mcp-pinot: Unauthenticated tool invocation via default oauth_enabled=False + host 0.0.0.0 bind
Default remote access without OAuth let anyone invoke tools over the network, enabling full unauthorized actions and data exposure.

2 CRIT · 7 HIGH · 3 MED · THREAT RED · 12 items · Generated in 240s
Default remote access without OAuth let anyone invoke tools over the network, enabling full unauthorized actions and data exposure.
Unauthenticated attackers can read, add, and delete stored memory data remotely, breaking confidentiality and integrity.
Patched MCP Atlassian can still be tricked into reaching metadata or internal hosts via DNS rebinding, bypassing the SSRF guard.
Unauthenticated requests can run OS commands on the host process, leading to full server compromise.
Allows redirect abuse and SSRF to internal services, exposing sensitive credentials such as cloud metadata tokens.
A remote client can bypass token checks and access the default Telegram session without a valid bearer token.
A valid hook token could grant owner-only MCP tool access, breaking isolation between automation and privileged actions.
An MCP client or injected agent can read local secrets and upload them to Confluence from the server account.
Shows an LLM-driven attack can exploit a real flaw, steal production data, and deploy ransomware on other systems.
Hallucinated domains can trick developers or agents into fetching attacker-owned resources, creating a supply chain entry point.
Workflow-level prompt tricks can bypass safety controls and make coding assistants produce harmful outputs.
Benign AI agents can mimic attacker behavior, causing false positives and weakening trust in endpoint detections.