Kong · Kong Konnect Mcp Server · CVE-2026-13341
**Name of the Vulnerable Software and Affected Versions**
Kong Konnect MCP server versions prior to 1.0.0
**Description**
An issue exists where the server fails to properly validate content returned to the Large Language Model (LLM). This allows a remote attacker to perform an indirect prompt injection by placing malicious text within data that the AI agent reads. Consequently, the agent may interpret these smuggled instructions as its own and execute unintended API requests against Kong Konnect using its own permissions, which could lead to the exposure of sensitive data.
**Recommendations**
Update Kong Konnect MCP server to version 1.0.0 or later.