SB2026072607 - Exposed dangerous method or function in MCP Gateway



SB2026072607 - Exposed dangerous method or function in MCP Gateway

Published: July 26, 2026

Security Bulletin ID SB2026072607
CSH Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Exposed dangerous method or function (CVE-ID: CVE-2025-64443)

CWE-ID: CWE-749 - Exposed Dangerous Method or Function

CVSSv4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to manipulate exposed MCP server features and tools.

The vulnerability exists due to exposed dangerous methods or functions in MCP Gateway when running in sse or streaming mode and processing browser-based access. A remote attacker can lure a victim into visiting a malicious website or viewing a malicious advertisement to manipulate exposed MCP server features and tools.

The issue does not affect instances running in the default stdio mode, which does not listen on network ports. User interaction is required.


Remediation

Install update from vendor's website.