Security Advisory

CVE-2026-13341

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-03 10:19:10
Last updated 2026-07-06 17:29:24
Assigner Kong
CVSS score 7.4
State PUBLISHED

Description

A vulnerability exists in the Kong Konnect Model Context Protocol (MCP) server prior to version 1.0.0, which could allow a remote attacker to perform an indirect prompt injection attack and execute unintended API requests.