Skip to content

馃毃 Security: Critical or high vulnerabilities in mcp-neo4j-cypher container#840

Description

@github-actions

馃毃 Security Scan Alert

A periodic security scan found fixable critical or high severity vulnerabilities in the container image. Findings at this level also block publishing in the build workflow.

  • Image: ghcr.io/stacklok/dockyard/uvx/mcp-neo4j-cypher:0.5.3
  • Critical vulnerabilities: 1
  • High vulnerabilities: 1

Details

See the Security tab for full details.

Critical Vulnerabilities

  • GHSA-vv7q-7jx5-f767 in fastmcp@2.14.7: FastMCP OpenAPI Provider has an SSRF & Path Traversal Vulnerability

High Vulnerabilities

  • GHSA-rww4-4w9c-7733 in fastmcp@2.14.7: FastMCP: Missing Consent Verification in OAuth Proxy Callback Facilitates Confused Deputy Vulnerabilities

Automated security scan from periodic-security-scan workflow

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions