Wednesday, 16 September 2026
0 agent hacks today 2 vs yesterday (2)

Contentful MCP Server Prompt Injection via Network Options

Contentful MCP Server versions prior to 1.7.19 expose network configuration options to LLM-controlled arguments, allowing prompt injection attacks to redirect API requests and steal authentication tokens. The vulnerability affects space-to-space migration tools and is fixed in updated versions.

Disclosed 15 September 2026 · Record updated 15 September 2026

Impact

Attackers can redirect Contentful Management API requests to attacker-controlled hosts via prompt injection, exposing personal access tokens and enabling persistent unauthorized access to all Contentful spaces within token scope.

Our coverage

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-53957