Vulnerabilities/

Uni-CLI: Legacy HTTP MCP transport accepted browser-originated localhost requests

Severity:
High

Description

Uni-CLI versions before 0.225.2 exposed the legacy JSON-RPC-over-HTTP MCP transport on loopback without validating browser Origin headers before routing requests. A malicious web page could send a CORS simple POST request, such as text/plain, to the local /mcp endpoint and deliver a JSON-RPC body to the dispatcher.

Recommendation

Update the @zenalexa/unicli package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@zenalexa/unicli
Anything's wrong? Let us know Last updated on June 19, 2026