MCPA-2026-0039
highauth-missingCVSS 8.8
@andrea9293/mcp-documentation-server Web UI binds to all interfaces without authentication (CVE-2026-54504)
@andrea9293/mcp-documentation-server (npm) 1.13.0: the Web UI/API that starts automatically on port 3080 binds to all network interfaces (0.0.0.0) instead of localhost-only, and its document-management API endpoints require no authentication — any network-adjacent attacker can read, modify, or delete the server's documents. Fixed in 1.13.1.
Affected packages
| Ecosystem | Package | Affected versions |
|---|---|---|
| npm | @andrea9293/mcp-documentation-server | >= 1.13.0, < 1.13.1 |
Identifiers
CVE-2026-54504GHSA-6f5r-5672-72j7CWE-306CWE-668
References
- advisory https://github.com/andrea9293/mcp-documentation-server/security/advisories/GHSA-6f5r-5672-72j7
- fix https://github.com/andrea9293/mcp-documentation-server/commit/37159d4e06b8ee50c3645b2496e3d3f6d32c47f9
- web https://github.com/andrea9293/mcp-documentation-server/releases/tag/v1.13.1
Timeline
- Published: 2026-07-15