Snyk has a proof-of-concept or detailed explanation of how to exploit this vulnerability.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade arcade-mcp-server to version 1.9.1 or higher.
arcade-mcp-server is a Model Context Protocol (MCP) server framework for Arcade.dev
Affected versions of this package are vulnerable to Use of Hard-coded Cryptographic Key via the HTTP server uses a hardcoded default worker secret ("dev") that is never validated or overridden during normal server startup. An attacker can gain unauthorized access to all HTTP worker endpoints by forging valid JWTs using the known default secret.