VYPR

BeamMCP.Server

by ScriptKittyOS

CVEs (1)

  • CVE-2026-104634LowOct 8, 2026
    risk 0.08cvss —epss —

    Incorrect Type Conversion or Cast vulnerability in BeamMCP.Server in ScriptKittyOS beam_mcp allows an MCP client's JSON true, false and null tool arguments to reach the host's dispatch function as the strings "true", "false" and "nil". After BeamMCP.Schema.validate/2 accepted a…