mcp is vulnerable to Insecure Default Variable Initialization
45
Medium Risk
Affected versions of this package do not enforce secure default server settings. When running locally, the server binds to all network interfaces (0.0.0.0) instead of restricting access to localhost (127.0.0.1). This increases the risk of exposure to external access and makes the application more susceptible to DNS rebinding attacks. The patch addresses this by setting localhost as the default bind address, thereby reducing the attack surface.
You are affected if you are using a version that falls within the vulnerable range.
mcp is vulnerable to Insecure Default Variable Initialization in versions 0.8.0 - 1.9.0.
Upgrade the mcp library to the latest patched version or ensure that the binding addresses are not set to 0.0.0.0.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant