An issue was discovered in mcp-neo4j 0.3.0 allowing attackers to obtain sensitive information or execute arbitrary commands via the SSE service. NOTE: the Supplier's position is that authentication is not mandatory for MCP servers, and the mcp-neo4j MCP server is only intended for use in a local environment where authentication realistically would not be needed. Also, the Supplier provides middleware to help isolate the MCP server from external access (if needed).
Metrics
Affected Vendors & Products
References
History
Tue, 16 Sep 2025 13:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An issue was discovered in mcp-neo4j 0.3.0 allowing attackers to gain sensitive information or execute arbitrary commands via the SSE service. | An issue was discovered in mcp-neo4j 0.3.0 allowing attackers to obtain sensitive information or execute arbitrary commands via the SSE service. NOTE: the Supplier's position is that authentication is not mandatory for MCP servers, and the mcp-neo4j MCP server is only intended for use in a local environment where authentication realistically would not be needed. Also, the Supplier provides middleware to help isolate the MCP server from external access (if needed). |
References |
|
Fri, 12 Sep 2025 09:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Neo4j
Neo4j neo4j Neo4j-contrib Neo4j-contrib mcp-neo4j |
|
Vendors & Products |
Neo4j
Neo4j neo4j Neo4j-contrib Neo4j-contrib mcp-neo4j |
Wed, 10 Sep 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-200 CWE-284 CWE-77 |
|
Metrics |
cvssV3_1
|
Wed, 10 Sep 2025 14:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An issue was discovered in mcp-neo4j 0.3.0 allowing attackers to gain sensitive information or execute arbitrary commands via the SSE service. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-09-16T12:59:07.639Z
Reserved: 2025-08-16T00:00:00.000Z
Link: CVE-2025-56406

Updated: 2025-09-10T14:00:04.154Z

Status : Awaiting Analysis
Published: 2025-09-10T14:15:39.567
Modified: 2025-09-16T13:16:11.347
Link: CVE-2025-56406

No data.