Skip to content

MCPA-2026-0036

highauth-missingCVSS 7.4

meta-ads-mcp X-Pipeboard-Token header auth bypass reuses the operator Meta token (CVE-2026-54547)

meta-ads-mcp (PyPI) before 1.0.115: AuthInjectionMiddleware rejects HTTP MCP requests only when both auth_token and pipeboard_token are absent, and extract_token_from_headers() does not recognize the X-Pipeboard-Token header — an attacker sending that header with any value passes the auth gate and the server executes Meta Ads API calls with the operator's own Meta token. Fixed in 1.0.115.

Affected packages

EcosystemPackageAffected versions
pypimeta-ads-mcp
>= 0, < 1.0.115

Identifiers

CVE-2026-54547GHSA-2v2f-mvfg-ph56CWE-287

References

Timeline

  • Published: 2026-07-17

← All advisories