GHSA-p7w7-4929-vpj5
HIGH@dynatrace-oss/dynatrace-mcp-server v1.8.5 exposes an HTTP transport mode (--http flag) that performs no authentication, session validation, or origin/host verification before dispatching MCP tool calls. Any network-reachable attacker can send a raw JSON-RPC tools/call request without an Authorization header and have it executed directly under the victim server's Dynatrace credentials. Confirmed h
- Affected
- >=0, <2.0.0, <= 1.8.7
- Fixed in
- 2.0.0
- Weakness
- CWE-306
- Published
- 2026-07-31
- Source
- osv