The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade mcp to version 1.23.0 or higher.
mcp is a Model Context Protocol SDK
Affected versions of this package are vulnerable to Insecure Default Initialization of Resource for the DNS rebinding protection that is not enabled by default for HTTP-based servers running on localhost without authentication using FastMCP. An attacker can access resources or invoke tools exposed by the local server by exploiting DNS rebinding through a malicious website.
Note:
This issue does not affect servers using stdio transport.
##Workaround
Users that can not upgrade to the fixed version are advised to explicitly configure TransportSecuritySettings when running an unauthenticated server on localhost with custom low-level server configurations using StreamableHTTPSessionManager or SseServerTransport directly.