Vulnerabilities/

MCP Connect has unauthenticated remote OS command execution via /bridge endpoint

Severity:
High

Description

When AUTH_TOKEN and ACCESS_TOKEN environment variables are not set (which is the default out-of-the-box configuration) the /bridge HTTP endpoint is completely unauthenticated.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
mcp-bridge
Anything's wrong? Let us know Last updated on March 19, 2026