CVE-2026-75130Disclosure

LOWCVSS 6.4 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Context7 through 2.1.2 contains a prompt injection vulnerability that allows attackers to execute malicious instructions in connected AI coding agents by injecting unsanitized content through the Custom AI Instructions feature served via the MCP server. Attackers can poison the custom instructions to exfiltrate credentials from environment files to an attacker-controlled service and perform destructive file deletion on the victim's machine when the agent makes a routine library documentation request.

2.0/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-08-24); latest day: 1
  • 5 total mentions across 4 days

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-08-19: 1Mentions · 2026-08-21: 1Mentions · 2026-08-24: 2Mentions · 2026-08-26: 1PoC Mentioned / Linked · 2026-08-24: 1Patch / Workaround · 2026-08-21: 1Technical Details · 2026-08-21: 1Technical Details · 2026-08-24: 2Technical Details · 2026-08-26: 108-1908-2108-2408-26
Signal classification2 categories
Disclosure
360.0%
General
240.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-08-191
General1
2026-08-211
Disclosure1
2026-08-242
Disclosure1General1
2026-08-261
Disclosure1
Full discourse5 posts
  • Sebastien Gioria@SPoint
    Disclosure

    CVE-2026-75130 : le serveur MCP Context7 (doc pour agents de code) injecte des instructions non filtrées dans votre contexte. 9.0 en CVSS 3.1, 6.4 en CVSS 4.0. 📖 Blog : https://blog.gioria.org/fr/ai-security/context7-mcp-cve-2026-75130-prompt-injection/?utm_source=twitter&utm_medium=post&utm_campaign=context7-mcp-cve-2026-75130-prompt-injection 📬 Substack : https://sgioria.substack.com/p/cve-2026-75130-le-serveur-mcp-que?utm_source=twitter&utm_medium=post&utm_campaign=context7-mcp-cve-2026-75130-prompt-injection #MCP #PromptInjection

    Post summary

    An announcement detailing a prompt injection flaw in MCP Context7 (CVE-2026-75130) with accompanying CVSS scores, but no PoC, exploit code, or patch information is provided.

    00011149
    2.3K followersView on X
  • Innora.ai@Innora_sg
    Disclosure

    CVE-2026-75130: Context7's MCP tools resolve-library-id/query-docs serve Custom AI Instructions verbatim — no sanitization. Poison the library → IDE agent executes. Through 2.1.2; production sanitization 2026-02-23. Found by Eli Ainhorn, Noma Security. #CVE #MCP #AppSec #InfoSec https://t.co/aZhbKJtXpv

    Post summary

    The tweet discloses that Context7's MCP tools lack sanitization of AI instructions, enabling malicious execution via library poisoning; a patch is scheduled for February 23, 2026.

    0002092
    26 followersView on X
  • Arun Tikaram@aruntikaram
    Disclosure

    CVSS 9.0. Published August 18. Still no fix as of August 22. CVE-2026-75130 lets attackers inject instructions into Context7's MCP server — used in Cursor, Claude Code, Windsurf — through a routine doc lookup. http://www.digitalapplied.com/blog/context7-mcp-prompt-injection-cve-2026-75130

    Post summary

    CVE-2026-75130 is a high‑severity injection flaw in Context7's MCP server with no patch available yet, and a linked blog post likely contains a PoC.

    00010103
    161 followersView on X
  • David Mytton@davidmytton
    General

    Every input/output has to be treated as untrusted, even (especially) MCP = CVE-2026-75130 https://github.com/advisories/GHSA-97r6-3rgm-v39r

    Post summary

    The message notes that all input/output should be treated as untrusted in the context of CVE‑2026‑75130, but provides no PoC, exploit, patch, or detailed technical description.

    00010220
    3.2K followersView on X
  • Vikram Jha@invinciblejha
    General

    CVE-2026-75130: a prompt-injection flaw in one of the most-installed MCP servers, Upstash Context7 (v2.1.2 and earlier), carrying two official severities that disagree by a full class — 9.0 Critical under CVSS 3.1 versus 6.4 Medium under CVSS 4.0 (CVE record, CNA VulnCheck). The industry cannot agree what an agent-context injection is worth. That split is the story, not the patch.

    Post summary

    The post highlights a CVE with conflicting severity ratings but does not provide a PoC, exploit, or patch, focusing solely on the controversy surrounding its impact.

    00000149
    3.2K followersView on X

Explore more