PT-2026-98461 · Rapid7 · Rapid7 Bulk Export Mcp
CVE-2026-97228
·
Published
2026-09-25
·
Updated
2026-09-25
CVSS v3.1
2.7
Low
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Rapid7 Bulk Export MCP versions 0.2.5 through 0.6.1
Description
A GraphQL query injection issue exists in the export-status component within the
get export status() function in src/export manager.py. The export id variable, which is an unvalidated argument passed through the check rapid7 export status and download rapid7 export tools, is interpolated directly into the GraphQL query string. An attacker can use a crafted export id containing quote and brace characters to terminate the intended selection and append unauthorized root-level selections, such as schema introspection. The resulting query is executed against the Rapid7 export API using the operator's authenticated API key. This issue does not allow crossing tenant or account boundaries, as queries execute within the operator's existing API scope. The primary risk involves compromised upstream MCP clients or indirect prompt injection.Recommendations
Update Rapid7 Bulk Export MCP to version 0.6.2.
As a temporary mitigation, restrict the use of the
check rapid7 export status and download rapid7 export tools to ensure only validated identifiers are used for the export id variable.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rapid7 Bulk Export Mcp