What happened
Two low-severity advisories (CVE-2026-88257 CVSS 5.3, CVE-2026-104634 CVSS 2.3) published 2026-10-08 via the Erlang CNA for BeamMCP: schema validation misses edge cases (type/required/additionalProperties/enum/numeric bounds) and the server coerces JSON booleans/null into strings, so tool arguments reaching host dispatch can violate the declared contract and type assumptions.
Why it matters
MCP tool-input validation is the trust boundary between an untrusted client and the host's dispatch functions; a schema that can be bypassed lets clients drive tools with unexpected values — a stepping stone to type-confusion/command-injection primitives inside MCP hosts, though the current blast radius is a niche Elixir library with no known exploit.
Attack vector
An MCP client can reach a tool's dispatch function with arguments that violate the schema the server advertised: schema validation does not fully enforce reject-additional-properties/number handling, and JSON true/false/null are converted to the strings 'true'/'false'/'nil' before reaching the host dispatch function — so a boolean/number expectation can be bypassed with unexpected types.
Affected systems
ScriptKittyOS beam_mcp (BeamMCP.Schema.validate/2 and BeamMCP.Server dispatch)
Mitigation
Update beam_mcp once fixes are released; treat schema validation as defense-in-depth and harden the host tool dispatch against unexpected argument types regardless of the advertised schema.