Network-AI MCP SSE Server Default-Empty-Secret Authentication Bypass with Wildcard CORS
highAgentProtocol VulnerabilityNetwork-AI's MCP SSE server ships with an empty default authentication secret, meaning every request is treated as authorized regardless of whether an Authorization header is present. Combined with a wildcard CORS policy on all responses, this lets a malicious webpage silently invoke any of the 22 exposed MCP tools on a victim's local server, including spawning agents and writing to shared blackboard state. This is a classic drive-by CSRF-style attack against a locally running privileged agent orchestrator.
Updated Jul 20, 2026 · CVSS 7.6