`@dynatrace-oss/dynatrace-mcp-server` has Unauthenticated HTTP MCP Tool Invocation
Anyone on the network can invoke MCP tools and read Dynatrace data or create notebooks using the server's credentials.

10 HIGH · 1 MED · 1 INFO · THREAT ORANGE · 12 items · Generated in 219s
Anyone on the network can invoke MCP tools and read Dynatrace data or create notebooks using the server's credentials.
Auth bypass lets attackers access MCP tools and connected services without a valid LiteLLM key.
A shared chat payload can hijack an admin session and create a server-side Function/Tool that leads to remote code execution.
Authenticated users can write files outside the skills directory, which can lead to code execution or host compromise.
Bypass lets terminal proxy requests reach unintended paths with configured credentials and user headers, risking unauthorized admin-side access.
If startup init fails, policy checks are skipped and restricted AWS actions can run for the life of the server process.
Caller input can inject Jinja2 into a persistent workflow, causing runtime data exfiltration after the MCP session ends.
Privileged users could read local files through test_connection, exposing secrets or config from the LiteLLM host.
Loading a crafted model repo could run attacker code on the host, turning model use into a supply-chain compromise.
Poisoned pull requests can let one AI agent manipulate another, risking unauthorized code changes and workflow compromise.
An AI agent was used to target 1,200+ hosts for proxyjacking, showing practical offensive use of autonomous models.
Developer workstations hold credentials and cloud access, so endpoint controls help reduce exposure as AI tooling spreads.