VDB
Sign up
—

PYSEC-2026-2629

MCP-Salesforce's arbitrary attribute access leads to disclosure of Salesforce auth token

Quick fix

PYSEC-2026-2629 — mcp-salesforce-connector: upgrade to the fixed version with the command below.

pip install --upgrade 'mcp-salesforce-connector>=0.1.10'

Details

### Impact _Disclosure of Salesforce OAuth bearer tokens used by the MCP._

### Patches _fix applied in 0.1.10_

### Workarounds _Rotate any Salesforce tokens/credentials used by MCP-Salesforce._

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/mcp-salesforce-connector
Introduced in: 0Fixed in: 0.1.10
Fixpip install --upgrade 'mcp-salesforce-connector>=0.1.10'

References