Description
The configure command accepted any endpoint URL and stored it beside the user-s access token. ConfigureCommand.execute in src/cli.ts persisted the value given to its endpoint option into the user profile without passing it through createSafeUrl in src/config.ts, the helper that already restricted the environment-variable form of the same setting to the vendor-s own hosts over HTTPS. Because the connect path in src/mcp.ts attaches the stored token as a bearer credential on every request to the configured endpoint, a user who was persuaded to run configure with an endpoint of the attacker-s choosing sent their personal access token to that destination on each subsequent invocation. Version 0.2.5 applies the same helper to the option.
CVSS 6.5EPSS 0.322%Risk 0.67
View source- Published
- 2026-08-27 17:20:52
- Affected versions
- <0.2.5
- Type
- Library
- Last modified
- 2026-08-27 20:18:49
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N