HIGH7.7npm
GHSA-2xhg-73j7-rrgx· CVE-2026-53957Contentful MCP Server: export_space/import_space tools pass LLM-controlled `host`/`proxy` args to CMA client, redirecting server PAT to attacker-controlled endpoint
Modified: 8/19/2026
package
pkg:npm/%40contentful/mcp-tools
Contentful MCP Server: export_space/import_space tools pass LLM-controlled `host`/`proxy` args to CMA client, redirecting server PAT to attacker-controlled endpoint
Modified: 8/19/2026