mcp_server_for_data_exploration_project CVE 脆弱性と CVE 一覧(1)

製品(CPE): — CVE 件数: 1

mcp_server_for_data_exploration_project 脆弱性概要

This page aggregates publicly disclosed CVE and security risk information related to mcp_server_for_data_exploration_project, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.

脆弱性分布の推移(直近24か月)

表示中 11 / 1 CVE 件数
«« 先頭 « 前へ 1 / 1 次へ »
CVE 概要 ソース CVSS 最大値 EPSS(%) 公開 更新
CVE-2025-63603 A command injection vulnerability exists in the MCP Data Science Server's (reading-plus-ai/mcp-server-data-exploration) 0.1.6 in the safe_eval() function (src/mcp_server_ds/server.py:108). The function uses Python's exec() to execute user-supplied scripts but fails to restrict the __builtins__ dictionary in the globals parameter. When __builtins__ is not explicitly defined, Python automatically provides access to all built-in functions including __import__, exec, eval, and open. This allows an a [email protected] 6.5 0.78% 2025-11-18 2026-01-02
«« 先頭 « 前へ 1 / 1 次へ »
cvelogic Threat Intelligence