PT-2026-98461 · Rapid7 · Rapid7 Bulk Export Mcp

CVE-2026-97228

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v3.1

2.7

Low

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Rapid7 Bulk Export MCP versions 0.2.5 through 0.6.1
Description A GraphQL query injection issue exists in the export-status component within the get export status() function in src/export manager.py. The export id variable, which is an unvalidated argument passed through the check rapid7 export status and download rapid7 export tools, is interpolated directly into the GraphQL query string. An attacker can use a crafted export id containing quote and brace characters to terminate the intended selection and append unauthorized root-level selections, such as schema introspection. The resulting query is executed against the Rapid7 export API using the operator's authenticated API key. This issue does not allow crossing tenant or account boundaries, as queries execute within the operator's existing API scope. The primary risk involves compromised upstream MCP clients or indirect prompt injection.
Recommendations Update Rapid7 Bulk Export MCP to version 0.6.2. As a temporary mitigation, restrict the use of the check rapid7 export status and download rapid7 export tools to ensure only validated identifiers are used for the export id variable.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-97228

Affected Products

Rapid7 Bulk Export Mcp