7.7 HIGH
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Scope (S): Changed (C)
- Confidentiality (C): High (H)
- Integrity (I): None (N)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Changed (C)
- Modified Integrity (MI): None (N)
- Modified Availability (MA): None (N)
Activity log
- Created suggestion
Contentful MCP Server: export_space/import_space tools pass LLM-controlled `host`/`proxy` args to CMA client, redirecting server PAT to attacker-controlled endpoint
Contentful MCP Server is a Model Context Protocol server for the Contentful Management API. Prior to @contentful/mcp-server 1.7.19 and @contentful/mcp-tools 0.4.5, export_space and import_space in packages/mcp-tools/src/tools/jobs/space-to-space-migration/exportSpace.ts and packages/mcp-tools/src/tools/jobs/space-to-space-migration/importSpace.ts expose host, proxy, rawProxy, and insecure network options to LLM-controlled tool arguments and combine those options with the server's CONTENTFUL_MANAGEMENT_TOKEN. After space_to_space_migration_handler enables the migration tools, a direct MCP call or prompt injection through attacker-controlled Contentful content can redirect Contentful Management API requests and their Authorization header to an attacker-controlled host or proxy. The regular tools that use createToolClient are unaffected because those tools pin the host from server configuration. Exposure of the personal access token permits persistent out-of-band access to every Contentful space within the token's scope. This issue is fixed in @contentful/mcp-server 1.7.19 and @contentful/mcp-tools 0.4.5.
References
-
https://github.com/contentful/contentful-mcp-server/pull/376 x_refsource_MISC
Affected products
- ==< 0.4.5
- ==< 1.7.19
- ==< 1.7.19
Matching in nixpkgs
pkgs.aks-mcp-server
Model Context Protocol server for Azure Kubernetes Service
pkgs.mcp-server-git
Model Context Protocol server providing tools to read, search, and manipulate Git repositories programmatically via LLMs
pkgs.mcp-server-time
Model Context Protocol server providing tools for time queries and timezone conversions for LLMs
pkgs.gitea-mcp-server
Gitea Model Context Protocol (MCP) Server
pkgs.mcp-server-fetch
Model Context Protocol server providing tools to fetch and convert web content for usage by LLMs
-
nixos-unstable -
- nixos-unstable-small 2026.8.31
-
nixos-26.05 -
- nixos-26.05-small 2026.1.26-unstable-2026-05-17
pkgs.github-mcp-server
GitHub's official MCP Server
pkgs.mcp-server-memory
MCP server for enabling memory for Claude through a knowledge graph
pkgs.influxdb-mcp-server
An MCP Server for querying InfluxDB
pkgs.opentofu-mcp-server
OpenTofu MCP server for accessing the OpenTofu Registry
-
nixos-unstable -
- nixos-unstable-small 1.0.0-unstable-2026-09-04
pkgs.terraform-mcp-server
Terraform Model Context Protocol (MCP) Server
pkgs.mcp-server-filesystem
MCP server for filesystem access
pkgs.haskellPackages.mcp-server
Library for building Model Context Protocol (MCP) servers
pkgs.mcp-server-sequential-thinking
MCP server for sequential thinking and problem solving
pkgs.python313Packages.django-mcp-server
Django MCP Server implementation
pkgs.python314Packages.django-mcp-server
Django MCP Server implementation
Package maintainers
-
@priyaananthasankar Priya Ananthasankar <priyagituniverse@gmail.com>
-
@connerohnesorge Conner Ohnesorge <conneroisu@outlook.com>
-
@i-am-logger Ido Samuelson <ido.samuelson@gmail.com>
-
@drupol Pol Dellaiera <pol.dellaiera@protonmail.com>
-
@MrMebelMan Vladyslav Burzakovskyy <burzakovskij@protonmail.com>
-
@pilz0 Pilz <nix@pilz.foo>
-
@eana Jonas Eana