Securva · CVE-derived pipeline
The MCP security wave, turned into a prospect list.
Every one of these shipped a real vulnerability in the exact class we break, and got a public advisory for it. That makes them the warmest possible outreach: we are not cold-pitching a problem, we are pointing at their own CVE.
314MCP / agent-security advisories mined
77distinct affected vendors found
~4 → 69monthly disclosure surge
The play. The market for MCP / AI-agent security audits is being created in real time, and we already hold CVEs in this class (File Browser, Gitea, OpenBao, the OpenSearch + Docker-MCP work). These 77 vendors just proved they have the same exposure. Lead every message with their own advisory, then offer the audit that stops the next one.
Suggested opener: "Saw the recent advisory in [project] ([class]). We do exactly this class of MCP / agent-security review and hold published CVEs in it. Happy to run a quick no-charge look at your current MCP surface and share what we'd check." Honest, specific, receipt-led.
Ranked prospects
By fit: shipping an MCP product + high-impact class (RCE / unauth / authz) ranks highest. Auto-mined, give it a 2-minute sanity pass before sending.
01
MCP Gateway
Cred leakUnauth exposureInjection
MCP Gateway: Authority-injection and JWT/session bypass via the unauthenticated router hair-pin "router-key" / "mcp-init-host" pat
02
mcp-memory-service
RCECred leakUnauth exposure
mcp-memory-service: Missing Authentication on Document API Endpoints Allows Unauthenticated Memory Read/Write/Delete
03
meta-ads-mcp
RCESSRFUnauth exposure
meta-ads-mcp: Server-Side Request Forgery (SSRF) in `upload_ad_image` via Unrestricted `image_url` Fetch
04
@samanhappy/mcphub
Cred leakUnauth exposure
@samanhappy/mcphub: SSE Endpoint Accepts Arbitrary Username from URL Path Without Authentication, Enabling User Impersonation
05
Network-AI
Cred leakUnauth exposure
Network-AI: Unauthenticated Cross-Origin MCP Tool Invocation via Empty Default Secret
06
PraisonAI
InjectionSSRFUnauth exposure
PraisonAI: MCP SSE transport binds 0.0.0.0 with no authentication and no Origin validation; bundled SecurityConfig is never wired in
07
NetLicensing-MCP
Cred leakUnauth exposure
NetLicensing-MCP: Unauthenticated Use of Server-Side NetLicensing API Key in HTTP Mode
08
Kozou
Unauth exposureInjection
Kozou: Unauthenticated MCP HTTP server and bundled dev-stack hardening (DNS-rebinding, request-body limits, read-only reads, default network exp
09
9router
RCEUnauth exposure
9router: Unauthenticated Remote Code Execution via unprotected MCP custom plugin routes
10
CamoFox MCP
Unauth exposure
CamoFox MCP: Unauthenticated HTTP MCP browser-control surface
11
Windows-MCP
Unauth exposure
Windows-MCP: HTTP transports expose unauthenticated PowerShell control with wildcard CORS
12
MCP Server Kubernetes
AuthZ bypass
MCP Server Kubernetes: Tool Access Control Bypass via Presentation-Layer Filtering Without Execution-Layer Enforcement
13
Meta Ads MCP
Cred leakUnauth exposure
Meta Ads MCP: Unauthenticated HTTP MCP Tool Execution Leaks Operator Meta Access Token
14
googleapis/mcp-toolbox
AuthZ bypassCred leak
googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken)
15
dbt MCP Server
Unauth exposure
dbt MCP Server: Unauthenticated OAuth Context Endpoint Leaks dbt Platform Tokens
16
ha-mcp
Cred leakUnauth exposure
ha-mcp: Add-on settings and policy routes are reachable without authentication at the bare root path
17
Gittensory
AuthZ bypassCred leak
Gittensory: Missing contributor-scoped access control on profile endpoint and MCP tool leaks miner financial data
18
LangBot
RCE
LangBot: Authenticated RCE Via MCP Configuration
19
@andrea9293/mcp-documentation-server
Unauth exposure
@andrea9293/mcp-documentation-server: Web UI API binds to all interfaces without authentication by default
20
auth-fetch-mcp
SSRFInjection
auth-fetch-mcp: SSRF and disk exfiltration via unvalidated auth_fetch and download_media URLs
21
SearXNG MCP Server
InjectionSSRF
SearXNG MCP Server: DNS-resolved Private Hostname SSRF in `web_url_read`
22
Apify Model Context Protocol (MCP) server
Cred leakInjection
Apify Model Context Protocol (MCP) server: Actor MCP path authority injection leaks Apify token
23
MCP Atlassian
InjectionSSRF
MCP Atlassian: DNS-rebinding TOCTOU bypass of the SSRF fix (CVE-2026-27826)
24
Crawl4AI
AuthZ bypassCred leakSSRFUnauth exposure
Crawl4AI: LLM credential exfiltration in Docker server via request base_url and env: token resolution
25
n8n
Unauth exposure
n8n: MCP Browser HTTP Transport Exposes Unauthenticated Browser-Control Sessions
26
MCP Toolbox for Databases
AuthZ bypass
MCP Toolbox for Databases: authenticated authorization bypass
27
mcp-pinot
Unauth exposure
mcp-pinot: Unauthenticated tool invocation via default oauth_enabled=False + host 0.0.0.0 bind
28
Langroid
RCEInjection
Langroid: Neo4jChatAgent executes LLM-generated Cypher without validation (prompt-to-Cypher injection; config-conditional RCE), mirroring the SQ
Auto-extracted from the ARGUS + tg-filter advisory corpus (8,375 items) on 2026-07-22 via mcp-vendor-extract.py. A few entries may need a quick human check (project name / commercial-fit). Outreach stays respectful and receipt-led, never spammy, never implying we found their bug. The list refills itself as new MCP CVEs land (wired into the daily sauce digest).