line-desktop-mcp HTTP mode exposes unauthenticated MCP endpoint (CVE-2026-49357)
In versions prior to 1.1.2, the line-desktop-mcp server's --http-mode bound to 0.0.0.0 and exposed the /mcp endpoint with no MCP-layer authentication, letting any network client initialize a session and call tools that read LINE Desktop chat history or send messages through the logged-in application. Version 1.1.2 fixes the issue.
Disclosed 19 June 2026 · Record updated 13 September 2026
Impact
Any client able to reach the exposed port could list and call MCP tools to read LINE Desktop chat history or send LINE messages via the already logged-in desktop application.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-49357
