PT-2026-107971 · Beam Mcp · Beam Mcp

CVE-2026-88257

·

Published

2026-10-08

·

Updated

2026-10-08

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions beam mcp versions 0.1.0 through 0.10.0
Description Improper input validation in BeamMCP.Schema allows an MCP client to send arguments to a tool's dispatch function that violate the advertised input schema. The BeamMCP.Schema.validate/2 function only validates type, required, additionalProperties, enum, and numeric bounds on top-level arguments. Constraints within nested objects and array items—including items, minItems, maxItems, minLength, maxLength, pattern, nested required, enum, and additionalProperties: false—are ignored during validation at the tools/call and prompts/get endpoints. Additionally, keywords such as oneOf, anyOf, and $ref are advertised but not enforced. This allows a host to receive forbidden values, such as out-of-range numbers or undeclared keys within nested objects, which may lead to unexpected behavior depending on how the host's dispatch code processes the input.
Recommendations Update beam mcp to version 0.10.1. As a temporary workaround, re-validate arguments inside the host's dispatch function against all constraints declared below the top level, or move all constraints to top-level properties.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-88257
GHSA-MRG2-4747-FMPW

Affected Products

Beam Mcp