CVE-2026-59973
- EPSS 0.38%
- Veröffentlicht 15.09.2026 15:13:40
- Zuletzt bearbeitet 30.09.2026 17:51:56
FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). From mcp-from-openapi 2.3.0 until 2.5.0 and from frontmcp and @frontmcp/adapters 1.2.1 until 1.5.0, libs/adapters/src/openapi/openapi.adapter.ts loadOpenAPISpec() forwards...
CVE-2026-67531
- EPSS 0.43%
- Veröffentlicht 05.08.2026 22:54:36
- Zuletzt bearbeitet 10.09.2026 20:37:00
FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). Prior to 1.5.7, the sandboxed codecall:execute tool exposes live host Zod schema instances to the script via getTool(), and because Zod v4 defines _zod as a non-configurab...
CVE-2026-39885
- EPSS 0.32%
- Veröffentlicht 08.04.2026 20:34:20
- Zuletzt bearbeitet 24.07.2026 21:10:00
FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). Prior to 2.3.0, the mcp-from-openapi library uses @apidevtools/json-schema-ref-parser to dereference $ref pointers in OpenAPI specifications without configuring any URL re...