Context7 MCP Server Prompt Injection Exfiltrates .env Files on a Routine Docs Lookup (CVE-2026-75130)
NVD published CVE-2026-75130 on 18 August 2026 against Upstash's Context7 through version 2.1.2: its Custom AI Instructions feature serves unsanitized content through the MCP server, so an attacker can poison the instructions to exfiltrate credentials from environment files to an attacker-controlled service and delete files, triggered when the agent makes an ordinary library documentation request. NVD carries a CVSS 4.0 base of 6.4 from VulnCheck with no vulnerability confidentiality impact but high subsequent-system confidentiality, integrity and availability impact; secondary coverage quotes a 9.0 under CVSS 3.1. Context7 is one of the most commonly installed MCP servers in coding agents, and no fix is documented.
Source
↳ Follow the thread