Impact
Meta Ads MCP is a Model Context Protocol server that enables AI assistants to run Meta Ads. Prior to version 1.0.115, the AuthInjectionMiddleware in meta_ads_mcp/core/http_auth_integration.py only rejects HTTP MCP requests when both auth_token and pipeboard_token are absent. In addition, extract_token_from_headers() does not treat X‑Pipeboard‑Token as a primary credential. A network caller that uses the streamable‑http transport can therefore send any X‑Pipeboard‑Token value, bypass the guard without establishing authentication context, and cause get_auth_token() to fall back to the server operator’s META_ACCESS_TOKEN. Subsequent MCP tools then execute with the operator’s Meta credentials, allowing the attacker to read or modify the operator’s Meta Ads data. This flaw is a CWE‑287 improper authentication vulnerability.
Affected Systems
The flaw affects installations of pipeboard‑co earlier than 1.0.115. Deployments that use the default stdio transport or have not defined a META_ACCESS_TOKEN are not susceptible.
Risk and Exploitability
The CVSS score of 7.4 indicates a high impact severity. The EPSS score is < 1%, meaning the likelihood of exploitation is very low. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a network-based attacker able to send a request with a crafted X‑Pipeboard‑Token header via the streamable‑http transport; the attacker need not have any prior authentication. Once the request passes the bypass, the server operates with the operator’s credentials, providing full access to Meta Ads resources.
OpenCVE Enrichment
Github GHSA