Unrated severityNVD Advisory· Published Jul 3, 2026· Updated Jul 6, 2026
Prompt Injection and Credential Exposure via Untrusted Analytics Data in Kong Konnect MCP
CVE-2026-13341
Description
A vulnerability exists in the Kong Konnect Model Context Protocol (MCP) server prior to version 1.0.0, which could allow a remote attacker to perform an indirect prompt injection attack and execute unintended API requests.
Affected products
1- Range: <1.0.0
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.