PT-2026-39262 · Unknown · Mcp Registry

·

CVE-2026-44428

·

Published

2026-05-08

·

Updated

2026-06-25

CVSS v3.1

4.7

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions MCP Registry versions prior to 1.7.6
Description The GitHub OIDC flow for both client and server is bound to a global audience string instead of the specific registry instance being targeted. On the client side, the publisher always appends audience=mcp-registry when requesting the GitHub Actions ID token, regardless of the --registry URL selected. On the server side, the exchange endpoint '/v0/auth/github-oidc' validates only this fixed audience and derives publish permissions directly from the repository owner variable. Consequently, a token obtained for one registry deployment can be replayed to any other deployment sharing the same code and audience string, allowing an attacker-controlled or compromised registry to impersonate a GitHub owner identity and perform unauthorized publication or update actions.
Recommendations Update to version 1.7.6.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44428
GHSA-95C3-6VVW-4MRQ
GO-2026-5273

Affected Products

Mcp Registry