PT-2026-33508 · Neo4J Contrib · Mcp-Neo4J

Published

2026-04-17

·

Updated

2026-04-17

·

CVE-2026-35402

CVSS v4.0

2.3

Low

AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
mcp-neo4j-cypher is an MCP server for executing Cypher queries against Neo4j databases. In versions prior to 0.6.0, the read only mode enforcement can be bypassed using APOC CALL procedures, potentially allowing unauthorized write operations or server-side request forgery. This issue is fixed in version 0.6.0.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2026-35402

Affected Products

Mcp-Neo4J