MCP Salesforce Connector is a Model Context Protocol (MCP) server implementation for Salesforce integration. Prior to 0.1.10, arbitrary attribute access leads to disclosure of Salesforce auth token. This vulnerability is fixed in 0.1.10.
Metrics
Affected Vendors & Products
References
History
Mon, 09 Feb 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 09 Feb 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Smn2gnt
Smn2gnt mcp-salesforce |
|
| Vendors & Products |
Smn2gnt
Smn2gnt mcp-salesforce |
Fri, 06 Feb 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MCP Salesforce Connector is a Model Context Protocol (MCP) server implementation for Salesforce integration. Prior to 0.1.10, arbitrary attribute access leads to disclosure of Salesforce auth token. This vulnerability is fixed in 0.1.10. | |
| Title | MCP Salesforce Connector has arbitrary attribute access which leads to disclosure of Salesforce auth token | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-02-09T15:28:43.765Z
Reserved: 2026-02-04T05:15:41.792Z
Link: CVE-2026-25650
Updated: 2026-02-09T15:22:03.695Z
Status : Awaiting Analysis
Published: 2026-02-06T19:16:09.743
Modified: 2026-02-06T21:57:22.450
Link: CVE-2026-25650
No data.