CVE-2026-47769

Summary

APIFold reads an OpenAPI 3.x or Swagger 2.x specification and generates a live, production-ready MCP server endpoint. Prior to commit 7f19b52280f414f57af2b79a95333d1c8fbeece5, the /webhooks/:serverSlug/:eventName endpoint accepts arbitrary unauthenticated JSON and stores it in Redis and the webhook_events PostgreSQL table without any signature check or authentication requirement. The root cause is that createWebhookRouter is called at server.ts:188 without a validators map, so receivers.ts:80's optional-chaining guard evaluates to undefined and the signature-validation block (receiver.ts:81–95) is unconditionally skipped. Any unauthenticated network client that knows a valid server slug can inject arbitrary payloads, which are subsequently served as trusted resource state to legitimate MCP clients. Commit 7f19b52280f414f57af2b79a95333d1c8fbeece5 patches the issue.

Affected Software

VendorProductVersion RangeStatus
Work90210APIFold< 7f19b52280f414f57af2b79a95333d1c8fbeece5affected

Weaknesses

  • CWE-306: CWE-306: Missing Authentication for Critical Function

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: poc
    • Automatable: yes
    • Technical Impact: partial

References