Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

line-desktop-mcp HTTP mode exposes unauthenticated MCP endpoint (CVE-2026-49357)

In versions prior to 1.1.2, the line-desktop-mcp server's --http-mode bound to 0.0.0.0 and exposed the /mcp endpoint with no MCP-layer authentication, letting any network client initialize a session and call tools that read LINE Desktop chat history or send messages through the logged-in application. Version 1.1.2 fixes the issue.

Disclosed 19 June 2026 · Record updated 13 September 2026

Impact

Any client able to reach the exposed port could list and call MCP tools to read LINE Desktop chat history or send LINE messages via the already logged-in desktop application.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-49357