All vulnerabilities

CVE-2026-81101

Airtable MCP CLI before 0.2.5: credential disclosure via unvalidated configured endpoint

mediumCVSS 6.9CWE-200
Vendor
Airtable
Package
airtable-mcp-cli npm
Affected
>= 0, < 0.2.5
Fixed in
0.2.5
Disclosed
2026-08-27
Credit
Avishai Gonen
credential-disclosuremcp

Bug bounty awarded. Reported through HackerOne.