Severity: LowVulnerabilityData exfiltration
Verbose tool errors leak internal schema and endpoints
APAC
Sample data. Showing illustrative sample items as a fallback — the live feed is not available right now.
A misconfigured MCP server returned full stack traces and internal endpoint names in error responses to agents. While not directly exploitable, the leaked detail meaningfully lowers the cost of reconnaissance for an attacker.
What to do
Return generic errors to agents, keep detailed diagnostics server-side in the SIEM, and review tool responses for inadvertent internal disclosure.
Mapped framework pillars
Sources
#information disclosure#hardening#misconfiguration
