Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (2):Search: mcp_server.py

Search Results: "mcp_server.py"

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-7386: Path Traversal in fatbobman mail-mcp-bridgeCVE-2026-7386
0

A flaw has been found in fatbobman mail-mcp-bridge up to 1.3.3. Affected is an unknown function of the file src/mail_mcp_server.py. Executing a manipulation of the argument message_ids can lead to path traversal. The attack can be executed remotely. The exploit has been published and may be used. Upgrading to version 1.3.4 is able to address this issue. This patch is called 638b162b26532e32fa8d8047f638537dbdfe197a. Upgrading the affected component is recommended.

Join the discussion
CVE-2026-7215: Command Injection in egtai gmx-vmd-mcpCVE-2026-7215
0

CVE-2026-7215 is a command injection vulnerability in the egtai gmx-vmd-mcp product version 0.1.0. The flaw exists in the launch_vmd_gui_tool function within the mcp_server.py file, where manipulation of the structure_file or trajectory_file arguments can lead to command injection. This vulnerability can be exploited remotely without authentication. The issue was reported to the project early, but no response or fix has been provided yet. The vulnerability has a CVSS 4.0 base score of 6.9, indicating medium severity.

Join the discussion
CVE-2026-7213: Path Traversal in ef10007 MLOps_MCPCVE-2026-7213
0

A vulnerability was detected in ef10007 MLOps_MCP 1.0.0. This impacts an unknown function of the file fastmcp_server.py of the component save_file Tool. The manipulation of the argument filename/destination results in path traversal. The attack may be performed from remote. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Join the discussion
CVE-2026-7211: Command Injection in dvladimirov MCPCVE-2026-7211
0

CVE-2026-7211 is a command injection vulnerability in dvladimirov MCP version 0.1.0, specifically in the GitSearchRequest function of the mcp_server.py file within the Git Search API component. An attacker can remotely manipulate the repo_url or pattern argument to execute arbitrary commands. The vulnerability has a CVSS 4.0 base score of 6.9, indicating medium severity. Although the issue was reported early, the project has not yet responded or provided a fix. Exploit code is publicly available, but no known exploits in the wild have been reported to date.

Join the discussion

Showing 1 to 4 of 4 results

Filters:mcp_server.py
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses