Ghostwire

CVE-2026-53957: Contentful MCP Server: export_space/import_space tools pass LLM-controlled `host`/`proxy` args to CMA client,...

HIGH CVSS 7.7 Exploit Available

Published: August 19, 2026 | Last Modified: August 19, 2026

Description

Contentful MCP Server: export_space/import_space tools pass LLM-controlled `host`/`proxy` args to CMA client, redirecting server PAT to attacker-controlled endpoint

Ghostwire Analysis — What This Means Practically

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

References