Description
Contentful MCP Server is a Model Context Protocol server for the Contentful Management API. Prior to @contentful/mcp-server 1.7.19 and @contentful/mcp-tools 0.4.5, export_space and import_space in packages/mcp-tools/src/tools/jobs/space-to-space-migration/exportSpace.ts and packages/mcp-tools/src/tools/jobs/space-to-space-migration/importSpace.ts expose host, proxy, rawProxy, and insecure network options to LLM-controlled tool arguments and combine those options with the server's CONTENTFUL_MANAGEMENT_TOKEN. After space_to_space_migration_handler enables the migration tools, a direct MCP call or prompt injection through attacker-controlled Contentful content can redirect Contentful Management API requests and their Authorization header to an attacker-controlled host or proxy. The regular tools that use createToolClient are unaffected because those tools pin the host from server configuration. Exposure of the personal access token permits persistent out-of-band access to every Contentful space within the token's scope. This issue is fixed in @contentful/mcp-server 1.7.19 and @contentful/mcp-tools 0.4.5.
Published: 2026-09-15
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Auth Token Misuse
Action: Immediate Patch
AI Analysis

Impact

The contentful MCP server’s export_space and import_space utilities accept host, proxy, rawProxy, and insecure options in arguments that can be influenced by a large language model (LLM). These options are merged with the server’s Contentful Management API PAT, allowing an attacker to redirect authenticated API calls to an arbitrary host or proxy. The result is persistent out‑of‑band access to every space within the token’s scope, enabling data exfiltration or modification without the knowledge of the legitimate user.

Affected Systems

Affected systems include the @contentful/mcp-server package (prior to version 1.7.19) and the @contentful/mcp-tools package (prior to version 0.4.5).

Risk and Exploitability

The vulnerability has a CVSS score of 7.7, indicating moderate to high severity. The EPSS score is less than 1%, suggesting a low likelihood of widespread exploitation in the near term, and it is not currently listed in CISA’s KEV catalog. The likely attack vector is remote, achieved through malicious LLM input or compromised Contentful content that triggers the export/import tools and manipulates the network options.

Generated by OpenCVE AI on September 17, 2026 at 15:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade @contentful/mcp-server to version 1.7.19 or newer and @contentful/mcp-tools to version 0.4.5 or newer.
  • If upgrading is delayed, disable or restrict the use of export_space and import to prevent host, proxy, and related options from being set by external input.
  • Implement application‑level validation to allow only trusted domains or disable proxy forwarding for these tools until a patch is applied.

Generated by OpenCVE AI on September 17, 2026 at 15:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-2xhg-73j7-rrgx Contentful MCP Server: export_space/import_space tools pass LLM-controlled `host`/`proxy` args to CMA client, redirecting server PAT to attacker-controlled endpoint
History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Contentful
Contentful contentful-mcp-server
Contentful mcp-tools
Vendors & Products Contentful
Contentful contentful-mcp-server
Contentful mcp-tools

Thu, 17 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description Contentful MCP Server is a Model Context Protocol server for the Contentful Management API. Prior to @contentful/mcp-server 1.7.19 and @contentful/mcp-tools 0.4.5, export_space and import_space in packages/mcp-tools/src/tools/jobs/space-to-space-migration/exportSpace.ts and packages/mcp-tools/src/tools/jobs/space-to-space-migration/importSpace.ts expose host, proxy, rawProxy, and insecure network options to LLM-controlled tool arguments and combine those options with the server's CONTENTFUL_MANAGEMENT_TOKEN. After space_to_space_migration_handler enables the migration tools, a direct MCP call or prompt injection through attacker-controlled Contentful content can redirect Contentful Management API requests and their Authorization header to an attacker-controlled host or proxy. The regular tools that use createToolClient are unaffected because those tools pin the host from server configuration. Exposure of the personal access token permits persistent out-of-band access to every Contentful space within the token's scope. This issue is fixed in @contentful/mcp-server 1.7.19 and @contentful/mcp-tools 0.4.5.
Title Contentful MCP Server: export_space/import_space tools pass LLM-controlled `host`/`proxy` args to CMA client, redirecting server PAT to attacker-controlled endpoint
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Contentful Contentful-mcp-server Mcp-tools
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T14:32:11.722Z

Reserved: 2026-06-11T15:50:01.282Z

Link: CVE-2026-53957

cve-icon Vulnrichment

Updated: 2026-09-17T14:32:00.711Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T15:17:17.367

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-53957

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T19:58:54Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)