{"generated_at":"2026-10-02T01:06:38.490Z","source":{"registry":"https://registry.modelcontextprotocol.io","vulnerabilities":"https://osv.dev","namespace_verification":"https://github.com/modelcontextprotocol/registry/blob/main/docs/modelcontextprotocol-io/authentication.mdx"},"method":["We mirror the latest version of every server in the official MCP Registry.","For each server whose packages are all on npm, PyPI, NuGet or crates.io (ecosystems OSV.dev covers) with an exact version, we ask OSV.dev (querybatch) which known vulnerabilities affect each package at that exact version. If any package of a server cannot be looked up, the whole server is marked not checkable: a partial count would understate it.","Advisory ids that are aliases of the same flaw (GHSA, PYSEC, CVE) are merged, so one flaw counts once.","A scheduled job aims to re-ask OSV.dev about each server every 7 days, and sooner when the registry entry changes. The page shows the dates of the oldest and the newest check, and the date each listed server was checked.","The registry checks who may publish each name at publish time: a GitHub account for io.github.* names, a domain for the rest. That says who published, not whether the code is safe."],"limits":["Only the version the registry lists is checked. It can lag behind the newest release in the package registry.","Coverage is whatever OSV.dev knows. A vulnerability not yet recorded there is not counted.","This is not a security audit and does not read the servers' code.","The absence of a record in OSV.dev is not proof that a server is secure.","Only the package itself is looked up, not the dependencies it installs.","For servers that also offer a remote endpoint, only the published package is checked, not the hosted service.","Remote-only servers, container images (OCI), MCPB bundles and packages without an exact version cannot be checked this way. They have no count: unknown, not safe."],"data":{"total_servers":38189,"checkable":13996,"uncheckable":24193,"not_yet_checked":0,"servers_with_vulnerabilities":5,"vulnerabilities_per_server_total":75,"last_checked_at":"2026-10-01T21:53:08.456+00:00","oldest_checked_at":"2026-10-01T21:49:06.862+00:00","deprecated":454,"namespace_counts":{"github_account":25114,"domain":13075},"vulnerable_servers":[{"name":"io.github.MervinPraison/praisonai","title":"PraisonAI","repository_url":"https://github.com/MervinPraison/PraisonAI","packages":["PyPI:praisonai@2.3.42"],"vulnerabilities":65,"advisory_ids":["GHSA-2763-cj5r-c79m","GHSA-29w3-p9w9-wc47","GHSA-2g3w-cpc4-chr4","GHSA-2jgc-f764-c5r2","GHSA-2xgv-5cv2-47vv","GHSA-32vr-5gcf-3pw2","GHSA-3c4r-6p77-xwr7","GHSA-4869-x4pr-q22x","GHSA-4mr5-g6f9-cfrh","GHSA-4ph2-f6pf-79wv","GHSA-4rx4-4r3x-6534","GHSA-4wr3-f4p3-5wjh","GHSA-5c6w-wwfq-7qqm","GHSA-5cxw-77wg-jrf3","GHSA-6g6r-q6gw-w8fg","GHSA-78r8-wwqv-r299","GHSA-8444-4fhq-fxpq","GHSA-86qc-r5v2-v6x6","GHSA-8ccj-p46r-jwqq","GHSA-8frj-8q3m-xhgm","GHSA-8w9j-hc3g-3g7f","GHSA-8x8f-54wf-vv92","GHSA-98f9-fqg5-hvq5","GHSA-9cq8-3v94-434g","GHSA-9cr9-25q5-8prj","GHSA-9mqq-jqxf-grvw","GHSA-9q28-ghcr-c4x3","GHSA-9qhq-v63v-fv3j","GHSA-cfg2-mxfj-j6pw","GHSA-cfh6-vr3j-qc3g","GHSA-ch89-h4r2-c8f8","GHSA-f292-66h9-fpmf","GHSA-f2h6-7xfr-xm8w","GHSA-fq2m-6wqh-x44g","GHSA-fvxx-ggmx-3cjg","GHSA-g985-wjh9-qxxc","GHSA-gcq3-mfvh-3x25","GHSA-gfq8-hmph-9gjv","GHSA-gmjg-hv98-qggq","GHSA-hmfx-4v44-9qw9","GHSA-hvhp-v2gc-268q","GHSA-hwg5-x759-7wjg","GHSA-j4hj-7hfh-g2f4","GHSA-jfxc-v5g9-38xr","GHSA-p4pj-vh7h-6cqh","GHSA-p75f-6fp4-p57w","GHSA-pj2r-f9mw-vrcq","GHSA-pm96-6xpr-978x","GHSA-pv9q-275h-rh7x","GHSA-pvph-5j39-v8qc","GHSA-pvxx-r596-f5qj","GHSA-q5r4-47m9-5mc7","GHSA-qwgj-rrpj-75xm","GHSA-r4f2-3m54-pp7q","GHSA-r7v3-x45f-g7hp","GHSA-r9x3-wx45-2v7f","GHSA-rg3h-x3jw-7jm5","GHSA-rg5q-pp8p-f7jm","GHSA-vc46-vw85-3wvm","GHSA-vg22-4gmj-prxw","GHSA-wj6g-v78p-6fx3","GHSA-wv94-5qcp-6m36","GHSA-x6m9-gxvr-7jpv","GHSA-x783-xp3g-mqhp","GHSA-x92v-rpx6-p6cw","PYSEC-2026-2895","PYSEC-2026-2896","PYSEC-2026-2898","PYSEC-2026-2899","PYSEC-2026-2900","PYSEC-2026-2901","PYSEC-2026-2902","PYSEC-2026-2903","PYSEC-2026-2905","PYSEC-2026-2906","PYSEC-2026-2907","PYSEC-2026-2908","PYSEC-2026-2909","PYSEC-2026-2910","PYSEC-2026-2911","PYSEC-2026-2912","PYSEC-2026-2913","PYSEC-2026-2914","PYSEC-2026-2915","PYSEC-2026-2916","PYSEC-2026-2917","PYSEC-2026-2918","PYSEC-2026-2919","PYSEC-2026-2920","PYSEC-2026-2921","PYSEC-2026-2922","PYSEC-2026-2923","PYSEC-2026-2924","PYSEC-2026-2925","PYSEC-2026-3500","PYSEC-2026-3501","PYSEC-2026-3508","PYSEC-2026-3511","PYSEC-2026-3512","PYSEC-2026-3513","PYSEC-2026-3516","PYSEC-2026-3517","PYSEC-2026-3523","PYSEC-2026-3885","PYSEC-2026-3886","PYSEC-2026-3888","PYSEC-2026-3889","PYSEC-2026-3890","PYSEC-2026-3892","PYSEC-2026-3893","PYSEC-2026-3894","PYSEC-2026-3895","PYSEC-2026-3896","PYSEC-2026-3897","PYSEC-2026-461","PYSEC-2026-462","PYSEC-2026-463","PYSEC-2026-465","PYSEC-2026-466","PYSEC-2026-467","PYSEC-2026-468","PYSEC-2026-470","PYSEC-2026-472","PYSEC-2026-473","PYSEC-2026-474","PYSEC-2026-475","PYSEC-2026-476","PYSEC-2026-477","PYSEC-2026-478"],"checked_at":"2026-10-01T21:52:12.378+00:00"},{"name":"io.github.flytohub/flyto-core","title":"Flyto Core","repository_url":"https://github.com/flytohub/flyto-core","packages":["PyPI:flyto-core@2.12.6"],"vulnerabilities":7,"advisory_ids":["GHSA-2956-977x-2w3r","GHSA-794r-5rp2-fpg8","GHSA-c9hr-64h3-gxpc","GHSA-hr7p-wg7r-hg9m","GHSA-pgwh-4jj4-qm8v","GHSA-qq9q-xgm3-xv9g","PYSEC-2026-2481","PYSEC-2026-3568","PYSEC-2026-3569","PYSEC-2026-3570","PYSEC-2026-3571","PYSEC-2026-3572","PYSEC-2026-3573"],"checked_at":"2026-10-01T21:51:44.758+00:00"},{"name":"io.github.agenticmail/mcp","title":null,"repository_url":"https://github.com/agenticmail/agenticmail","packages":["npm:@agenticmail/mcp@0.5.59"],"vulnerabilities":1,"advisory_ids":["GHSA-63gr-g7jc-v8rg"],"checked_at":"2026-10-01T21:51:14.369+00:00"},{"name":"io.github.bx33661/wireshark-mcp","title":null,"repository_url":"https://github.com/bx33661/Wireshark-MCP","packages":["PyPI:wireshark-mcp@0.6.5"],"vulnerabilities":1,"advisory_ids":["GHSA-3r68-x3xc-rxpg","PYSEC-2026-3426"],"checked_at":"2026-10-01T21:51:22.402+00:00"},{"name":"io.github.neo4j-contrib/mcp-neo4j-cypher","title":null,"repository_url":"https://github.com/neo4j-contrib/mcp-neo4j","packages":["PyPI:mcp-neo4j-cypher@0.5.1"],"vulnerabilities":1,"advisory_ids":["GHSA-x3cv-r3g3-fpg9","PYSEC-2026-2626"],"checked_at":"2026-10-01T21:52:21.318+00:00"}]}}