Description
MCP Documentation Server is a local-first document management and semantic search server for AI coding agents. From 1.13.0 until 1.13.1, the automatically started Web UI in src/server.ts calls startWebServer in src/web-server.ts with START_WEB_UI enabled by default and WEB_PORT set to 3080. startWebServer uses app.listen(PORT) without a host, which binds the unauthenticated document-management API to all interfaces rather than localhost. A network-reachable client can invoke GET /api/documents, GET /api/documents/:id, POST /api/documents, POST /api/search-all, DELETE /api/documents/:id, and GET /api/config without credentials to enumerate and read documents, search the corpus, insert or delete documents, and tamper with the MCP assistant's knowledge base. The service must be reachable from the attacker's LAN, VM network, container bridge, VPN, or another routed network, and the issue does not provide remote code execution. This issue is fixed in 1.13.1.
Published: 2026-09-17
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated API Access
Action: Patch immediately
AI Analysis

Impact

The MCP Documentation Server, between releases 1.13.0 and 1.13.1, starts a Web UI that automatically binds its API to all network interfaces on port 3080 without requiring authentication. Attackers who can reach this port from a network that the server exposes—such as a local LAN, a virtual machine bridge, or a VPN—can invoke various endpoints to list, read, search, add, or delete documents, and modify the internal knowledge base, all without credentials. This flaw provides unauthorized data exposure and write capabilities, constituting a significant breach of confidentiality and integrity, but does not enable remote code execution. The weakness is attributable to improper access control (CWE‑306) and insecure default configuration (CWE‑668).

Affected Systems

The issue affects the andrea9293 MCP Documentation Server product, specifically versions 1.13.0 through 1.13.1. The vulnerability was fixed in release 1.13.1; earlier versions must be upgraded to avoid malicious exploitation.

Risk and Exploitability

With a CVSS score of 8.8 the flaw is considered high severity. The EPSS score of less than 1% indicates a very low exploitation probability under current conditions, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, because the service listens on all interfaces by default and requires no authentication, a network‑reachable attacker can easily discover and abuse the API. The attack requires no special privileges beyond access to the network segment; once the port is reachable, the attacker can enumerate and modify the document corpus without additional constraints.

Generated by OpenCVE AI on September 19, 2026 at 02:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the MCP Documentation Server to version 1.13.1 or later
  • If upgrading is not feasible, reconfigure the server to bind the Web UI to localhost only or use host‑level firewall rules to block external traffic on port 3080
  • Verify that exposed network interfaces are restricted to trusted hosts and monitor access logs for anomalous API activity

Generated by OpenCVE AI on September 19, 2026 at 02:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-6f5r-5672-72j7 @andrea9293/mcp-documentation-server: Web UI API binds to all interfaces without authentication by default
History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Andrea9293
Andrea9293 mcp-documentation-server
Vendors & Products Andrea9293
Andrea9293 mcp-documentation-server

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description MCP Documentation Server is a local-first document management and semantic search server for AI coding agents. From 1.13.0 until 1.13.1, the automatically started Web UI in src/server.ts calls startWebServer in src/web-server.ts with START_WEB_UI enabled by default and WEB_PORT set to 3080. startWebServer uses app.listen(PORT) without a host, which binds the unauthenticated document-management API to all interfaces rather than localhost. A network-reachable client can invoke GET /api/documents, GET /api/documents/:id, POST /api/documents, POST /api/search-all, DELETE /api/documents/:id, and GET /api/config without credentials to enumerate and read documents, search the corpus, insert or delete documents, and tamper with the MCP assistant's knowledge base. The service must be reachable from the attacker's LAN, VM network, container bridge, VPN, or another routed network, and the issue does not provide remote code execution. This issue is fixed in 1.13.1.
Title MCP Documentation Server: Web UI API binds to all interfaces without authentication by default
Weaknesses CWE-306
CWE-668
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Andrea9293 Mcp-documentation-server
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T19:09:50.152Z

Reserved: 2026-06-15T18:01:15.512Z

Link: CVE-2026-54504

cve-icon Vulnrichment

Updated: 2026-09-17T19:09:41.396Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T19:16:50.517

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-54504

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T02:30:17Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function

  • CWE-668

    Exposure of Resource to Wrong Sphere