Impact
The MCP Documentation Server, between releases 1.13.0 and 1.13.1, starts a Web UI that automatically binds its API to all network interfaces on port 3080 without requiring authentication. Attackers who can reach this port from a network that the server exposes—such as a local LAN, a virtual machine bridge, or a VPN—can invoke various endpoints to list, read, search, add, or delete documents, and modify the internal knowledge base, all without credentials. This flaw provides unauthorized data exposure and write capabilities, constituting a significant breach of confidentiality and integrity, but does not enable remote code execution. The weakness is attributable to improper access control (CWE‑306) and insecure default configuration (CWE‑668).
Affected Systems
The issue affects the andrea9293 MCP Documentation Server product, specifically versions 1.13.0 through 1.13.1. The vulnerability was fixed in release 1.13.1; earlier versions must be upgraded to avoid malicious exploitation.
Risk and Exploitability
With a CVSS score of 8.8 the flaw is considered high severity. The EPSS score of less than 1% indicates a very low exploitation probability under current conditions, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, because the service listens on all interfaces by default and requires no authentication, a network‑reachable attacker can easily discover and abuse the API. The attack requires no special privileges beyond access to the network segment; once the port is reachable, the attacker can enumerate and modify the document corpus without additional constraints.
OpenCVE Enrichment
Github GHSA