Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

mcp-router CLI exposed MCP aggregator without authentication by default

The mcp-router CLI served its MCP aggregator on all network interfaces without requiring authentication unless explicitly configured, exposing the aggregator and all fronted MCP servers to unauthorized network access. The vulnerability was fixed in version 0.6.3 by defaulting to loopback address and requiring authentication for non-loopback hosts.

Disclosed 27 August 2026 · Record updated 13 September 2026

Impact

Unauthenticated exposure of MCP aggregator and all fronted MCP servers to anyone able to reach the listening port on any network interface

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-81094