PT-2026-50897 · Unknown · Line-Desktop-Mcp
CVSS v4.0
8.8
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Line Desktop MCP versions prior to 1.1.2
Description
Line Desktop MCP allows users to operate the LINE Desktop application on Windows or Mac via Model Context Protocol (MCP). When using the
--http-mode Streamable HTTP transport, the server binds to 0.0.0.0 and exposes the '/mcp' endpoint without an MCP-layer authentication check. This allows any network client with access to the port to initialize a session, list tools, and execute tools to read chat history or send messages through the authenticated desktop application.Recommendations
Update to version 1.1.2.
Exploit
Fix
Missing Authentication
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Line-Desktop-Mcp