MCPA-2026-0038
highauth-missingCVSS 8.1
NetLicensing-MCP HTTP mode uses the server-side NetLicensing API key for unauthenticated requests (CVE-2026-54446)
netlicensing-mcp (PyPI) through 0.1.5: in HTTP transport mode, ApiKeyMiddleware forwards requests that carry no client API key unconditionally, and the downstream HTTP client falls back to the server's own NetLicensing API key — unauthenticated remote callers act with the operator's full API privileges. Fixed in 0.1.6.
Affected packages
| Ecosystem | Package | Affected versions |
|---|---|---|
| pypi | netlicensing-mcp | >= 0, < 0.1.6 |
Identifiers
CVE-2026-54446GHSA-x9vc-9ffq-p3gjCWE-306
References
- advisory https://github.com/Labs64/NetLicensing-MCP/security/advisories/GHSA-x9vc-9ffq-p3gj
- fix https://github.com/Labs64/NetLicensing-MCP/commit/fbbb1d5ff88eb5400ec933a84e75601ebee48927
- web https://github.com/Labs64/NetLicensing-MCP/releases/tag/0.1.6
Timeline
- Published: 2026-07-14