MCP server CVE index
LAST UPDATED 2026-08-10
A consolidated, dated list of publicly disclosed CVEs affecting Model Context Protocol servers and related client tooling. There is no single index for this today — each entry below links to its real, official source (GitHub's Security Advisory Database, which mirrors NVD), not a claim aimcplist is making on its own.
| CVE | Package | Severity | Published | Fixed in | Source |
|---|---|---|---|---|---|
CVE-2026-0755 Command injection and file exfiltration in gemini-mcp-tool | gemini-mcp-tool (npm) 1.1.2 – 1.1.5 | Critical · 9.8 | 2026-01-08 | 1.1.6 | Snyk / GitHub Advisory Database |
CVE-2025-68145 / 68144 / 68143 Path traversal and argument-injection chain in Anthropic's mcp-server-git | mcp-server-git (Anthropic reference server) Before 2025.12.18 (68143 fixed earlier, in 2025.9.25) | High · 8.6 | 2026-01-21 | 2025.12.18 | The Hacker News, citing Anthropic's disclosure |
CVE-2025-6514 OS command injection in mcp-remote | mcp-remote (npm) 0.0.5 – 0.1.15 | Critical · 9.6 | 2025-07-09 | 0.1.16 | GitHub Advisory Database (discovered by JFrog Security Research) |
CVE-2025-49596 Unauthenticated remote code execution in Anthropic's MCP Inspector | @modelcontextprotocol/inspector (npm) Before 0.14.1 | Critical · 9.4 | 2025-06-01 | 0.14.1 | GitHub Advisory Database |
