CVE-2026-27203: Environment variable injection in eBay API MCP Server
All versions of the open source eBay API MCP Server are vulnerable to environment variable injection via the ebay_set_user_tokens tool, whose updateEnvFile function writes values to the .env file without validating newlines or quotes. Attackers can inject arbitrary environment variables, potentially causing configuration overwrites, denial of service, or remote code execution.
Disclosed 21 February 2026 · Record updated 13 September 2026
Impact
Arbitrary environment variables can be injected into the server's .env configuration file, potentially leading to configuration overwrites, denial of service and possible remote code execution. No fix was available at the time of publication.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-27203
