GHSA-vrxg-gm77-7q5g
HTTP transports expose unauthenticated PowerShell control with wildcard CORS There is an issue in the SSE and Streamable HTTP transport modes. The default stdio mode is not affected, but the documented HTTP modes expose the MCP control plane without authentication and add wildcard CORS handling around it. The same server exposes the `PowerShell` tool, which executes caller-controlled commands as the Windows user running Windows-MCP. Relevant source: - `src/windows_mcp/__main__.py:37-42`: `_http_middleware()` installs `OptionsMiddleware` and `CORSMiddleware` with `allow_origins=["*"]`, `allow_methods=["*"]`, and `allow_headers=["*"]`. - `src/windows_mcp/__main__.py:45-72`: `OptionsMiddleware` responds to every `OPTIONS` request with wildcard `Access-Control-Allow-Origin`, `Access-Control-Allow-Methods`, and `Access-Control-Allow-Headers`. - `src/windows_mcp/__main__.py:75-113`: `_build_mcp()` constructs `FastMCP(name="windows-mcp", ...)` without an auth provider. - `src/windows_mcp/__main__.py:139-151`: both `sse` and `streamable-http` call `mcp.run(...)` with that middleware and no application-level auth/security settings. - `src/windows_mcp/tools/shell.py:10-24`: registers the `PowerShell` tool and passes caller-controlled `command` to `PowerShellExecutor.execute_command`. - `src/windows_mcp/desktop/powershell.py:176-204`: executes that command through PowerShell `-EncodedCommand`. - `README.md:421-424` and `433-434`: documents the HTTP transports and describes Streamable HTTP as network-accessible HTTP streaming. In an affected configuration, a client that can reach `http://localhost:8000/mcp` can initialize an MCP session and invoke `tools/call` for `PowerShell`. The issue is not just that PowerShell is powerful; it is that the HTTP control plane around that tool is unauthenticated and configured with wildcard CORS. ## Root cause The HTTP transport entry points compose two independent design decisions that fail-open together: the FastMCP instance is built w
Properties
- ghsa_id
- GHSA-vrxg-gm77-7q5g
- summary
- Windows-MCP: HTTP transports expose unauthenticated PowerShell control with wildcard CORS
- severity
- high
- cve_id
- GHSA-vrxg-gm77-7q5g
- is_ghsa_only
- true
- ghsa_published
- 2026-05-21T16:46:02Z
- source_url
- https://github.com/advisories/GHSA-vrxg-gm77-7q5g
- ghsa_updated
- 2026-05-21T16:46:04Z
Related Entities (4)
HAS_WEAKNESS (1)
REPORTED_BY (1)
VULNERABLE_TO (1)
AFFECTS (1)
Explore deeper with Ninja Signal's threat intelligence graph