pipeboard-co disclosed and fixed a critical vulnerability in meta-ads-mcp that allowed unauthenticated users to execute MCP tools over HTTP and potentially obtain the operator’s Meta access token. The issue, tracked as GHSA-9gw6-46qc-99vr, affected version 1.0.101 and earlier, particularly in self-hosted deployments using --transport streamable-http on a network-reachable port. The flaw stemmed from authentication middleware forwarding requests without enforcing authorization, allowing downstream handlers to run with the server’s META_ACCESS_TOKEN when no per-request credential was supplied.
The advisory said a second bug in api.py appended the token to Meta Graph API request URLs and returned the raw request_url in JSON-RPC error responses, creating a direct token leakage path. A proof of concept showed an unauthenticated POST to /mcp returning 200 OK and exposing the access_token after a Graph API error. Release 1.0.109 changes unauthenticated behavior to return 401 Unauthorized with a WWW-Authenticate: Bearer header, redacts access_token and appsecret_proof from Graph API error payloads, and adds SECURITY.md. Operators were urged to upgrade immediately, rotate Meta access tokens if vulnerable instances were exposed to untrusted networks, and review Graph API access logs for misuse.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
The vulnerability previously tracked as GHSA-9gw6-46qc-99vr was published as CVE-2026-48039, covering unauthenticated HTTP MCP tool execution and leakage of the operator's Meta access token in meta-ads-mcp versions before 1.0.109. The CVE assigned a CVSS 3.1 score of 9.1 (Critical) and mapped the issue to CWE-287.
Release 1.0.109 fixed GHSA-9gw6-46qc-99vr by changing HTTP middleware so unauthenticated requests return 401 instead of reaching tool handlers. The release also redacted access_token and appsecret_proof from Graph API error payloads and added a SECURITY.md file.
A GitHub security advisory disclosed GHSA-9gw6-46qc-99vr affecting meta-ads-mcp version 1.0.101 and earlier. The advisory described unauthenticated HTTP MCP tool execution that could leak the operator’s Meta access token and enable attacker actions against connected ad accounts.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.