highVulnerability

GHSA-vrxg-gm77-7q5g

HTTP transports expose unauthenticated PowerShell control with wildcard CORS There is an issue in the SSE and Streamable HTTP transport modes. The default stdio mode is not affected, but the documented HTTP modes expose the MCP control plane without authentication and add wildcard CORS handling around it. The same server exposes the `PowerShell` tool, which executes caller-controlled commands as the Windows user running Windows-MCP. Relevant source: - `src/windows_mcp/__main__.py:37-42`: `_http_middleware()` installs `OptionsMiddleware` and `CORSMiddleware` with `allow_origins=["*"]`, `allow_methods=["*"]`, and `allow_headers=["*"]`. - `src/windows_mcp/__main__.py:45-72`: `OptionsMiddleware` responds to every `OPTIONS` request with wildcard `Access-Control-Allow-Origin`, `Access-Control-Allow-Methods`, and `Access-Control-Allow-Headers`. - `src/windows_mcp/__main__.py:75-113`: `_build_mcp()` constructs `FastMCP(name="windows-mcp", ...)` without an auth provider. - `src/windows_mcp/__main__.py:139-151`: both `sse` and `streamable-http` call `mcp.run(...)` with that middleware and no application-level auth/security settings. - `src/windows_mcp/tools/shell.py:10-24`: registers the `PowerShell` tool and passes caller-controlled `command` to `PowerShellExecutor.execute_command`. - `src/windows_mcp/desktop/powershell.py:176-204`: executes that command through PowerShell `-EncodedCommand`. - `README.md:421-424` and `433-434`: documents the HTTP transports and describes Streamable HTTP as network-accessible HTTP streaming. In an affected configuration, a client that can reach `http://localhost:8000/mcp` can initialize an MCP session and invoke `tools/call` for `PowerShell`. The issue is not just that PowerShell is powerful; it is that the HTTP control plane around that tool is unauthenticated and configured with wildcard CORS. ## Root cause The HTTP transport entry points compose two independent design decisions that fail-open together: the FastMCP instance is built w

Properties

ghsa_id
GHSA-vrxg-gm77-7q5g
summary
Windows-MCP: HTTP transports expose unauthenticated PowerShell control with wildcard CORS
severity
high
cve_id
GHSA-vrxg-gm77-7q5g
is_ghsa_only
true
ghsa_published
2026-05-21T16:46:02Z
source_url
https://github.com/advisories/GHSA-vrxg-gm77-7q5g
ghsa_updated
2026-05-21T16:46:04Z

Related Entities (4)

HAS_WEAKNESS (1)

[Weakness]Missing Authentication for Critical Function

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]pip/windows-mcp

AFFECTS (1)

[Software]pip/windows-mcp

Explore deeper with Ninja Signal's threat intelligence graph