Vulnerability  ·  2026-09-26

Rapid7 Bulk Export MCP GraphQL query injection in export-status component (CVE-2026-97228)

VulnerabilityLow impactGlobalCVE-2026-97228
Rapid7 fixed a GraphQL query injection in the Bulk Export MCP server's export-status component (published 24 Sept 2026), where an unvalidated MCP tool argument flows into a GraphQL query.
Precision item: MCP tool arguments flowing unsanitized into backend queries is the recurring agent-tool injection pattern; here it reaches a GraphQL data-export API.
The get_export_status MCP tool passes an unvalidated export_id argument into a GraphQL query (export_status in src/export_manager.py), enabling GraphQL query injection through the check_rapid7_export_status path.
Rapid7 Bulk Export MCP versions 0.2.5-0.6.1 (fixed 0.6.2)
Upgrade to rapid7-bulk-export-mcp >= 0.6.2 (release tag v0.6.2).
NVD CVE-2026-97228Rapid7 release v0.6.2
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →