VDB
Sign up
HIGH8.3

GHSA-97rm-xj73-33jh

eBay API MCP Server Affected by Environment Variable Injection

Details

The `ebay_set_user_tokens` tool allows updating the `.env` file with new tokens. The `updateEnvFile` function in `src/auth/oauth.ts` blindly appends or replaces values without validating them for newlines or quotes. This allows an attacker to inject arbitrary environment variables into the configuration file.

### Impact An attacker can inject arbitrary environment variables into the `.env` file. This could lead to: - **Configuration Overwrites**: Attackers can overwrite critical settings like `EBAY_REDIRECT_URI` to hijack OAuth flows. - **Denial of Service**: Injecting invalid configuration can prevent the server from starting. - **Potential RCE**: In some environments, controlling environment variables (like `NODE_OPTIONS`) can lead to Remote Code Execution.

Found with [MCPwner](https://github.com/Pigyon/MCPwner) 🕶

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/ebay-mcp
Introduced in: 0

No fixed version published yet for ebay-mcp (npm). Pin to a known-safe version or switch to an alternative.

References