Unknown · Line-Desktop-Mcp · CVE-2026-49357
**Name of the Vulnerable Software and Affected Versions**
Line Desktop MCP versions prior to 1.1.2
**Description**
Line Desktop MCP allows users to operate the LINE Desktop application on Windows or Mac via Model Context Protocol (MCP). When using the `--http-mode` Streamable HTTP transport, the server binds to `0.0.0.0` and exposes the '/mcp' endpoint without an MCP-layer authentication check. This allows any network client with access to the port to initialize a session, list tools, and execute tools to read chat history or send messages through the authenticated desktop application.
**Recommendations**
Update to version 1.1.2.