Impact
BeamMCP.Server incorrectly normalizes JSON boolean and null arguments to their string equivalents before dispatch. Because strings are truthy in Elixir, host logic that tests a boolean flag, such as if args.dry_run, will evaluate true when the client sends false, and vice‑versa. This misinterpretation can alter control flow, allowing a client to trigger the opposite branch of a conditional or to satisfy a guard that expects a false value. The practical impact is limited to hosts whose behavior differs between true and false, or to policy layers that accept false but reject true, and does not provide a pathway to code execution or privilege escalation.
Affected Systems
The vulnerability affects all ScriptKittyOS beam_mcp instances from version 0.1.0 up to but not including 0.10.1, as identified by the CNA. This includes all distributions of beam_mcp that have not received the fix present in 0.10.1 and newer.
Risk and Exploitability
The CVSS score of 2.3 indicates a low severity assessment. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog. Because any client can send crafted JSON, the attack vector is remote, but the impact is confined to hosts that rely on strict boolean behavior. The potential for exploitation is low, and the correct solution is to patch or apply the provided workaround rather than to enact broader security controls.
OpenCVE Enrichment