VYPR

rapid7-bulk-export-mcp

by Rapid7

CVEs (1)

  • CVE-2026-97228LowSep 25, 2026
    risk 0.18cvss 2.7epss —

    Rapid7 Bulk Export MCP versions 0.2.5 through 0.6.1 suffer from a GraphQL query injection issue in the export-status component (`get_export_status` in `src/export_manager.py`), whereby the `export_id` value — an unvalidated MCP tool argument reaching the function via the…