MCP Connect has unauthenticated remote OS command execution via /bridge endpoint
- Severity:
- High
Description
When AUTH_TOKEN and ACCESS_TOKEN environment variables are not set (which is the default out-of-the-box configuration) the /bridge HTTP endpoint is completely unauthenticated.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 2.0.0
References
Related Issues
- A remote command execution (RCE) vulnerability in the /api/runscript endpoint of FUXA - CVE-2023-33831
- DbGate: Remote Code Execution via functionName injection in loadReader endpoint - CVE-2026-48017
- @saltcorn/server Remote Code Execution (RCE) / SQL injection via prototype pollution by manipulating `lang` and `defst - Vulnerability
- DbGate: Unauthenticated Remote Code Execution via JSON Script Runner - CVE-2026-47668
You might also like:
- Tags:
- npm
- mcp-bridge
Anything's wrong? Let us know Last updated on March 19, 2026


