CVE-2026-97228

LOWCVSS 2.7 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Rapid7 Bulk Export MCP versions 0.2.5 through 0.6.1 suffer from a GraphQL query injection issue in the export-status component (`get_export_status` in `src/export_manager.py`), whereby the `export_id` value — an unvalidated MCP tool argument reaching the function via the `check_rapid7_export_status` and `download_rapid7_export` tools — is interpolated directly into the GraphQL query string. A crafted `export_id` containing quote and brace characters can terminate the intended `export(id: "...")` selection early and append attacker-controlled root-level selections (for example, schema introspection), producing a single well-formed GraphQL document that is then sent to the Rapid7 export API under the operator's own API key. Notably, this issue does not grant an existing actor any access they do not already have: every injected query executes within the operator's own already-authenticated API scope, using the operator's own valid API key, and cannot cross a tenant or account boundary. A directly-malicious operator gains nothing they could not already do by calling the API directly; the realistic exposure is limited to a compromised or careless upstream MCP client, or indirect prompt injection forwarding an unvalidated identifier. This is fixed in version 0.6.2, which passes `export_id` as a parameterized GraphQL variable (`$exportId: ID!`).

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-943

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-06: 110-06
Full discourse1 post
  • TechSignal@tchsignal

    MCP Security Risks Grow as AI Agents Start Trusting Other Agents A newly examined set of vulnerabilities shows why AI-agent security becomes harder when one system starts trusting another. Google's MCP Toolbox for Databases had an SSRF flaw, CVE-2026-14540, rated 8.0 High by Google and fixed through an SSRF guard in version 1.5.0. Rapid7's Bulk Export MCP separately had a low-severity GraphQL query-injection flaw, CVE-2026-97228, fixed in version 0.6.2. These are different implementation bugs, not proof that MCP itself contains one universal vulnerability. The broader concern is how agents, tools and protocols are chained together. Researcher Syed Anas Mohiuddin describes one such cross-protocol pattern as Protocol Pivoting: malicious instructions can enter one agent, pass through MCP tool use or another delegation layer, and reach downstream agents that may inherit too much trust. NSA and Microsoft have separately warned about related risks including prompt injection, unsafe tool chaining and insufficient policy enforcement around agent actions. The security challenge is therefore larger than patching individual CVEs. As multi-agent systems become more interconnected, each trust boundary must be validated rather than assumed. #MCP #AISecurity

    5000081
    38 followersView on X

Explore more