Get real-time updates on Telegram
CVE-2026-104634: beam_mcp 0.1.0 to before 0.10.1
Affected technology
beam_mcp · 0.1.0 to before 0.10.1
ScriptKittyOS
beam_mcp · 083838eb8e17fe5f6fcaf761bdbe203110288b0b to before 289dbdbad641943b29a3b8d1eb36506cc8cec10a
ScriptKittyOS
Component: 'Elixir.BeamMCP.Server'
Function: 'Elixir.BeamMCP.Server':handle_message/2, 'Elixir.BeamMCP.Server':normalize_arguments/2, 'Elixir.BeamMCP.Server':to_json_value/1, as
File: lib/beam_mcp/server.ex
Attack conditions (Source advisory, CVSS 4.0): Network (remote) · Low privileges required · No user interaction required
What an attacker can do
Source advisory’s CVSS 4.0 assessment (base score 2.3/10) rates confidentiality and availability impact as none; integrity impact as low. The description does not specify what an attacker can achieve beyond these rated impacts.
- CWE
- CWE-704
- KEV
- no
Provenance
- GitHub Advisory Database · Source record · observed 2026-10-08 18:27:24.781324+00:00 UTC
- NVD CVE API 2.0 · Source record · observed 2026-10-08 17:32:11.049884+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-104634.html