Incident database
Contentful MCP Server Prompt Injection via Network Options
Contentful MCP Server versions prior to 1.7.19 expose network configuration options to LLM-controlled arguments, allowing prompt injection attacks to redirect API requests and steal authentication tokens. The vulnerability affects space-to-space migration tools and is fixed in updated versions.
Disclosed 15 September 2026 · Record updated 15 September 2026
Impact
Attackers can redirect Contentful Management API requests to attacker-controlled hosts via prompt injection, exposing personal access tokens and enabling persistent unauthorized access to all Contentful spaces within token scope.
Our coverage
VulnerabilitiesA fixed vulnerability in Contentful's Model Context Protocol server allowed AI-controlled tool arguments to redirect management API calls, and their credentials, to attacker hosts.
15 Sept 2026
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-53957