VendorsLF Projectsmcp_registryall versions
Vulnerabilities

LF Projects Model Context Protocol (MCP) Registry

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2026-44430
MCP Registry: Unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist
Published 2026-05-14 · Modified
6.3EPSS 0.003
CVE-2026-44429
MCP Registry: Stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled `websiteUrl`
Published 2026-05-14 · Analyzed
5.4EPSS 0.002
CVE-2026-44428
MCP Registry: GitHub OIDC tokens replayable across registry deployments due to shared audience
Published 2026-05-14 · Analyzed
4.7EPSS 0.002