MCPNews

The Model Context Protocol ecosystem, verified

Current spec 2026-07-28

Contentful

Contentful MCP Server advisory: two migration tools let a model redirect the server's access token to any host

GHSA-2xhg-73j7-rrgx (CVE-2026-53957), CVSS 7.7 high: the maintainer's repository advisory was published 2026-06-12 and GitHub's reviewed record followed on 2026-08-19. The export_space and import_space tools spread LLM-controlled arguments, host and proxy among them, into the options passed to contentful-export, so the Management API client built its base URL from an attacker-supplied host and attached the server's Personal Access Token as a bearer header. Fixed 2026-06-01, eleven days before the repository advisory and eleven weeks before the reviewed record.

GitHub's reviewed advisory record for Contentful's first-party MCP server, dated 2026-08-19, carries CVE-2026-53957, a CWE-918 server-side request forgery rated 7.7 high. The maintainer's own repository advisory under the same identifier had been public since 2026-06-12. Its interest is less the class than the path: two tools handed a model direct control of where the server sent its own credentials.

The export_space and import_space tools spread their incoming arguments into the options object passed to contentful-export and contentful-import. Those options travel to the Contentful Management API SDK, which builds its baseURL from the host value and attaches the server's Management API Personal Access Token as an Authorization: Bearer header on every outgoing request. Because host and proxy were accepted from the tool call, a caller who could invoke the tool, or who could inject instructions into Contentful content the model read, could point all Management API traffic and the token at an endpoint of their choosing. The tools' own Zod schema advertised host, proxy, rawProxy and insecure to the model as ordinary optional parameters.

The advisory is precise about why the rest of the server was unaffected, and that detail is the useful part. All forty-plus regular tools obtain their client through createToolClient, which pins host: config.host ?? 'api.contentful.com' so the model cannot override it. Only these two diverged, calling a helper that extracted the access token and discarded the configured host, then spreading the raw arguments on top. The CONTENTFUL_HOST environment variable was never applied to the export options at all. Both tools are also registered disabled by default, so the documented trigger needs an enabling call first.

The remedy, in pull request #376, was to remove host, proxy and headers from both tool schemas rather than to validate them. It merged on 2026-06-01 and shipped the same day in mcp-server@1.7.19 and mcp-tools@0.4.5, eleven days before the repository advisory and eleven weeks before GitHub's reviewed record. When this story first ran, current releases were mcp-server@1.16.0 and mcp-tools@0.12.6, both from 2026-08-18, so anyone tracking releases had the fix well before the reviewed record described the problem.

Correction, 2026-09-15: this story originally dated the advisory to 2026-08-19, which is the date of GitHub's reviewed record in the Advisory Database, and described the fix as landing eleven weeks before "the advisory." The maintainer published the repository advisory under the same GHSA identifier on 2026-06-12, eleven days after the fix. The two records also state the affected ranges differently: the repository advisory lists <= 1.7.15 and <= 0.4.1 with no patched version entered, while the reviewed record lists < 1.7.19 and < 0.4.5 with those patched versions. The mechanism, the fix commit and the fixed releases are unchanged.

Related servers and clients

How was this verified, and what are the sources?

Published · last verified · confidence 1.00.

  1. GHSA-2xhg-73j7-rrgx, published 2026-08-19T19:17:00Z, CVE-2026-53957, high, CVSS 3.1 7.7 (AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N), CWE-918 - states export_space and import_space in @contentful/mcp-tools "accept LLM-controlled host and proxy parameters that are spread directly into the options object passed to contentful-export / contentful-import", that the CMA SDK "builds baseURL from host and attaches the server's CMA Personal Access Token as Authorization: Bearer <PAT> on every outgoing request", and that an attacker "who can invoke MCP tools, or inject instructions into Contentful content the LLM reads, can redirect all CMA requests - and the PAT - to an attacker-controlled endpoint"; names createClientConfig as extracting only accessToken while discarding config.host, states the CONTENTFUL_HOST environment variable "is never applied to exportOptions", quotes the Zod schema exposing host, proxy, rawProxy and insecure, and states all 40+ regular tools call createToolClient which enforces host: config.host ?? 'api.contentful.com' so "the LLM cannot override this value"; affected npm @contentful/mcp-server < 1.7.19 and @contentful/mcp-tools < 0.4.5; the documented trigger requires first enabling the tools, which register.ts registers disabled by default - accessed
  2. contentful-mcp-server pull request #376 "fix: remove host/proxy/headers from export_space and import_space tool schemas [DX-1177]", merged 2026-06-01T16:01:30Z as commit fa7477ee48515f4248bc91a025eab0ca83423fe0 - the fix named in the advisory's references, showing the remedy was removal of the parameters from the tool schemas rather than validation of them - accessed
  3. contentful-mcp-server releases - mcp-server@1.7.19 and mcp-tools@0.4.5 both published 2026-06-01, eleven weeks before the advisory; the current releases are mcp-server@1.16.0 and mcp-tools@0.12.6, both published 2026-08-18, so any deployment tracking releases had the fix long before the record appeared - accessed
  4. Repository advisory record for GHSA-2xhg-73j7-rrgx via the GitHub API, fetched 2026-09-15 - state published, published_at 2026-06-12T07:50:50Z, vulnerable ranges "<= 1.7.15" for @contentful/mcp-server and "<= 0.4.1" for @contentful/mcp-tools, no patched version entered - accessed
  5. GitHub Advisory Database reviewed record for GHSA-2xhg-73j7-rrgx via the GitHub API, fetched 2026-09-15 - published_at and github_reviewed_at 2026-08-19T19:17:00Z, ranges "< 1.7.19" and "< 0.4.5", first patched versions 1.7.19 and 0.4.5 - accessed

← All news