An issue was discovered in mcp-neo4j 0.3.0 allowing attackers to obtain sensitive information or execute arbitrary commands via the SSE service. NOTE: the Supplier's position is that authentication is not mandatory for MCP servers, and the mcp-neo4j MCP server is only intended for use in a local environment where authentication realistically would not be needed. Also, the Supplier provides middleware to help isolate the MCP server from external access (if needed).
History

Tue, 16 Sep 2025 13:15:00 +0000

Type Values Removed Values Added
Description An issue was discovered in mcp-neo4j 0.3.0 allowing attackers to gain sensitive information or execute arbitrary commands via the SSE service. An issue was discovered in mcp-neo4j 0.3.0 allowing attackers to obtain sensitive information or execute arbitrary commands via the SSE service. NOTE: the Supplier's position is that authentication is not mandatory for MCP servers, and the mcp-neo4j MCP server is only intended for use in a local environment where authentication realistically would not be needed. Also, the Supplier provides middleware to help isolate the MCP server from external access (if needed).
References

Fri, 12 Sep 2025 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Neo4j
Neo4j neo4j
Neo4j-contrib
Neo4j-contrib mcp-neo4j
Vendors & Products Neo4j
Neo4j neo4j
Neo4j-contrib
Neo4j-contrib mcp-neo4j

Wed, 10 Sep 2025 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284
CWE-77
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 10 Sep 2025 14:00:00 +0000

Type Values Removed Values Added
Description An issue was discovered in mcp-neo4j 0.3.0 allowing attackers to gain sensitive information or execute arbitrary commands via the SSE service.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-09-16T12:59:07.639Z

Reserved: 2025-08-16T00:00:00.000Z

Link: CVE-2025-56406

cve-icon Vulnrichment

Updated: 2025-09-10T14:00:04.154Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-09-10T14:15:39.567

Modified: 2025-09-16T13:16:11.347

Link: CVE-2025-56406

cve-icon Redhat

No data.