CVE-2026-44427

NONE
CVSS v3
CVSS v2
0.02% EPSS (exploit probability)
CWE-601CWE

Description

The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. From 1.1.0 to 1.7.4, the TrailingSlashMiddleware in internal/api/server.go is vulnerable to an open redirect attack. An attacker can craft a URL with a protocol-relative path (e.g., //evil.com/) that, after trailing slash removal, results in a Location header of //evil.com — which browsers interpret as an absolute URL to an external domain. This vulnerability is fixed in 1.7.5.

Affected routers (0)

No routers currently mapped to this CVE in our database.

External references