Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

CVE-2026-27203: Environment variable injection in eBay API MCP Server

All versions of the open source eBay API MCP Server are vulnerable to environment variable injection via the ebay_set_user_tokens tool, whose updateEnvFile function writes values to the .env file without validating newlines or quotes. Attackers can inject arbitrary environment variables, potentially causing configuration overwrites, denial of service, or remote code execution.

Disclosed 21 February 2026 · Record updated 13 September 2026

Impact

Arbitrary environment variables can be injected into the server's .env configuration file, potentially leading to configuration overwrites, denial of service and possible remote code execution. No fix was available at the time of publication.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-27203