Meta Ads MCP Server Missing Authentication with Access Token Leakage
criticalAgentProtocol VulnerabilityThe Meta Ads MCP server (prior to v1.0.109) fails to enforce authentication on Streamable HTTP requests, allowing any network-reachable caller to invoke privileged Meta Ads tool handlers. When these calls fail downstream, the server leaks the operator's Meta access token by embedding it in the raw request URL returned within the JSON-RPC error response, giving attackers full account takeover potential.
Updated Aug 8, 2026 · CVSS 9.1