Get real-time updates on Telegram
CVE-2026-88257: beam_mcp 0.1.0 to before 0.10.1
Affected technology
beam_mcp · 0.1.0 to before 0.10.1
ScriptKittyOS
beam_mcp · 083838eb8e17fe5f6fcaf761bdbe203110288b0b to before 289dbdbad641943b29a3b8d1eb36506cc8cec10a
ScriptKittyOS
Component: 'Elixir.BeamMCP.Schema', 'Elixir.BeamMCP.Server'
Function: 'Elixir.BeamMCP.Schema':validate/2, 'Elixir.BeamMCP.Server':handle_message/2, with
File: lib/beam_mcp/schema.ex, lib/beam_mcp/server.ex
Attack conditions (Source advisory, CVSS 4.0): Network (remote) · Low privileges required · No user interaction required
What an attacker can do
Source advisory’s CVSS 4.0 assessment (base score 5.3/10) rates confidentiality and availability impact as none; integrity impact as low. The description does not specify what an attacker can achieve beyond these rated impacts.
- CWE
- CWE-20
- KEV
- no
Provenance
- GitHub Advisory Database · Source record · observed 2026-10-08 18:27:24.781324+00:00 UTC
- NVD CVE API 2.0 · Source record · observed 2026-10-08 17:32:11.049884+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-88257.html