The Python code being run by 'runPython' or 'runPythonAsync' is not isolated from the rest of the JS code, allowing any Python code to use the Pyodide APIs to modify the JS environment. This may result in an attacker hijacking the MCP server - for malicious purposes including MCP tool shadowing. Note - the "mcp-run-python" project is archived and unlikely to receive a fix.
References
Configurations
No configuration.
History
09 Feb 2026, 09:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-09 09:16
Updated : 2026-02-09 16:08
NVD link : CVE-2026-25905
Mitre link : CVE-2026-25905
CVE.ORG link : CVE-2026-25905
JSON object : View
Products Affected
No product.
CWE
CWE-653
Improper Isolation or Compartmentalization
