PT-2026-107951 · Beam Mcp · Beam Mcp

CVE-2026-104634

·

Published

2026-10-08

·

Updated

2026-10-08

CVSS v4.0

2.3

Low

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions beam mcp versions 0.1.0 through 0.10.0
Description An incorrect type conversion issue exists in BeamMCP.Server where JSON true, false, and null tool arguments are converted into the strings "true", "false", and "nil" before reaching the host's dispatch function. This occurs because normalize arguments/2 passes arguments through to json value/1, which converts atoms to strings. In Elixir, strings are truthy, meaning a host checking a boolean argument (e.g., if args.dry run) will execute the true branch even if the client sent false. This affects tool arguments and prompts/get arguments. The impact is primarily on hosts or policy layers that differentiate behavior between true and false or use boolean guards like confirm: false.
Recommendations Update beam mcp to version 0.10.1. As a temporary workaround, modify the host's dispatch function to compare boolean arguments against both their boolean and string forms, such as args.flag in [true, "true"] and args.flag in [false, "false"], and treat the string "nil" as null where the schema allows.

Fix

Incorrect Type Conversion or Cast

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-104634
GHSA-WV7P-J6QH-3HJ4

Affected Products

Beam Mcp