Threat Advisory

MCP Import-Time Code Execution via Set Functype Version

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-59176 is a Remote Code Execution (RCE) vulnerability affecting functype-mcp-server versions <= 1.4.3 in the MCP server, allowing an attacker to execute arbitrary JavaScript in the server process via the set_functype_version tool, which requires no authentication and is enabled by default. The impact at exploitation includes confidentiality, integrity, and availability — an attacker can read secrets from the process environment, modify files, or crash the server. Any MCP client that can invoke the set_functype_version tool, including developers running functype-mcp-server in their local or CI environments as an AI coding assistant integration, users whose AI assistant is connected to this MCP server and susceptible to indirect prompt injection, and network-accessible attackers in non-default TRANSPORT_TYPE=httpStream deployments, are impacted. This flaw type allows for a high CVSS score of 7.8 due to its potential business impact on confidentiality, integrity, and availability. The attack vector involves exploiting the set_functype_version tool via unsanitized pnpm install and dynamic import, which can be triggered by a malicious document or web page read by the AI assistant. This vulnerability has significant business implications as it allows an attacker to execute arbitrary code in the server process, potentially leading to data breaches, system crashes, or unauthorized modifications of files.

RECOMMENDATION:

We recommend you to update functype-mcp-server to version 1.4.4.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-59176 is a Remote Code Execution (RCE) vulnerability affecting functype-mcp-server versions <= 1.4.3 in the MCP server, allowing an attacker to execute arbitrary JavaScript in the server process via the set_functype_version tool, which requires no authentication and is enabled by default. The impact at exploitation includes confidentiality, integrity, and availability — an attacker can read secrets from the process environment, modify files, or crash the server. Any MCP client that can invoke the set_functype_version tool, including developers running functype-mcp-server in their local or CI environments as an AI coding assistant integration, users whose AI assistant is connected to this MCP server and susceptible to indirect prompt injection, and network-accessible attackers in non-default TRANSPORT_TYPE=httpStream deployments, are impacted. This flaw type allows for a high CVSS score of 7.8 due to its potential business impact on confidentiality, integrity, and availability. The attack vector involves exploiting the set_functype_version tool via unsanitized pnpm install and dynamic import, which can be triggered by a malicious document or web page read by the AI assistant. This vulnerability has significant business implications as it allows an attacker to execute arbitrary code in the server process, potentially leading to data breaches, system crashes, or unauthorized modifications of files.

RECOMMENDATION:

We recommend you to update functype-mcp-server to version 1.4.4.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu