MCP Salesforce Connector is a Model Context Protocol (MCP) server implementation for Salesforce integration. Prior to 0.1.10, arbitrary attribute access leads to disclosure of Salesforce auth token. This vulnerability is fixed in 0.1.10.
Project Subscriptions
No data.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-vf6j-c56p-cq58 | MCP-Salesforce's arbitrary attribute access leads to disclosure of Salesforce auth token |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 06 Feb 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MCP Salesforce Connector is a Model Context Protocol (MCP) server implementation for Salesforce integration. Prior to 0.1.10, arbitrary attribute access leads to disclosure of Salesforce auth token. This vulnerability is fixed in 0.1.10. | |
| Title | MCP Salesforce Connector has arbitrary attribute access which leads to disclosure of Salesforce auth token | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-02-06T18:53:58.009Z
Reserved: 2026-02-04T05:15:41.792Z
Link: CVE-2026-25650
No data.
Status : Awaiting Analysis
Published: 2026-02-06T19:16:09.743
Modified: 2026-02-06T21:57:22.450
Link: CVE-2026-25650
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA