VYPR

Terraform MCP Server

by Hashicorp

CVEs (3)

  • CVE-2026-16498Jul 28, 2026
    risk 0.00cvss epss 0.00

    The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant credential reuse issue in the streamable-HTTP stateless transport mode that may allow one user's Terraform token to be used to execute tool calls on behalf of subsequent users. This vulnerability,…

  • CVE-2026-16496Jul 28, 2026
    risk 0.00cvss epss 0.00

    The terraform-mcp-server before version 1.1.0 is vulnerable to an authorization bypass in the streamable-HTTP stateful transport mode that may allow a user who obtains another user's MCP session ID to have their tool calls executed using that user's Terraform credentials. This…

  • CVE-2026-14869Jul 28, 2026
    risk 0.00cvss epss 0.00

    The terraform-mcp-server before version 1.1.0 is vulnerable to a server-side request forgery issue in the streamable-HTTP transport that may allow an unauthenticated remote client to redirect the server's Terraform API requests, and the server-side authorization token, to an…