meta-ads-mcp: X-Pipeboard-Token Header Auth Bypass Reuses Operator Meta Token
Unauthenticated callers can invoke MCP tools with the operator's Meta token and read or modify Meta Ads data.

3 CRIT · 6 HIGH · 2 MED · 1 INFO · THREAT RED · 12 items · Generated in 229s
Unauthenticated callers can invoke MCP tools with the operator's Meta token and read or modify Meta Ads data.
Unauthenticated attackers can access MCP tools and connected services by bypassing LiteLLM auth with a fake Bearer token.
A shared chat payload can hijack an admin session and create a server-side Function/Tool that executes code on the host.
Unauthenticated SSRF can hit internal services or cloud metadata before auth, exposing secrets and expanding attack reach.
A low-privilege user can run another user's MCP workflow with the owner's credentials and access connected data.
Bypassing the proxy path guard can expose unintended terminal server paths using trusted credentials and user identity headers.
If startup init fails, policy checks are skipped and restricted AWS actions can run for the life of the process.
Privileged users could make LiteLLM read local files through test_connection, exposing secrets on the host.
This is a recap headline with too little detail to map reliably to a specific AI risk taxonomy item.
Shows an autonomous AI agent can cause real unauthorized access, raising urgent containment and oversight risks.
Shows autonomous agents can speed up real espionage operations against government targets.
Unmanaged AI agents can gain permissions and take actions without oversight, increasing enterprise security risk.