Vulnerability  ·  2026-10-12

hyper-mcp: TOCTOU Cosign signature-verification bypass lets unsigned WASM MCP plugins execute (CVSS 6.5)

VulnerabilityHigh impactGlobalCVE-2026-108698
VulnCheck published CVE-2026-108698 (published 2026-10-11, CVSS 6.5, CWE-367) for hyper-mcp ≤ 0.8.3: the OCI plugin loader has a signature-verification TOCTOU so a tampered registry can cause unsigned WebAssembly plugins to run. Verified against NVD REST API; companion issue CVE-2026-108699 covers permissive default signer/issuer acceptance.
hyper-mcp loads WebAssembly plugins into MCP servers; breaking plugin signature integrity means an attacker who controls a plugin image reference can execute arbitrary WASM with the capabilities granted to plugins — a code-execution path in the agent tooling supply chain that defeats the signed-plugin trust model.
load_wasm in src/wasm/oci.rs verifies the Cosign signature of a separately resolved tag rather than the actual loaded manifest; a registry that serves an unsigned malicious manifest to the loader and a signed one to Cosign (CWE-367 TOCTOU) bypasses signature verification, executing attacker WASM with configured host capabilities.
hyper-mcp (cargo) through 0.8.3
Upgrade past 0.8.3 and pin/verify plugin image references; restrict registry access and host capabilities granted to WASM plugins. Advisory: https://www.vulncheck.com/advisories/hyper-mcp-through-0.8.3-oci-plugin-signature-verification-toctou-race-condition
NVD CVE-2026-108698VulnCheck advisory
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →