VYPR

claude-code-action

by GitHub Actions

CVEs (1)

  • CVE-2026-47751Jun 10, 2026
    risk 0.00cvss epss

    Due to the combination of checking out PR head branches (attacker-controlled), reading `.mcp.json` from the working directory via default setting sources, and unconditionally enabling all project MCP servers via `enableAllProjectMcpServers`, it was possible for an attacker who…