PT-2026-107951 · Beam Mcp · Beam Mcp
CVE-2026-104634
·
Published
2026-10-08
·
Updated
2026-10-08
CVSS v4.0
2.3
Low
| Vector | AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
beam mcp versions 0.1.0 through 0.10.0
Description
An incorrect type conversion issue exists in
BeamMCP.Server where JSON true, false, and null tool arguments are converted into the strings "true", "false", and "nil" before reaching the host's dispatch function. This occurs because normalize arguments/2 passes arguments through to json value/1, which converts atoms to strings. In Elixir, strings are truthy, meaning a host checking a boolean argument (e.g., if args.dry run) will execute the true branch even if the client sent false. This affects tool arguments and prompts/get arguments. The impact is primarily on hosts or policy layers that differentiate behavior between true and false or use boolean guards like confirm: false.Recommendations
Update beam mcp to version 0.10.1.
As a temporary workaround, modify the host's dispatch function to compare boolean arguments against both their boolean and string forms, such as
args.flag in [true, "true"] and args.flag in [false, "false"], and treat the string "nil" as null where the schema allows.Fix
Incorrect Type Conversion or Cast
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Beam Mcp