Impact
BeamMCP.Schema.validate/2 only verifies type, required fields, additionalProperties, enum and numeric bounds on the top‑level arguments object. Constraints that apply to nested objects or array elements—such as items, minItems, maxItems, minLength, maxLength, pattern, nested required, enum and additionalProperties: false—are advertised but never checked during tool calls. Keywords outside the enforced set, including oneOf, anyOf and $ref, are also ignored. As a result, a malicious MCP client can invoke a tool’s dispatch function with arguments that violate the advertised schema, such as out‑of‑range numbers or undeclared keys within nested structures. The host component that processes these arguments determines the final impact, which could range from a simple misuse of resources to a denial‑of‑service condition if the code is not prepared to handle unexpected input.
Affected Systems
The vulnerability affects the ScriptKittyOS beam_mcp package, specifically all releases from version 0.1.0 up to (and excluding) 0.10.1.
Risk and Exploitability
The CVSS v3 score of 5.3 indicates moderate severity, and the EPSS is not disclosed, so no concrete exploitation probability is available. The issue is not listed in CISA’s KEV catalog. Attackers need only to communicate with the beam_mcp service as a client and supply malformed arguments; no privileged credentials are required. The likelihood of exploitation depends on an attacker’s ability to reach the service and the host’s handling of out‑of‑spec data.
OpenCVE Enrichment