mcp_server_for_data_exploration_project CVE Vulnerabilities & CVE List (1)

Products (CPE): — CVEs: 1

mcp_server_for_data_exploration_project vulnerability overview

This page aggregates publicly disclosed CVE and security risk information related to mcp_server_for_data_exploration_project, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.

Vulnerability distribution trend (last 24 months)

Showing 11 of 1 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2025-63603 A command injection vulnerability exists in the MCP Data Science Server's (reading-plus-ai/mcp-server-data-exploration) 0.1.6 in the safe_eval() function (src/mcp_server_ds/server.py:108). The function uses Python's exec() to execute user-supplied scripts but fails to restrict the __builtins__ dictionary in the globals parameter. When __builtins__ is not explicitly defined, Python automatically provides access to all built-in functions including __import__, exec, eval, and open. This allows an a [email protected] 6.5 1.38% 2025-11-18 2026-01-02
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence