CVE-2026-44429: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in modelcontextprotocol registry
CVE-2026-44429 is a stored cross-site scripting (XSS) vulnerability in the modelcontextprotocol (MCP) registry versions prior to 1.7.7. The vulnerability arises from improper neutralization of input in the server.websiteUrl field, which is included in the public catalogue UI without sufficient escaping. This allows an attacker with publish access to inject malicious event handlers into the registry homepage. The vulnerability is medium severity with a CVSS 5.1 score and is fixed in version 1.7.7.
AI Analysis
Technical Summary
The MCP Registry serves a public catalogue UI listing MCP servers. Versions before 1.7.7 are vulnerable to stored XSS via the server.websiteUrl field in published server.json files. Server-side validation only ensures the URL parses, is absolute, and uses HTTPS, but does not reject quote characters. Client-side, the URL is inserted into a double-quoted href attribute using a custom escapeHtml function that does not encode quotes, allowing injection of arbitrary on* event handlers. The Content-Security-Policy permits inline scripts, enabling execution of injected handlers. Any user with a publish token can exploit this to inject malicious scripts visible to all visitors. The issue is resolved in version 1.7.7.
Potential Impact
An attacker with publish token access can inject malicious JavaScript into the MCP registry homepage, potentially executing arbitrary scripts in the context of users visiting the page. This could lead to session hijacking, defacement, or other client-side attacks. The vulnerability requires at least low privileges (publish token) and user interaction (visiting the page). No known exploits in the wild have been reported.
Mitigation Recommendations
This vulnerability is fixed in modelcontextprotocol registry version 1.7.7. Users should upgrade to version 1.7.7 or later to remediate this issue. No official patch or temporary fix is indicated other than upgrading. Until upgraded, restrict publish token issuance to trusted users only to reduce risk.
CVE-2026-44429: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in modelcontextprotocol registry
Description
CVE-2026-44429 is a stored cross-site scripting (XSS) vulnerability in the modelcontextprotocol (MCP) registry versions prior to 1.7.7. The vulnerability arises from improper neutralization of input in the server.websiteUrl field, which is included in the public catalogue UI without sufficient escaping. This allows an attacker with publish access to inject malicious event handlers into the registry homepage. The vulnerability is medium severity with a CVSS 5.1 score and is fixed in version 1.7.7.
CVSS v4.0
Score 5.1medium
Affected software
pkg:github/modelcontextprotocol/registryRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The MCP Registry serves a public catalogue UI listing MCP servers. Versions before 1.7.7 are vulnerable to stored XSS via the server.websiteUrl field in published server.json files. Server-side validation only ensures the URL parses, is absolute, and uses HTTPS, but does not reject quote characters. Client-side, the URL is inserted into a double-quoted href attribute using a custom escapeHtml function that does not encode quotes, allowing injection of arbitrary on* event handlers. The Content-Security-Policy permits inline scripts, enabling execution of injected handlers. Any user with a publish token can exploit this to inject malicious scripts visible to all visitors. The issue is resolved in version 1.7.7.
Potential Impact
An attacker with publish token access can inject malicious JavaScript into the MCP registry homepage, potentially executing arbitrary scripts in the context of users visiting the page. This could lead to session hijacking, defacement, or other client-side attacks. The vulnerability requires at least low privileges (publish token) and user interaction (visiting the page). No known exploits in the wild have been reported.
Mitigation Recommendations
This vulnerability is fixed in modelcontextprotocol registry version 1.7.7. Users should upgrade to version 1.7.7 or later to remediate this issue. No official patch or temporary fix is indicated other than upgrading. Until upgraded, restrict publish token issuance to trusted users only to reduce risk.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-05-06T14:40:00.954Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a063d1aec166c07b0130140
Added to database: 05/14/2026, 21:22:34 UTC
Last enriched: 05/22/2026, 15:37:04 UTC
Last updated: 07/31/2026, 19:22:59 UTC
Views: 88
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.