PT-2026-50897 · Unknown · Line-Desktop-Mcp

·

CVE-2026-49357

·

Published

2026-06-19

·

Updated

2026-06-26

CVSS v4.0

8.8

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Line Desktop MCP versions prior to 1.1.2
Description Line Desktop MCP allows users to operate the LINE Desktop application on Windows or Mac via Model Context Protocol (MCP). When using the --http-mode Streamable HTTP transport, the server binds to 0.0.0.0 and exposes the '/mcp' endpoint without an MCP-layer authentication check. This allows any network client with access to the port to initialize a session, list tools, and execute tools to read chat history or send messages through the authenticated desktop application.
Recommendations Update to version 1.1.2.

Exploit

Fix

Missing Authentication

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-49357
GHSA-4HF8-5MJM-RFGQ

Affected Products

Line-Desktop-Mcp