092",
      "packageRecordId": "VULN092",
      "disclosureDate": "2025-12-19",
      "cve": "CVE-2025-68433",
      "advisory": "CVE-2025-68433",
      "component": "Zed",
      "affectedLayer": "Host/project config",
      "issueClass": "Malicious project MCP configuration can trigger code execution",
      "affectedVersions": "<0.218.2-pre",
      "patchedOrFixed": "0.218.2-pre",
      "primaryUrl": "https://nvd.nist.gov/vuln/detail/CVE-2025-68433",
      "packageSourceId": "SEC092",
      "sourceId": "S246",
      "protocolRelevance": "Implementation/ecosystem issue; not automatically a core-protocol flaw",
      "currentStatus": "LIVE-CHECK REQUIRED",
      "notes": "Affected/fixed ranges must be re-opened immediately before publication."
    },
    {
      "recordId": "R4-VULN059",
      "packageRecordId": "VULN059",
      "disclosureDate": "2026-01-08",
      "cve": "CVE-2026-0621",
      "advisory": "GHSA-cqwc-fm46-7fff",
      "component": "MCP TypeScript SDK",
      "affectedLayer": "SDK/parser",
      "issueClass": "UriTemplate regular-expression denial of service",
      "affectedVersions": "<1.25.2",
      "patchedOrFixed": "1.25.2",
      "primaryUrl": "https://github.com/advisories/GHSA-cqwc-fm46-7fff",
      "packageSourceId": "SEC059",
      "sourceId": "S214",
      "protocolRelevance": "Implementation/ecosystem issue; not automatically a core-protocol flaw",
      "currentStatus": "LIVE-CHECK REQUIRED",
      "notes": "Affected/fixed ranges must be re-opened immediately before publication."
    },
    {
      "recordId": "R4-VULN077",
      "packageRecordId": "VULN077",
      "disclosureDate": "2026-01-15",
      "cve": "CVE-2026-11529",
      "advisory": "GHSA-mvq4-39wx-6h5g",
      "component": "MySQL MCP Server",
      "affectedLayer": "Server implementation",
      "issueClass": "SQL injection through insufficient input handling",
      "affectedVersions": "<0.3.0",
      "patchedOrFixed": "0.3.0",
      "primaryUrl": "https://github.com/advisories/GHSA-mvq4-39wx-6h5g",
      "packageSourceId": "SEC077",
      "sourceId": "S231",
      "protocolRelevance": "Implementation/ecosystem issue; not automatically a core-protocol flaw",
      "currentStatus": "LIVE-CHECK REQUIRED",
      "notes": "Affected/fixed ranges must be re-opened immediately before publication."
    },
    {
      "recordId": "R4-VULN070",
      "packageRecordId": "VULN070",
      "disclosureDate": "2026-01-16",
      "cve": "CVE-2026-23744",
      "advisory": "GHSA-232v-j27c-5pp6",
      "component": "MCPJam Inspector",
      "affectedLayer": "Host/developer tool",
      "issueClass": "Remote command execution",
      "affectedVersions": "<=1.4.2",
      "patchedOrFixed": "1.4.3",
      "primaryUrl": "https://github.com/advisories/GHSA-232v-j27c-5pp6",
      "packageSourceId": "SEC070",
      "sourceId": "S224",
      "protocolRelevance": "Implementation/ecosystem issue; not automatically a core-protocol flaw",
      "currentStatus": "LIVE-CHECK REQUIRED",
      "notes": "Affected/fixed ranges must be re-opened immediately before publication."
    },
    {
      "recordId": "R4-VULN090",
      "packageRecordId": "VULN090",
      "disclosureDate": "2026-01-23",
      "cve": "",
      "advisory": "MALICIOUS-PACKAGE",
      "component": "Postmark MCP impersonator",
      "affectedLayer": "Supply chain",
      "issueClass": "Malicious npm package impersonating an official server and exfiltrating API keys",
      "affectedVersions": ">=1.0.16 malicious series",
      "patchedOrFixed": "Remove package; use verified vendor source",
      "primaryUrl": "https://snyk.io/blog/postmark-mcp-server-backdoor/",
      "packageSourceId": "SEC090",
      "sourceId": "S244",
      "protocolRelevance": "Implementation/ecosystem issue; not automatically a core-protocol flaw",
      "currentStatus": "LIVE-CHECK REQUIRED",
      "notes": "Affected/fixed ranges must be re-opened immediately before publication."
    },
    {
      "recordId": "R4-VULN060",
      "packageRecordId": "VULN060",
      "disclosureDate": "2026-02-06",
      "cve": "CVE-2026-25536",
      "advisory": "GHSA-345p-7cg4-v4c7",
      "component": "MCP TypeScript SDK",
      "affectedLayer": "SDK/multi-tenancy",
      "issueClass": "Cross-client response data leakage when server/transport instances are reused",
      "affectedVersions": "1.10.0–1.25.3",
      "patchedOrFixed": "1.26.0",
      "primaryUrl": "https://github.com/advisories/GHSA-345p-7cg4-v4c7",
      "packageSourceId": "SEC060",
      "sourceId": "S147",
      "protocolRelevance": "Implementation/ecosystem issue; not automatically a core-protocol flaw",
      "currentStatus": "LIVE-CHECK REQUIRED",
      "notes": "Affected/fixed ranges must be re-opened immediately before publication."
    },
    {
      "recordId": "R4-VULN052",
      "packageRecordId": "VULN052",
      "disclosureDate": "2026-02-20",
      "cve": "CVE-2026-34742",
      "advisory": "GHSA-xw59-hvm2-8pj6",
      "component": "MCP Go SDK",
      "affectedLayer": "SDK/transport",
      "issueClass": "DNS rebinding protection gap for localhost HTTP servers",
      "affectedVersions": "<1.4.0",
      "patchedOrFixed": "1.4.0",
      "primaryUrl": "https://github.com/advisories/GHSA-xw59-hvm2-8pj6",
      "packageSourceId": "SEC052",
      "sourceId": "S207",
      "protocolRelevance": "Implementation/ecosystem issue; not automatically a core-protocol flaw",
      "currentStatus": "LIVE-CHECK REQUIRED",
      "notes": "Affected/fixed ranges must be re-opened immediately before publication."
    },
    {
      "recordId": "R4-VULN053",
      "packageRecordId": "VULN053",
      "disclosureDate": "2026-02-26",
      "cve": "CVE-2026-35568",
      "advisory": "GHSA-8jxr-pr72-r468",
      "component": "MCP Java SDK",
      "affectedLayer": "SDK/transport",
      "issueClass": "DNS rebinding protection gap for localhost HTTP servers",
      "affectedVersions": "<1.0.0",
      "patchedOrFixed": "1.0.0",
      "primaryUrl": "https://github.com/advisories/GHSA-8jxr-pr72-r468",
      "packageSourceId": "SEC053",
      "sourceId": "S208",
      "protocolRelevance": "Implementation/ecosystem issue; not automatically a core-protocol flaw",
      "currentStatus": "LIVE-CHECK REQUIRED",
      "notes": "Affected/fixed ranges must be re-opened immediately before publication."
    },
    {
      "recordId": "R4-VULN069",
      "packageRecordId": "VULN069",
      "disclosureDate": "2026-03-03",
      "cve": "",
      "advisory": "GHSA-jwj7-74jh-p5c4",
      "component": "CircleCI MCP Server",
      "affectedLayer": "Server/transport",
      "issueClass": "DNS rebinding protection weakness",
      "affectedVersions": "<0.17.0",
      "patchedOrFixed": "0.17.0",
      "primaryUrl": "https://github.com/advisories/GHSA-jwj7-74jh-p5c4",
      "packageSourceId": "SEC069",
      "sourceId": "S223",
      "protocolRelevance": "Implementation/ecosystem issue; not automatically a core-protocol flaw",
      "currentStatus": "LIVE-CHECK REQUIRED",
      "notes": "Affected/fixed ranges must be re-opened immediately before publication."
    },
    {
      "recordId": "R4-VULN088",
      "packageRecordId": "VULN088",
      "disclosureDate": "2026-03-15",
      "cve": "CVE-2026-33032",
      "advisory": "CVE-2026-33032",
      "component": "Nginx UI MCP integration",
      "affectedLayer": "Server/product integration",
      "issueClass": "Unauthenticated MCP endpoint enabling administrative takeover",
      "affectedVersions": "<=2.3.3 reported",
      "patchedOrFixed": "2.3.4 reported",
      "primaryUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-33032",
      "packageSourceId": "SEC088",
      "sourceId": "S242",
      "protocolRelevance": "Implementation/ecosystem issue; not automatically a core-protocol flaw",
      "currentStatus": "LIVE-CHECK REQUIRED",
      "notes": "Affected/fixed ranges must be re-opened immediately before publication."
    },
    {
      "recordId": "R4-VULN081",
      "packageRecordId": "VULN081",
      "disclosureDate": "2026-03-24",
      "cve": "CVE-2026-31944",
      "advisory": "GHSA-vf7j-7mrx-hp7g",
      "component": "LibreChat",
      "affectedLayer": "Host/auth",
      "issueClass": "OAuth callback binding/account-linking weakness",
      "affectedVersions": "LIVE-CHECK REQUIRED",
      "patchedOrFixed": "0.8.3-rc1 reported",
      "primaryUrl": "https://github.com/advisories/GHSA-vf7j-7mrx-hp7g",
      "packageSourceId": "SEC081",
      "sourceId": "S235",
      "protocolRelevance": "Implementation/ecosystem issue; not automatically a core-protocol flaw",
      "currentStatus": "LIVE-CHECK REQUIRED",
      "notes": "Affected/fixed ranges must be re-opened immediately before publication."
    },
    {
      "recordId": "R4-VULN082",
      "packageRecordId": "VULN082",
      "disclosureDate": "2026-03-26",
      "cve": "CVE-2026-32625",
      "advisory": "GHSA-4pcc-j6m6-wcwx",
      "component": "LibreChat",
      "affectedLayer": "Host/configuration",
      "issueClass": "Environment-expanded MCP URL can expose secrets",
      "affectedVersions": "<=0.8.3",
      "patchedOrFixed": "0.8.4-rc1 reported",
      "primaryUrl": "https://github.com/advisories/GHSA-4pcc-j6m6-wcwx",
      "packageSourceId": "SEC082",
      "sourceId": "S236",
      "protocolRelevance": "Implementation/ecosystem issue; not automatically a core-protocol flaw",
      "currentStatus": "LIVE-CHECK REQUIRED",
      "notes": "Affected/fixed ranges must be re-opened immediately before publication."
    },
    {
      "recordId": "R4-VULN083",
      "packageRecordId": "VULN083",
      "disclosureDate": "2026-03-26",
      "cve": "",
      "advisory": "GHSA-pmw7-gqwj-f954",
      "component": "LibreChat",
      "affectedLayer": "Host/auth",
      "issueClass": "Attacker-controlled headers can expose tokens",
      "affectedVersions": ">=0.8.2-rc1,<=0.8.3-rc1",
      "patchedOrFixed": ">=0.8.3-rc2",
      "primaryUrl": "https://github.com/advisories/GHSA-pmw7-gqwj-f954",
      "packageSourceId": "SEC083",
      "sourceId": "S237",
      "protocolRelevance": "Implementation/ecosystem issue; not automatically a core-protocol flaw",
      "currentStatus": "LIVE-CHECK REQUIRED",
      "notes": "Affected/fixed ranges must be re-opened immediately before publication."
    },
    {
      "recordId": "R4-VULN084",
      "packageRecordId": "VULN084",
      "disclosureDate": "2026-04-01",
      "cve": "CVE-2026-40159",
      "advisory": "CVE-2026-40159",
      "component": "PraisonAI",
      "affectedLayer": "Host/local process",
      "issueClass": "Environment variables inherited by local MCP processes",
      "affectedVersions": "<4.5.128",
      "patchedOrFixed": "4.5.128",
      "primaryUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-40159",
      "packageSourceId": "SEC084",
      "sourceId": "S238",
      "protocolRelevance": "Implementation/ecosystem issue; not automatically a core-protocol flaw",
      "currentStatus": "LIVE-CHECK REQUIRED",
      "notes": "Affected/fixed ranges must be re-opened immediately before publication."
    },
    {
      "recordId": "R4-VULN071",
      "packageRecordId": "VULN071",
      "disclosureDate": "2026-04-03",
      "cve": "CVE-2026-27124",
      "advisory": "GHSA-rww4-4w9c-7733",
      "component": "FastMCP",
      "affectedLayer": "Framework/auth",
      "issueClass": "OAuth proxy callback missing consent binding; confused deputy",
      "affectedVersions": "<3.2.0",
      "patchedOrFixed": "3.2.0",
      "primaryUrl": "https://github.com/advisories/GHSA-rww4-4w9c-7733",
      "packageSourceId": "SEC071",
      "sourceId": "S225",
      "protocolRelevance": "Implementation/ecosystem issue; not automatically a core-protocol flaw",
      "currentStatus": "LIVE-CHECK REQUIRED",
      "notes": "Affected/fixed ranges must be re-opened immediately before publication."
    },
    {
      "recordId": "R4-VULN085",
      "packageRecordId": "VULN085",
      "disclosureDate": "2026-04-10",
      "cve": "CVE-2026-41497",
      "advisory": "GHSA-9qhq-v63v-fv3j",
      "component": "PraisonAI",
      "affectedLayer": "Host/local process",
      "issueClass": "Unsafe command parsing for MCP server configuration",
      "affectedVersions": "<=4.5.148",
      "patchedOrFixed": "Patched after 4.5.148",
      "primaryUrl": "https://github.com/advisories/GHSA-9qhq-v63v-fv3j",
      "packageSourceId": "SEC085",
      "sourceId": "S239",
      "protocolRelevance": "Implementation/ecosystem issue; not automatically a core-protocol flaw",
      "currentStatus": "LIVE-CHECK REQUIRED",
      "notes": "Affected/fixed ranges must be re-opened immediately before publication."
    },
    {
      "recordId": "R4-VULN054",
      "packageRecordId": "VULN054",
      "disclosureDate": "2026-04-14",
      "cve": "CVE-2026-42559",
      "advisory": "GHSA-89vp-x53w-74fx",
      "component": "MCP Rust SDK",
      "affectedLayer": "SDK/transport",
      "issueClass": "DNS rebinding protection gap",
      "affectedVersions": "<1.4.0",
      "patchedOrFixed": "1.4.0",
      "primaryUrl": "https://github.com/advisories/GHSA-89vp-x53w-74fx",
      "packageSourceId": "SEC054",
      "sourceId": "S209",
      "protocolRelevance": "Implementation/ecosystem issue; not automatically a core-protocol flaw",
      "currentStatus": "LIVE-CHECK REQUIRED",
      "notes": "Affected/fixed ranges must be re-opened immediately before publication."
    },
    {
      "recordId": "R4-VULN073",
      "packageRecordId": "VULN073",
      "disclosureDate": "2026-04-20",
      "cve": "CVE-2026-47427",
      "advisory": "GHSA-w4q6-qw23-4rg7",
      "component": "GitHub MCP Server",
      "affectedLayer": "Server implementation",
      "issueClass": "Nil-pointer denial of service",
      "affectedVersions": "<1.1.0",
      "patchedOrFixed": "1.1.0",
      "primaryUrl": "https://github.com/advisories/GHSA-w4q6-qw23-4rg7",
      "packageSourceId": "SEC073",
      "sourceId": "S227",
      "protocolRelevance": "Implementation/ecosystem issue; not automatically a core-protocol flaw",
      "currentStatus": "LIVE-CHECK REQUIRED",
      "notes": "Affected/fixed ranges must be re-opened immediately before publication."
    },
    {
      "recordId": "R4-VULN093",
      "packageRecordId": "VULN093",
      "disclosureDate": "2026-04-22",
      "cve": "CVE-2026-44118",
      "advisory": "GHSA-r6xh-pqhr-v4xh",
      "component": "OpenClaw",
      "affectedLayer": "Host/identity",
      "issueClass": "Owner identity spoofing in MCP-connected workflow",
      "affectedVersions": "<=2026.4.21",
      "patchedOrFixed": "2026.4.22",
      "primaryUrl": "https://github.com/advisories/GHSA-r6xh-pqhr-v4xh",
      "packageSourceId": "SEC093",
      "sourceId": "S247",
      "protocolRelevance": "Implementation/ecosystem issue; not automatically a core-protocol flaw",
      "currentStatus": "LIVE-CHECK REQUIRED",
      "notes": "Affected/fixed ranges must be re-opened immediately before publication."
    },
    {
      "recordId": "R4-VULN062",
      "packageRecordId": "VULN062",
      "disclosureDate": "2026-04-29",
      "cve": "CVE-2026-44430",
      "advisory": "GHSA-r48c-v28r-pf6v",
      "component": "Official MCP Registry",
      "affectedLayer": "Registry",
      "issueClass": "Server-side request forgery in registry processing",
      "affectedVersions": "<1.7.7",
      "patchedOrFixed": "1.7.7",
      "primaryUrl": "https://github.com/advisories/GHSA-r48c-v28r-pf6v",
      "packageSourceId": "SEC062",
      "sourceId": "S216",
      "protocolRelevance": "Implementation/ecosystem issue; not automatically a core-protocol flaw",
      "currentStatus": "LIVE-CHECK REQUIRED",
      "notes": "Affected/fixed ranges must be re-opened immediately before publication."
    },
    {
      "recordId": "R4-VULN063",
      "packageRecordId": "VULN063",
      "disclosureDate": "2026-04-29",
      "cve": "CVE-2026-44428",
      "advisory": "GHSA-95c3-6vvw-4mrq",
      "component": "Official MCP Registry",
      "affectedLayer": "Registry/auth",
      "issueClass": "OIDC token replay / validation flaw",
      "affectedVersions": "<1.7.6",
      "patchedOrFixed": "1.7.6",
      "primaryUrl": "https://github.com/advisories/GHSA-95c3-6vvw-4mrq",
      "packageSourceId": "SEC063",
      "sourceId": "S217",
      "protocolRelevance": "Implementation/ecosystem issue; not automatically a core-protocol flaw",
      "currentStatus": "LIVE-CHECK REQUIRED",
      "notes": "Affected/fixed ranges must be re-opened immediately before publication."
    },
    {
      "recordId": "R4-VULN064",
      "packageRecordId": "VULN064",
      "disclosureDate": "2026-04-29",
      "cve": "CVE-2026-44427",
      "advisory": "GHSA-v8vw-gw5j-w7m6",
      "component": "Official MCP Registry",
      "affectedLayer": "Registry/web",
      "issueClass": "Open redirect",
      "affectedVersions": ">=1.1.0,<1.7.5",
      "patchedOrFixed": "1.7.5",
      "primaryUrl": "https://github.com/advisories/GHSA-v8vw-gw5j-w7m6",
      "packageSourceId": "SEC064",
      "sourceId": "S218",
      "protocolRelevance": "Implementation/ecosystem issue; not automatically a core-protocol flaw",
      "currentStatus": "LIVE-CHECK REQUIRED",
      "notes": "Affected/fixed ranges must be re-opened immediately before publication."
    },
    {
      "recordId": "R4-VULN065",
      "packageRecordId": "VULN065",
      "disclosureDate": "2026-05-01",
      "cve": "",
      "advisory": "GHSA-rqv2-m695-f8j4",
      "component": "Official MCP Registry",
      "affectedLayer": "Registry/web",
      "issueClass": "Stored cross-site scripting",
      "affectedVersions": "LIVE-CHECK REQUIRED",
      "patchedOrFixed": "LIVE-CHECK REQUIRED",
      "primaryUrl": "https://github.com/advisories/GHSA-rqv2-m695-f8j4",
      "packageSourceId": "SEC065",
      "sourceId": "S219",
      "protocolRelevance": "Implementation/ecosystem issue; not automatically a core-protocol flaw",
      "currentStatus": "LIVE-CHECK REQUIRED",
      "notes": "Affected/fixed ranges must be re-opened immediately before publication."
    },
    {
      "recordId": "R4-VULN066",
      "packageRecordId": "VULN066",
      "disclosureDate": "2026-05-01",
      "cve": "",
      "advisory": "GHSA-2v5f-5r6w-p67r",
      "component": "Official MCP Registry",
      "affectedLayer": "Registry/supply chain",
      "issueClass": "OCI verification fail-open behavior",
      "affectedVersions": "<1.7.9",
      "patchedOrFixed": "1.7.9",
      "primaryUrl": "https://github.com/advisories/GHSA-2v5f-5r6w-p67r",
      "packageSourceId": "SEC066",
      "sourceId": "S220",
      "protocolRelevance": "Implementation/ecosystem issue; not automatically a core-protocol flaw",
      "currentStatus": "LIVE-CHECK REQUIRED",
      "notes": "Affected/fixed ranges must be re-opened immediately before publication."
    },
    {
      "recordId": "R4-VULN075",
      "packageRecordId": "VULN075",
      "disclosureDate": "2026-05-04",
      "cve": "CVE-2026-46519",
      "advisory": "GHSA-cr22-wjx7-2w6m",
      "component": "Kubernetes MCP Server",
      "affectedLayer": "Server/authorization",
      "issueClass": "Presentation-only authorization without server-side enforcement",
      "affectedVersions": "<3.6.0",
      "patchedOrFixed": "3.6.0",
      "primaryUrl": "https://github.com/advisories/GHSA-cr22-wjx7-2w6m",
      "packageSourceId": "SEC075",
      "sourceId": "S229",
      "protocolRelevance": "Implementation/ecosystem issue; not automatically a core-protocol flaw",
      "currentStatus": "LIVE-CHECK REQUIRED",
      "notes": "Affected/fixed ranges must be re-opened immediately before publication."
    },
    {
      "recordId": "R4-VULN079",
      "packageRecordId": "VULN079",
      "disclosureDate": "2026-05-09",
      "cve": "CVE-2026-47751",
      "advisory": "GHSA-8q5r-mmjf-575q",
      "component": "Claude Code Action",
      "affectedLayer": "Host/project config",
      "issueClass": "Malicious repository .mcp.json can execute configured server code",
      "affectedVersions": "<1.0.74",
      "patchedOrFixed": "1.0.74",
      "primaryUrl": "https://github.com/advisories/GHSA-8q5r-mmjf-575q",
      "packageSourceId": "SEC079",
      "sourceId": "S233",
      "protocolRelevance": "Implementation/ecosystem issue; not automatically a core-protocol flaw",
      "currentStatus": "LIVE-CHECK REQUIRED",
      "notes": "Affected/fixed ranges must be re-opened immediately before publication."
    },
    {
      "recordId": "R4-VULN087",
      "packageRecordId": "VULN087",
      "disclosureDate": "2026-05-12",
      "cve": "CVE-2026-47394",
      "advisory": "GHSA-9cr9-25q5-8prj",
      "component": "PraisonAI",
      "affectedLayer": "Host/server",
      "issueClass": "Arbitrary local file read through MCP integration",
      "affectedVersions": "<=4.6.39",
      "patchedOrFixed": "4.6.40",
      "primaryUrl": "https://github.com/advisories/GHSA-9cr9-25q5-8prj",
      "packageSourceId": "SEC087",
      "sourceId": "S241",
      "protocolRelevance": "Implementation/ecosystem issue; not automatically a core-protocol flaw",
      "currentStatus": "LIVE-CHECK REQUIRED",
      "notes": "Affected/fixed ranges must be re-opened immediately before publication."
    },
    {
      "recordId": "R4-VULN074",
      "packageRecordId": "VULN074",
      "disclosureDate": "2026-05-16",
      "cve": "CVE-2026-48529",
      "advisory": "GHSA-pjp5-fpmr-3349",
      "component": "GitHub MCP Server",
      "affectedLayer": "Server/authorization",
      "issueClass": "Lockdown mode cross-user authorization separation flaw",
      "affectedVersions": ">=0.22.0,<1.1.2",
      "patchedOrFixed": "1.1.2",
      "primaryUrl": "https://github.com/advisories/GHSA-pjp5-fpmr-3349",
      "packageSourceId": "SEC074",
      "sourceId": "S228",
      "protocolRelevance": "Implementation/ecosystem issue; not automatically a core-protocol flaw",
      "currentStatus": "LIVE-CHECK REQUIRED",
      "notes": "Affected/fixed ranges must be re-opened immediately before publication."
    },
    {
      "recordId": "R4-VULN072",
      "packageRecordId": "VULN072",
      "disclosureDate": "2026-05-20",
      "cve": "CVE-2026-49257",
      "advisory": "GHSA-73cv-556c-w3g6",
      "component": "mcp-pinot",
      "affectedLayer": "Server/deployment",
      "issueClass": "Network service bound broadly without authentication",
      "affectedVersions": "<=3.0.1",
      "patchedOrFixed": "3.1.0",
      "primaryUrl": "https://github.com/advisories/GHSA-73cv-556c-w3g6",
      "packageSourceId": "SEC072",
      "sourceId": "S226",
      "protocolRelevance": "Implementation/ecosystem issue; not automatically a core-protocol flaw",
      "currentStatus": "LIVE-CHECK REQUIRED",
      "notes": "Affected/fixed ranges must be re-opened immediately before publication."
    },
    {
      "recordId": "R4-VULN078",
      "packageRecordId": "VULN078",
      "disclosureDate": "2026-05-22",
      "cve": "CVE-2026-5059",
      "advisory": "GHSA-fgmx-xfp3-w28p",
      "component": "aws-mcp",
      "affectedLayer": "Server implementation",
      "issueClass": "Command injection",
      "affectedVersions": "<=1.7.0",
      "patchedOrFixed": "No patch listed when recorded",
      "primaryUrl": "https://github.com/advisories/GHSA-fgmx-xfp3-w28p",
      "packageSourceId": "SEC078",
      "sourceId": "S232",
      "protocolRelevance": "Implementation/ecosystem issue; not automatically a core-protocol flaw",
      "currentStatus": "LIVE-CHECK REQUIRED",
      "notes": "Affected/fixed ranges must be re-opened immediately before publication."
    },
    {
      "recordId": "R4-VULN080",
      "packageRecordId": "VULN080",
      "disclosureDate": "2026-05-25",
      "cve": "CVE-2026-50143",
      "advisory": "GHSA-6gr2-qh89-hxwm",
      "component": "Apify MCP Server",
      "affectedLayer": "Server/authorization",
      "issueClass": "Path/token authorization weakness",
      "affectedVersions": "<0.10.11",
      "patchedOrFixed": "0.10.11",
      "primaryUrl": "https://github.com/advisories/GHSA-6gr2-qh89-hxwm",
      "packageSourceId": "SEC080",
      "sourceId": "S234",
      "protocolRelevance": "Implementation/ecosystem issue; not automatically a core-protocol flaw",
      "currentStatus": "LIVE-CHECK REQUIRED",
      "notes": "Affected/fixed ranges must be re-opened immediately before publication."
    },
    {
      "recordId": "R4-VULN076",
      "packageRecordId": "VULN076",
      "disclosureDate": "2026-05-29",
      "cve": "CVE-2026-55786",
      "advisory": "GHSA-h9f9-h6gm-wc85",
      "component": "flyto-core",
      "affectedLayer": "Server implementation",
      "issueClass": "Unauthenticated command execution through MCP capability",
      "affectedVersions": ">=2.26.2,<2.26.4",
      "patchedOrFixed": "2.26.4",
      "primaryUrl": "https://github.com/advisories/GHSA-h9f9-h6gm-wc85",
      "packageSourceId": "SEC076",
      "sourceId": "S230",
      "protocolRelevance": "Implementation/ecosystem issue; not automatically a core-protocol flaw",
      "currentStatus": "LIVE-CHECK REQUIRED",
      "notes": "Affected/fixed ranges must be re-opened immediately before publication."
    },
    {
      "recordId": "R4-VULN086",
      "packageRecordId": "VULN086",
      "disclosureDate": "2026-06-01",
      "cve": "CVE-2026-57124",
      "advisory": "GHSA-p75f-6fp4-p57w",
      "component": "PraisonAI",
      "affectedLayer": "Host/network",
      "issueClass": "Unauthenticated remote MCP connect path",
      "affectedVersions": "<=4.6.48",
      "patchedOrFixed": "4.6.59",
      "primaryUrl": "https://github.com/advisories/GHSA-p75f-6fp4-p57w",
      "packageSourceId": "SEC086",
      "sourceId": "S240",
      "protocolRelevance": "Implementation/ecosystem issue; not automatically a core-protocol flaw",
      "currentStatus": "LIVE-CHECK REQUIRED",
      "notes": "Affected/fixed ranges must be re-opened immediately before publication."
    },
    {
      "recordId": "R4-VULN055",
      "packageRecordId": "VULN055",
      "disclosureDate": "2026-06-08",
      "cve": "CVE-2026-63118",
      "advisory": "GHSA-rjr6-rcgv-9m7m",
      "component": "MCP Ruby SDK",
      "affectedLayer": "SDK/transport",
      "issueClass": "DNS rebinding protection gap",
      "affectedVersions": "<=0.22.0",
      "patchedOrFixed": "0.23.0",
      "primaryUrl": "https://github.com/advisories/GHSA-rjr6-rcgv-9m7m",
      "packageSourceId": "SEC055",
      "sourceId": "S210",
      "protocolRelevance": "Implementation/ecosystem issue; not automatically a core-protocol flaw",
      "currentStatus": "LIVE-CHECK REQUIRED",
      "notes": "Affected/fixed ranges must be re-opened immediately before publication."
    },
    {
      "recordId": "R4-VULN056",
      "packageRecordId": "VULN056",
      "disclosureDate": "2026-06-24",
      "cve": "CVE-2026-67431",
      "advisory": "GHSA-5p9g-j988-pcwv",
      "component": "MCP Ruby SDK",
      "affectedLayer": "SDK/session",
      "issueClass": "Protocol-session poisoning / state confusion in legacy session architecture",
      "affectedVersions": "<=0.22.0",
      "patchedOrFixed": "0.23.0",
      "primaryUrl": "https://github.com/advisories/GHSA-5p9g-j988-pcwv",
      "packageSourceId": "SEC056",
      "sourceId": "S211",
      "protocolRelevance": "Implementation/ecosystem issue; not automatically a core-protocol flaw",
      "currentStatus": "LIVE-CHECK REQUIRED",
      "notes": "Affected/fixed ranges must be re-opened immediately before publication."
    },
    {
      "recordId": "R4-VULN057",
      "packageRecordId": "VULN057",
      "disclosureDate": "2026-06-24",
      "cve": "CVE-2026-67430",
      "advisory": "CVE-2026-67430",
      "component": "MCP Ruby SDK",
      "affectedLayer": "SDK/stdio",
      "issueClass": "Unbounded stdio message handling can exhaust resources",
      "affectedVersions": "LIVE-CHECK REQUIRED",
      "patchedOrFixed": "0.23.0 reported",
      "primaryUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-67430",
      "packageSourceId": "SEC057",
      "sourceId": "S212",
      "protocolRelevance": "Implementation/ecosystem issue; not automatically a core-protocol flaw",
      "currentStatus": "LIVE-CHECK REQUIRED",
      "notes": "Affected/fixed ranges must be re-opened immediately before publication."
    },
    {
      "recordId": "R4-VULN058",
      "packageRecordId": "VULN058",
      "disclosureDate": "2026-06-24",
      "cve": "CVE-2026-67432",
      "advisory": "CVE-2026-67432",
      "component": "MCP Ruby SDK",
      "affectedLayer": "SDK/session",
      "issueClass": "Legacy session retention / cleanup flaw",
      "affectedVersions": "LIVE-CHECK REQUIRED",
      "patchedOrFixed": "0.23.0 reported",
      "primaryUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-67432",
      "packageSourceId": "SEC058",
      "sourceId": "S213",
      "protocolRelevance": "Implementation/ecosystem issue; not automatically a core-protocol flaw",
      "currentStatus": "LIVE-CHECK REQUIRED",
      "notes": "Affected/fixed ranges must be re-opened immediately before publication."
    },
    {
      "recordId": "R4-VULN068",
      "packageRecordId": "VULN068",
      "disclosureDate": "2026-08-07",
      "cve": "CVE-2026-9739",
      "advisory": "GHSA-7pf3-8xx7-rvhf",
      "component": "Google MCP Toolbox for Databases",
      "affectedLayer": "Server/transport",
      "issueClass": "DNS rebinding in legacy SSE/local deployment",
      "affectedVersions": "<1.2.0",
      "patchedOrFixed": "1.2.0",
      "primaryUrl": "https://github.com/advisories/GHSA-7pf3-8xx7-rvhf",
      "packageSourceId": "SEC068",
      "sourceId": "S222",
      "protocolRelevance": "Implementation/ecosystem issue; not automatically a core-protocol flaw",
      "currentStatus": "LIVE-CHECK REQUIRED",
      "notes": "Affected/fixed ranges must be re-opened immediately before publication."
    }
  ]
}