Medium severity6.5NVD Advisory· Published Oct 11, 2026
CVE-2026-108699
CVE-2026-108699
Description
hyper-mcp through 0.8.3 contains an improper signature verification vulnerability that allows attackers to load malicious WebAssembly plugins because cosign_verify_args() accepts any signer identity and OIDC issuer by default. Attackers controlling a plugin image reference can sign a malicious image with a free Sigstore keyless certificate to execute plugins with configured host, filesystem, and environment capabilities.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <=0.8.3
Patches
Vulnerability mechanics
References
4- github.com/hyper-mcp-rs/hyper-mcp/blob/v0.8.3/src/config.rsnvd
- github.com/hyper-mcp-rs/hyper-mcp/blob/v0.8.3/src/wasm/oci.rsnvd
- hackmd.io/@1ExmmukzRMWN7B4gQ4W-4Q/hyper-mcp-oci-signature-manifest-toctounvd
- www.vulncheck.com/advisories/hyper-mcp-through-0.8.3-improper-signature-verification-of-oci-webassembly-pluginsnvd
News mentions
0No linked articles in our index yet.