Vulnerability  ·  2026-10-09

BeamMCP (Elixir) MCP server schema-validation and type-conversion gap lets clients pass non-conforming tool arguments

VulnerabilityLow impactGlobalCVE-2026-88257
Two low-severity advisories (CVE-2026-88257 CVSS 5.3, CVE-2026-104634 CVSS 2.3) published 2026-10-08 via the Erlang CNA for BeamMCP: schema validation misses edge cases (type/required/additionalProperties/enum/numeric bounds) and the server coerces JSON booleans/null into strings, so tool arguments reaching host dispatch can violate the declared contract and type assumptions.
MCP tool-input validation is the trust boundary between an untrusted client and the host's dispatch functions; a schema that can be bypassed lets clients drive tools with unexpected values — a stepping stone to type-confusion/command-injection primitives inside MCP hosts, though the current blast radius is a niche Elixir library with no known exploit.
An MCP client can reach a tool's dispatch function with arguments that violate the schema the server advertised: schema validation does not fully enforce reject-additional-properties/number handling, and JSON true/false/null are converted to the strings 'true'/'false'/'nil' before reaching the host dispatch function — so a boolean/number expectation can be bypassed with unexpected types.
ScriptKittyOS beam_mcp (BeamMCP.Schema.validate/2 and BeamMCP.Server dispatch)
Update beam_mcp once fixes are released; treat schema validation as defense-in-depth and harden the host tool dispatch against unexpected argument types regardless of the advertised schema.
Erlang CNA — CVE-2026-88257NVD — CVE-2026-104634
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →