Severity: CriticalVulnerabilityMCP/tool abuse
Unauthenticated RCE in MCP server bound to 0.0.0.0 over SSE
Global
Sample data. Showing illustrative sample items as a fallback — the live feed is not available right now.
A flaw in an MCP server's Server-Sent Events transport allows command execution when the service is bound to 0.0.0.0 without authentication. Internet-exposed instances were discoverable through routine scanning of /sse endpoints.
What to do
Inventory and remove 0.0.0.0 bindings, require authentication on every MCP transport, and place servers behind a gateway rather than exposing them directly.
Mapped framework pillars
Sources
CVE references
- CVE-SAMPLE-001(sample — not a real CVE)
#RCE#SSE#exposed endpoint#0.0.0.0
