Missing Authentication for Critical Function Affecting gmaps-mcp package, versions [,0.1.3)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Missing Authentication for Critical Function vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PYTHON-GMAPSMCP-16635115
  • published11 May 2026
  • disclosed8 May 2026
  • creditUnknown

Introduced: 8 May 2026

CVE NOT AVAILABLE CWE-306  (opens in a new tab)

How to fix?

Upgrade gmaps-mcp to version 0.1.3 or higher.

Overview

gmaps-mcp is a MCP server for Google Maps — places search, directions, geocoding. Works with Claude Desktop, Cursor, Claude Code.

Affected versions of this package are vulnerable to Missing Authentication for Critical Function in the HTTP authentication process. An attacker can make unlimited API requests billed to the operator by sending unauthenticated requests to the public server endpoint. This is only exploitable if the server is deployed with the default configuration where the authentication key is unset and exposed to the internet.

CVSS Base Scores

version 4.0
version 3.1