Vulnerabilities/

eBay API MCP Server Affected by Environment Variable Injection

Severity:
High

Description

The ebay_set_user_tokens tool allows updating the .env file with new tokens. The updateEnvFile function in src/auth/oauth.ts blindly appends or replaces values without validating them for newlines or quotes. This allows an attacker to inject arbitrary environment variables into the configuration file.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
ebay-mcp
Anything's wrong? Let us know Last updated on February 23, 2026