Impact
The flaw in consul‑mcp‑server allows a client that has established a connection to the server to supply a custom request header that overrides the server’s configured Consul backend address. Because the server does not validate this header, it can redirect internal Consul API traffic to an arbitrary endpoint controlled by the attacker. This redirects the traffic that carries the Consul token embedded in those requests, enabling the attacker to exfiltrate that token and compromise the credentials used by the server.
Affected Systems
HashiCorp’s consul‑mcp‑server versions 0.1.0 through 0.1.3 are affected. The vulnerability does not extend to later releases that enforce address restrictions.
Risk and Exploitability
The CVSS score of 8.6 indicates a high severity based on confidentiality impact, and the EPSS score of less than 1 % shows a low publicly known exploitation probability. The issue is not listed in the CISA KEV catalog. Attackers would need to be a client with network connectivity to the consul‑mcp‑server and must send a crafted request header; the flaw is therefore exploitable from within the same trusted network or through an authenticated client access channel.
OpenCVE Enrichment