
🚨High - Kong Konnect MCP Server Indirect Prompt Injection (CVE-2026-13341) Kong's mcp-konnect MCP server — which lets an AI agent query and manage Kong Konnect API resources — fails to properly validate the content it returns to the LLM (CWE-20). An attacker who plants malicious text inside data the agent later reads can smuggle in instructions the model treats as its own. The result is an indirect prompt injection: the agent can be steered into making unintended API requests against Konnect under its own permissions, potentially exposing sensitive data. No direct access to the LLM prompt is required — only that the poisoned data gets read. 👉Affected: Kong mcp-konnect < 1.0.0
Post summary
Kong's mcp-konnect MCP server suffers a high‑severity indirect prompt injection flaw (CVE‑2026‑13341) due to improper content validation, but no PoC, exploit, or patch is noted.


