Impact
The contentful MCP server’s export_space and import_space utilities accept host, proxy, rawProxy, and insecure options in arguments that can be influenced by a large language model (LLM). These options are merged with the server’s Contentful Management API PAT, allowing an attacker to redirect authenticated API calls to an arbitrary host or proxy. The result is persistent out‑of‑band access to every space within the token’s scope, enabling data exfiltration or modification without the knowledge of the legitimate user.
Affected Systems
Affected systems include the @contentful/mcp-server package (prior to version 1.7.19) and the @contentful/mcp-tools package (prior to version 0.4.5).
Risk and Exploitability
The vulnerability has a CVSS score of 7.7, indicating moderate to high severity. The EPSS score is less than 1%, suggesting a low likelihood of widespread exploitation in the near term, and it is not currently listed in CISA’s KEV catalog. The likely attack vector is remote, achieved through malicious LLM input or compromised Contentful content that triggers the export/import tools and manipulates the network options.
OpenCVE Enrichment
Github GHSA