What happened
Verified via NVD REST API (published 2026-10-09): a native Model Context Protocol plugin for the x64dbg debugger ships CWE-306 missing authentication. Prior to v1.1 it exposes all MCP debugger tools over HTTP and SSE without authentication while listening on 0.0.0.0 by default, so any unauthenticated network client can execute arbitrary x64dbg commands, attach to processes, and read/write debuggee memory and files.
Why it matters
This is a textbook agentic-tool-surface compromise: the MCP server is the interface an AI coding/debugging agent uses to drive the debugger. Combined with prompt-injection on the agent side, an internet-reachable instance hands an attacker a remote, root-equivalent code-execution and process-manipulation primitive on the analyst/malware-reversing workstation — critical severity (CVSS 9.3) with zero authentication.
Attack vector
No credentials or user interaction: an unauthenticated network client connects to the MCP HTTP/SSE port and invokes any MCP debugger tool to execute arbitrary x64dbg commands, attach to processes by PID, read/write debuggee memory, and write files to arbitrary paths on the host.
Affected systems
x64dbg-mcp-server < 1.1 (native MCP plugin for x64dbg on Windows; listens on 0.0.0.0:9094 x64 / 9095 x32 by default)
Mitigation
Upgrade to version 1.1 (or 1.2 for the DoS fix). Do not expose the MCP port beyond localhost; restrict network access and require authentication. Advisory: https://github.com/duty1g/x64dbg-mcp-server/security/advisories/GHSA-4478-h5jv-647m