MCP Salesforce Connector is a Model Context Protocol (MCP) server implementation for Salesforce integration. Prior to 0.1.10, arbitrary attribute access leads to disclosure of Salesforce auth token. This vulnerability is fixed in 0.1.10.
Metrics
Affected Vendors & Products
References
History
Mon, 09 Feb 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Smn2gnt
Smn2gnt mcp-salesforce |
|
| Vendors & Products |
Smn2gnt
Smn2gnt mcp-salesforce |
Fri, 06 Feb 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MCP Salesforce Connector is a Model Context Protocol (MCP) server implementation for Salesforce integration. Prior to 0.1.10, arbitrary attribute access leads to disclosure of Salesforce auth token. This vulnerability is fixed in 0.1.10. | |
| Title | MCP Salesforce Connector has arbitrary attribute access which leads to disclosure of Salesforce auth token | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-02-06T18:53:58.009Z
Updated: 2026-02-06T18:53:58.009Z
Reserved: 2026-02-04T05:15:41.792Z
Link: CVE-2026-25650
No data.
Status : Awaiting Analysis
Published: 2026-02-06T19:16:09.743
Modified: 2026-02-06T21:57:22.450
Link: CVE-2026-25650
No data.