frontmcp CVE 脆弱性と CVE 一覧(1)

製品(CPE): — CVE 件数: 1

frontmcp 脆弱性概要

This page aggregates publicly disclosed CVE and security risk information related to frontmcp, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.

脆弱性分布の推移(直近24か月)

表示中 11 / 1 CVE 件数
«« 先頭 « 前へ 1 / 1 次へ »
CVE 概要 ソース CVSS 最大値 EPSS(%) 公開 更新
CVE-2026-39885 FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). Prior to 2.3.0, the mcp-from-openapi library uses @apidevtools/json-schema-ref-parser to dereference $ref pointers in OpenAPI specifications without configuring any URL restrictions or custom resolvers. A malicious OpenAPI specification containing $ref values pointing to internal network addresses, cloud metadata endpoints, or local files will cause the library to fetch those resources during the initialize() call. Th [email protected] 7.5 0.31% 2026-04-08 2026-04-15
«« 先頭 « 前へ 1 / 1 次へ »
cvelogic Threat Intelligence