Skip to content

MCPA-2026-0039

highauth-missingCVSS 8.8

@andrea9293/mcp-documentation-server Web UI binds to all interfaces without authentication (CVE-2026-54504)

@andrea9293/mcp-documentation-server (npm) 1.13.0: the Web UI/API that starts automatically on port 3080 binds to all network interfaces (0.0.0.0) instead of localhost-only, and its document-management API endpoints require no authentication — any network-adjacent attacker can read, modify, or delete the server's documents. Fixed in 1.13.1.

Affected packages

EcosystemPackageAffected versions
npm@andrea9293/mcp-documentation-server
>= 1.13.0, < 1.13.1

Identifiers

CVE-2026-54504GHSA-6f5r-5672-72j7CWE-306CWE-668

References

Timeline

  • Published: 2026-07-15

← All advisories