Security Research

security MCP Server

Independent AI/LLM security research — 10 shipped fixes, 5 GHSA advisories; focus on multi-tenant isolation, MCP protocol attack surface, SSRF/cookie boundary leakage

Verified
securitysecurity
2 views0 stars0 forks

Why This Matters

Discovered via github-topic:mcp and last synced 3mo ago.

Verified
Source
github-topic:mcp
Stars
0
Last synced
3mo ago
Install
Check source

Install

Install instructions not detected yet

Check the source repository for the latest setup steps.

View source instructions
8
Tools
0
Resources
0
Prompts
Standard I/O
Transport

Available Tools (8)

XSS

`dangerouslySetInnerHTML` rendered untrusted MCP server descriptions and search results unsanitized

GHSA

Project

PR

Class

GHSA-2qwc-c2cc-2xwv

Dify

Dify

Tenant boundary violation

Gradio

SSRF (regression coverage)

IDOR

Data source binding missed `tenant_id` validation, enabling cross-tenant resource access

SSRF

MCP `server_url` accepted internal addresses (127.0.0.1, link-local, RFC1918)