CRLF Injection Affecting ebay-mcp package, versions <1.7.3


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.04% (13th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about CRLF Injection vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-JS-EBAYMCP-15325868
  • published23 Feb 2026
  • disclosed19 Feb 2026
  • creditnedlir

Introduced: 19 Feb 2026

NewCVE-2026-27203  (opens in a new tab)
CWE-93  (opens in a new tab)

How to fix?

Upgrade ebay-mcp to version 1.7.3 or higher.

Overview

ebay-mcp is a Local MCP server for eBay APIs - provides access to eBay developer functionality through MCP (Model Context Protocol)

Affected versions of this package are vulnerable to CRLF Injection via the updateEnvFile() function of the ebay_set_user_tokens tool. An attacker can inject arbitrary environment variables into the configuration file by supplying values containing newlines or quotes, potentially overwriting critical settings, hijacking OAuth flows, causing denial of service, or enabling remote code execution in certain environments.

References

CVSS Base Scores

version 4.0
version 3.1