Skip to content
Agentic AI Security Hub
Back to feed
Severity: CriticalVulnerabilityMCP/tool abuse

Unauthenticated RCE in MCP server bound to 0.0.0.0 over SSE

Global

Sample data. Showing illustrative sample items as a fallback — the live feed is not available right now.

A flaw in an MCP server's Server-Sent Events transport allows command execution when the service is bound to 0.0.0.0 without authentication. Internet-exposed instances were discoverable through routine scanning of /sse endpoints.

What to do

Inventory and remove 0.0.0.0 bindings, require authentication on every MCP transport, and place servers behind a gateway rather than exposing them directly.

#RCE#SSE#exposed endpoint#0.0.0.0