kozou@1.6.0

Kozou CLI: scaffolding, schema introspection, and MCP server entry points.

  • latest version

    1.17.0

  • latest non vulnerable version

  • first published

    2 months ago

  • latest version published

    2 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the kozou package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Insecure Default Initialization of Resource

    kozou is a Kozou CLI: scaffolding, schema introspection, and MCP server entry points.

    Affected versions of this package are vulnerable to Insecure Default Initialization of Resource due to insufficient validation of the Host and Origin headers in the MCP HTTP server, unbounded request-body buffering, improper transaction handling for read requests, and default network exposure of unauthenticated development surfaces. An attacker can gain unauthorized access to sensitive schema metadata, execute exposed functions with elevated privileges, exhaust server memory, or perform unintended write operations by sending crafted HTTP requests or exploiting network exposure. This is only exploitable if the MCP HTTP server or Admin UI is accessible from an untrusted network, or if the opt-in call execution tool is enabled in a non-loopback or unauthenticated deployment.

    How to fix Insecure Default Initialization of Resource?

    Upgrade kozou to version 1.8.1 or higher.

    <1.8.1