What happened
VulnCheck published CVE-2026-108698 (published 2026-10-11, CVSS 6.5, CWE-367) for hyper-mcp ≤ 0.8.3: the OCI plugin loader has a signature-verification TOCTOU so a tampered registry can cause unsigned WebAssembly plugins to run. Verified against NVD REST API; companion issue CVE-2026-108699 covers permissive default signer/issuer acceptance.
Why it matters
hyper-mcp loads WebAssembly plugins into MCP servers; breaking plugin signature integrity means an attacker who controls a plugin image reference can execute arbitrary WASM with the capabilities granted to plugins — a code-execution path in the agent tooling supply chain that defeats the signed-plugin trust model.
Attack vector
load_wasm in src/wasm/oci.rs verifies the Cosign signature of a separately resolved tag rather than the actual loaded manifest; a registry that serves an unsigned malicious manifest to the loader and a signed one to Cosign (CWE-367 TOCTOU) bypasses signature verification, executing attacker WASM with configured host capabilities.
Affected systems
hyper-mcp (cargo) through 0.8.3
Mitigation
Upgrade past 0.8.3 and pin/verify plugin image references; restrict registry access and host capabilities granted to WASM plugins. Advisory: https://www.vulncheck.com/advisories/hyper-mcp-through-0.8.3-oci-plugin-signature-verification-toctou-race-condition