Impact
A flaw in the Kong Konnect Model Context Protocol (MCP) server before version 1.0.0 permits a remote attacker to manipulate untrusted analytics data, leading to indirect prompt injection that can cause unintended API requests. This input‑validation weakness, classified as CWE‑20, can result in the server executing commands or accessing protected endpoints, potentially leaking credentials and altering state.
Affected Systems
All Kong Konnect MCP deployments running any release prior to 1.0.0 are vulnerable. The issue specifically lies in the component that processes incoming analytics payloads from external sources, so any installation that accepts such data without strict validation can be affected.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.4, indicating high severity, while an EPSS score of less than 1% suggests a low likelihood of exploitation. Based on the description, the likely attack vector is remote; an adversary must send crafted analytics payloads to the MCP service. Although the vulnerability is not listed in the CISA KEV catalog and no active exploits are reported, the possibility of credential exposure and unintended API execution warrants immediate attention.
OpenCVE Enrichment