Impact
A flaw in the Kong Konnect Model Context Protocol (MCP) server before version 1.0.0 permits a remote attacker to manipulate untrusted analytics data, resulting in an indirect prompt injection that can cause unintended API requests. This input‑validation weakness, classified as CWE‑20, may affect the intended request flow on the MCP service.
Affected Systems
All Kong Konnect MCP deployments running any release prior to 1.0.0 are vulnerable. The issue lies in the component that processes incoming analytics payloads from external sources, so any installation that accepts such data without strict validation can be affected.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.4, indicating high severity, while an EPSS score of less than 1% indicates a low likelihood of exploitation. Based on the description, the likely attack vector is remote; an adversary would need to send crafted analytics payloads to the MCP service. Although the vulnerability is not listed in the CISA KEV catalog and no active exploits are reported, the potential for unintended API requests warrants attention.
OpenCVE Enrichment