0.1.3
1 months ago
19 days ago
Known vulnerabilities in the gmaps-mcp package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
gmaps-mcp is a MCP server for Google Maps — places search, directions, geocoding. Works with Claude Desktop, Cursor, Claude Code. Affected versions of this package are vulnerable to Missing Authentication for Critical Function in the HTTP authentication process. An attacker can make unlimited API requests billed to the operator by sending unauthenticated requests to the public server endpoint. This is only exploitable if the server is deployed with the default configuration where the authentication key is unset and exposed to the internet. How to fix Missing Authentication for Critical Function? Upgrade | [,0.1.3) |