APIFold Vulnerable to Unauthenticated Webhook Event Injection
Description
APIFold reads an OpenAPI 3.x or Swagger 2.x specification and generates a live, production-ready MCP server endpoint. Prior to commit 7f19b52280f414f57af2b79a95333d1c8fbeece5, the /webhooks/:serverSlug/:eventName endpoint accepts arbitrary unauthenticated JSON and stores it in Redis and the webhook_events PostgreSQL table without any signature check or authentication requirement. The root cause is that createWebhookRouter is called at server.ts:188 without a validators map, so receivers.ts:80's optional-chaining guard evaluates to undefined and the signature-validation block (receiver.ts:81–95) is unconditionally skipped. Any unauthenticated network client that knows a valid server slug can inject arbitrary payloads, which are subsequently served as trusted resource state to legitimate MCP clients. Commit 7f19b52280f414f57af2b79a95333d1c8fbeece5 patches the issue.
Affected products
2Patches
Vulnerability mechanics
References
3- github.com/Work90210/APIFold/commit/7f19b52280f414f57af2b79a95333d1c8fbeece5mitrex_refsource_MISC
- github.com/Work90210/APIFold/pull/235mitrex_refsource_MISC
- github.com/Work90210/APIFold/security/advisories/GHSA-x82h-9r8v-m672mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.