All vulnerabilities

CVE-2026-61542 · GHSA-fmvx-487g-mrww

Gearsystem: MCP HTTP transport binds every interface without authentication

highCVSS 7.6CWE-306
Vendor
drhelius
Package
io.github.drhelius/gearsystem
Affected
<= 3.8.6
Disclosed
2026-06-12
Credit
Avishai Gonen
auth-bypassmcp