MCPA-2026-0036
highauth-missingCVSS 7.4
meta-ads-mcp X-Pipeboard-Token header auth bypass reuses the operator Meta token (CVE-2026-54547)
meta-ads-mcp (PyPI) before 1.0.115: AuthInjectionMiddleware rejects HTTP MCP requests only when both auth_token and pipeboard_token are absent, and extract_token_from_headers() does not recognize the X-Pipeboard-Token header — an attacker sending that header with any value passes the auth gate and the server executes Meta Ads API calls with the operator's own Meta token. Fixed in 1.0.115.
Affected packages
| Ecosystem | Package | Affected versions |
|---|---|---|
| pypi | meta-ads-mcp | >= 0, < 1.0.115 |
Identifiers
CVE-2026-54547GHSA-2v2f-mvfg-ph56CWE-287
References
- advisory https://github.com/pipeboard-co/meta-ads-mcp/security/advisories/GHSA-2v2f-mvfg-ph56
- web https://github.com/pipeboard-co/meta-ads-mcp/releases/tag/1.0.115
Timeline
- Published: 2026-07-17