
Critical Unauthenticated RCE Vulnerability in CircleCI's MCP Server
cybersecurityvulnerabilityRCECircleCIallowlist_bypass
A critical vulnerability in CircleCI’s MCP server allows unauthenticated remote code execution (RCE). The flaw involves a bypass of the Host/Origin allowlist when accessed by non-browser clients. The issue is tracked under the identifier GHSA-xv5j-cwgj-22r4.