PT-2026-39262 · Unknown · Mcp Registry

Forimoc

·

Published

2026-05-08

·

Updated

2026-05-15

·

CVE-2026-44428

CVSS v3.1

4.7

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions MCP Registry versions prior to 1.7.6
Description The GitHub OIDC flow for both client and server is bound to a global audience string instead of the specific registry instance being targeted. On the client side, the publisher always appends audience=mcp-registry when requesting the GitHub Actions ID token, regardless of the --registry URL selected. On the server side, the exchange endpoint '/v0/auth/github-oidc' validates only this fixed audience and derives publish permissions directly from the repository owner variable. Consequently, a token obtained for one registry deployment can be replayed to any other deployment sharing the same code and audience string, allowing an attacker-controlled or compromised registry to impersonate a GitHub owner identity and perform unauthorized publication or update actions.
Recommendations Update to version 1.7.6.

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2026-44428
GHSA-95C3-6VVW-4MRQ

Affected Products

Mcp Registry