Description
Improper Input Validation vulnerability in BeamMCP.Schema in ScriptKittyOS beam_mcp allows an MCP client to reach a tool's dispatch function with arguments that violate the input schema the server advertised. BeamMCP.Schema.validate/2 checked type, required, additionalProperties, enum and numeric bounds on the top-level arguments object only. Constraints inside nested objects and on array items (items, minItems, maxItems, minLength, maxLength, pattern, nested required, enum and additionalProperties: false) were advertised by tools/list and never checked at tools/call or prompts/get, and keywords outside the enforced subset (oneOf, anyOf, $ref) were advertised and ignored.

A host whose dispatch code relies on the schema it declared receives values the schema forbids, such as an out-of-range number or an undeclared key inside a nested object. What the host does with such a value decides the impact.

This issue affects beam_mcp: from 0.1.0 before 0.10.1.
Published: 2026-10-08
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Improper Input Validation
Action: Patch
AI Analysis

Impact

BeamMCP.Schema.validate/2 only verifies type, required fields, additionalProperties, enum and numeric bounds on the top‑level arguments object. Constraints that apply to nested objects or array elements—such as items, minItems, maxItems, minLength, maxLength, pattern, nested required, enum and additionalProperties: false—are advertised but never checked during tool calls. Keywords outside the enforced set, including oneOf, anyOf and $ref, are also ignored. As a result, a malicious MCP client can invoke a tool’s dispatch function with arguments that violate the advertised schema, such as out‑of‑range numbers or undeclared keys within nested structures. The host component that processes these arguments determines the final impact, which could range from a simple misuse of resources to a denial‑of‑service condition if the code is not prepared to handle unexpected input.

Affected Systems

The vulnerability affects the ScriptKittyOS beam_mcp package, specifically all releases from version 0.1.0 up to (and excluding) 0.10.1.

Risk and Exploitability

The CVSS v3 score of 5.3 indicates moderate severity, and the EPSS is not disclosed, so no concrete exploitation probability is available. The issue is not listed in CISA’s KEV catalog. Attackers need only to communicate with the beam_mcp service as a client and supply malformed arguments; no privileged credentials are required. The likelihood of exploitation depends on an attacker’s ability to reach the service and the host’s handling of out‑of‑spec data.

Generated by OpenCVE AI on October 8, 2026 at 16:28 UTC.

Remediation

Vendor Workaround

Re-validate the arguments inside the host's dispatch function against every constraint the schema declares below the top level, or move each constraint to a top-level property, which the affected versions do enforce.


OpenCVE Recommended Actions

  • Upgrade ScriptKittyOS beam_mcp to version 0.10.1 or later to receive the vendor fix that enforces all schema constraints
  • If an upgrade is not immediately possible, modify the host’s dispatch function to perform full validation of incoming arguments against the entire schema, including nested objects and array items
  • Consider disabling or restricting the use of tools that accept untrusted input until the host can enforce the full schema or until a patch is applied

Generated by OpenCVE AI on October 8, 2026 at 16:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 14:00:00 +0000

Type Values Removed Values Added
Description Improper Input Validation vulnerability in BeamMCP.Schema in ScriptKittyOS beam_mcp allows an MCP client to reach a tool's dispatch function with arguments that violate the input schema the server advertised. BeamMCP.Schema.validate/2 checked type, required, additionalProperties, enum and numeric bounds on the top-level arguments object only. Constraints inside nested objects and on array items (items, minItems, maxItems, minLength, maxLength, pattern, nested required, enum and additionalProperties: false) were advertised by tools/list and never checked at tools/call or prompts/get, and keywords outside the enforced subset (oneOf, anyOf, $ref) were advertised and ignored. A host whose dispatch code relies on the schema it declared receives values the schema forbids, such as an out-of-range number or an undeclared key inside a nested object. What the host does with such a value decides the impact. This issue affects beam_mcp: from 0.1.0 before 0.10.1.
Title beam_mcp: nested tool argument constraints advertised but not enforced
First Time appeared Scriptkittyos
Scriptkittyos beam Mcp
Weaknesses CWE-20
CPEs cpe:2.3:a:scriptkittyos:beam_mcp:*:*:*:*:*:*:*:*
Vendors & Products Scriptkittyos
Scriptkittyos beam Mcp
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Scriptkittyos Beam Mcp
cve-icon MITRE

Status: PUBLISHED

Assigner: EEF

Published:

Updated: 2026-10-08T14:09:41.540Z

Reserved: 2026-10-07T22:15:01.878Z

Link: CVE-2026-88257

cve-icon Vulnrichment

Updated: 2026-10-08T13:59:26.255Z

cve-icon NVD

Status : Received

Published: 2026-10-08T14:17:01.613

Modified: 2026-10-08T15:17:56.367

Link: CVE-2026-88257

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T16:30:05Z

Weaknesses
  • CWE-20

    Improper Input Validation