PT-2026-82567 · Unknown · Mcp-Router
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
mcp-router versions prior to 0.6.3
Description
The CLI serves its MCP aggregator on every network interface by default and only enforces authentication if explicitly requested by the operator. In the
serve command located in apps/cli/src/commands/serve.ts, the host defaults to the all-interfaces address on a fixed port and requires a token only when a specific flag is provided. Consequently, a default invocation exposes the aggregator and all connected MCP servers to any user capable of reaching the port.Recommendations
Update to version 0.6.3 or later.
Exploit
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mcp-Router