CVE-2026-44428 Details
Description
The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. Prior to 1.7.6, the client-side and server-side GitHub OIDC flow is bound only to a global audience string, not to the specific registry instance being targeted. On the client side, the publisher always appends audience=mcp-registry when requesting the GitHub Actions ID token, regardless of the selected --registry URL. On the server side, the exchange endpoint validates only that same fixed audience and then derives publish permissions directly from repository_owner. As a result, a token legitimately obtained while interacting with one registry deployment remains acceptable to any other deployment that shares the same code and audience string. This vulnerability is fixed in 1.7.6.
A vulnerability exists in the MCP Registry's GitHub OpenID Connect (OIDC) authentication flow, allowing tokens to be replayed across different registry deployments. This issue arises because the OIDC flow is tied to a global audience string, rather than to individual registry instances. As a result, a token obtained from one registry can be used to authenticate with another registry that shares the same audience, bypassing intended access controls. This vulnerability affects MCP Registry versions prior to 1.7.6.
Users are advised to update to MCP Registry version 1.7.6 or later. Additionally, the audience string should be replaced with a registry-specific identifier, and the publisher should request an audience that matches the exact registry instance being targeted. It is also recommended to bind the token exchange to deployment-specific claims to prevent cross-registry token replay.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/modelcontextprotocol/registry/security/advisories/GHSA-95c3-6vvw-4mrq | [email protected] | MitigationVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| lfprojects mcp registry | < 1.7.6 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 15, 2026 | Initial Analysis | [email protected] |
| May 14, 2026 | New CVE Received | [email protected] |