CVE-2026-13341Disclosure

LOWCVSS 7.4 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability exists in the Kong Konnect Model Context Protocol (MCP) server prior to version 1.0.0, which could allow a remote attacker to perform an indirect prompt injection attack and execute unintended API requests.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-07-03); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-07-03: 1Mentions · 2026-07-05: 1Mentions · 2026-07-07: 1Patch / Workaround · 2026-07-07: 1Technical Details · 2026-07-03: 1Technical Details · 2026-07-05: 1Technical Details · 2026-07-07: 107-0307-0507-07
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-07-031
Disclosure1
2026-07-051
Disclosure1
2026-07-071
Patch1
Full discourse3 posts
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨High - Kong Konnect MCP Server Indirect Prompt Injection (CVE-2026-13341) Kong's mcp-konnect MCP server — which lets an AI agent query and manage Kong Konnect API resources — fails to properly validate the content it returns to the LLM (CWE-20). An attacker who plants malicious text inside data the agent later reads can smuggle in instructions the model treats as its own. The result is an indirect prompt injection: the agent can be steered into making unintended API requests against Konnect under its own permissions, potentially exposing sensitive data. No direct access to the LLM prompt is required — only that the poisoned data gets read. 👉Affected: Kong mcp-konnect < 1.0.0

    Post summary

    Kong's mcp-konnect MCP server suffers a high‑severity indirect prompt injection flaw (CVE‑2026‑13341) due to improper content validation, but no PoC, exploit, or patch is noted.

    20020158
    296 followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH SEVERITY: CVE-2026-13341 (CVSS 7.4) Kong Konnect MCP server &lt;1.0.0 vulnerable to indirect prompt injection → unintended API execution. Update to v1.0.0+ immediately. #CVE #Vulnerability #PatchNow https://t.co/UdXBvz5Z4V

    Post summary

    A high‑severity advisory urges users of Kong Konnect MCP server to upgrade to v1.0.0+ to mitigate a prompt injection vulnerability (CVE‑2026‑13341).

    0000070
    66 followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Disclosure

    #CVE-2026-13341 - Unauthorized access in Kong Konnect MCP server. Indirect prompt injection could lead to unintended #API requests. #CVSS 7.4. No patch yet. Monitor and mitigate immediately. #developers #Kong #infosec #devsecops #devops #infosec #cybersecuritytips More: https://www.valtersit.com/cve/CVE-2026-13341/

    Post summary

    The post discloses CVE-2026-13341, a CVSS 7.4 vulnerability in Kong Konnect MCP that allows indirect prompt injection and unauthorized API requests; no patch is available yet, so monitoring and mitigation are advised.

    0000064
    972 followersView on X

Explore more