<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-10T16:33:33.777613+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-371239</id>
    <title>EUVD-2026-371239</title>
    <updated>2026-10-10T16:33:33.780568+00:00</updated>
    <content>EUVD-2026-371239</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-371239"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-54547</id>
    <title>fkie_cve-2026-54547</title>
    <updated>2026-10-10T16:33:33.780601+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.115, AuthInjectionMiddleware in meta_ads_mcp/core/http_auth_integration.py rejects HTTP MCP requests only when both auth_token and pipeboard_token are absent, while extract_token_from_headers() does not recognize X-Pipeboard-Token as a primary credential. A network caller using the streamable-http transport can therefore send any X-Pipeboard-Token value, pass the guard without establishing authentication context, and cause get_auth_token() to fall back to the server operator's META_ACCESS_TOKEN. Subsequent MCP tools execute with the operator's Meta credentials and can read or modify the operator's Meta Ads data. Deployments using the default stdio transport or without META_ACCESS_TOKEN are not affected. This issue is fixed in version 1.0.115.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-54547"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-2v2f-mvfg-ph56</id>
    <title>GHSA-2v2f-mvfg-ph56 — meta-ads-mcp: X-Pipeboard-Token Header Auth Bypass Reuses Operator Meta Token</title>
    <updated>2026-10-10T16:33:33.780637+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: meta-ads-mcp</p>
<p>## X-Pipeboard-Token Header Auth Bypass Reuses Operator Meta Token</p>
<p>### Summary</p>
<p>`AuthInjectionMiddleware` in `meta-ads-mcp` rejects HTTP MCP requests only when **both** `auth_token` and `pipeboard_token` are absent. Because `extract_token_from_headers()` does not recognise the `X-Pipeboard-Token` header, an attacker who sends that header with any arbitrary value produces `auth_token = None` and `pipeboard_token = &lt;attacker value&gt;`, making the guard condition evaluate to `False` and passing the request through. No authentication context is set; the token getter falls back to the server operator's `META_ACCESS_TOKEN` environment variable. Every subsequent MCP tool call executes with the operator's Meta credentials, allowing an unauthenticated network caller to read and write the operator's Meta Ads data.</p>
<p>### Details</p>
<p>The vulnerable condition is at `meta_ads_mcp/core/http_auth_integration.py:259`:</p>
<p>```python
# http_auth_integration.py:255-260
auth_token = FastMCPAuthIntegration.extract_token_from_headers(dict(request.headers))
pipeboard_token = FastMCPAuthIntegration.extract_pipeboard_token_from_headers(dict(request.headers))</p>
<p>if not auth_token and not pipeboard_token:      # ← bypass condition
    return Response(..., status_code=401)
```</p>
<p>`extract_token_from_headers()` (lines 77–95) recognises only `Authorization: Bearer`, `X-META-ACCESS-TOKEN`, and `X-PIPEBOARD-API-TOKEN`. It does **not** recognise `X-Pipeboard-Token`, so that header never populates `auth_token`.</p>
<p>`extract…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-2v2f-mvfg-ph56"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-3484</id>
    <title>PYSEC-2026-3484 — meta-ads-mcp: X-Pipeboard-Token Header Auth Bypass Reuses Operator Meta Token</title>
    <updated>2026-10-10T16:33:33.780756+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: meta-ads-mcp</p>
<p>## X-Pipeboard-Token Header Auth Bypass Reuses Operator Meta Token</p>
<p>### Summary</p>
<p>`AuthInjectionMiddleware` in `meta-ads-mcp` rejects HTTP MCP requests only when **both** `auth_token` and `pipeboard_token` are absent. Because `extract_token_from_headers()` does not recognise the `X-Pipeboard-Token` header, an attacker who sends that header with any arbitrary value produces `auth_token = None` and `pipeboard_token = &lt;attacker value&gt;`, making the guard condition evaluate to `False` and passing the request through. No authentication context is set; the token getter falls back to the server operator's `META_ACCESS_TOKEN` environment variable. Every subsequent MCP tool call executes with the operator's Meta credentials, allowing an unauthenticated network caller to read and write the operator's Meta Ads data.</p>
<p>### Details</p>
<p>The vulnerable condition is at `meta_ads_mcp/core/http_auth_integration.py:259`:</p>
<p>```python
# http_auth_integration.py:255-260
auth_token = FastMCPAuthIntegration.extract_token_from_headers(dict(request.headers))
pipeboard_token = FastMCPAuthIntegration.extract_pipeboard_token_from_headers(dict(request.headers))</p>
<p>if not auth_token and not pipeboard_token:      # ← bypass condition
    return Response(..., status_code=401)
```</p>
<p>`extract_token_from_headers()` (lines 77–95) recognises only `Authorization: Bearer`, `X-META-ACCESS-TOKEN`, and `X-PIPEBOARD-API-TOKEN`. It does **not** recognise `X-Pipeboard-Token`, so that header never populates `auth_token`.</p>
<p>`extract…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-3484"/>
  </entry>
</feed>
