VYPR

hyper-mcp

by Hyper Mcp Rs

CVEs (2)

  • CVE-2026-108699MedOct 11, 2026
    risk 0.42cvss 6.5epss —

    hyper-mcp through 0.8.3 contains an improper signature verification vulnerability that allows attackers to load malicious WebAssembly plugins because cosign_verify_args() accepts any signer identity and OIDC issuer by default. Attackers controlling a plugin image reference can…

  • CVE-2026-108698MedOct 11, 2026
    risk 0.42cvss 6.5epss —

    hyper-mcp through 0.8.3 contains a signature verification bypass vulnerability in load_wasm in src/wasm/oci.rs that verifies the Cosign signature of a separately resolved tag rather than the loaded manifest. Attackers controlling registry responses for the tag can serve an…