← Retour à la recherche de CVE

CVE-2026-81101

tiger-gh-mcp-server

Description

The configure command accepted any endpoint URL and stored it beside the user-s access token. ConfigureCommand.execute in src/cli.ts persisted the value given to its endpoint option into the user profile without passing it through createSafeUrl in src/config.ts, the helper that already restricted the environment-variable form of the same setting to the vendor-s own hosts over HTTPS. Because the connect path in src/mcp.ts attaches the stored token as a bearer credential on every request to the configured endpoint, a user who was persuaded to run configure with an endpoint of the attacker-s choosing sent their personal access token to that destination on each subsequent invocation. Version 0.2.5 applies the same helper to the option.

CVSS 6.5EPSS 0.322%Risque 0.67
Voir la source
Publication
2026-08-27 17:20:52
Versions concernées
<0.2.5
Type
Bibliothèque
Dernière modification
2026-08-27 20:18:49
Vecteur
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N