Improper exposure of the MCP server in alibabacloud-rds-openapi-mcp-server allows remote attackers to invoke exposed MCP tools via network access to an MCP endpoint listening on all network interfaces by default.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-07-28 09:16
Updated : 2026-07-28 20:35
NVD link : CVE-2026-9680
Mitre link : CVE-2026-9680
CVE.ORG link : CVE-2026-9680
JSON object : View
Products Affected
No product.
CWE
CWE-1188
Initialization of a Resource with an Insecure Default
