CVE-2026-108698
HIGH
8,3
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
MEDIUM
6,5
Source: [email protected]
Attack Vector: network
Attack Complexity: high
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: low
Integrity: high
Availability: none
Description
AI Translation Available
hyper-mcp through 0.8.3 contains a signature verification bypass vulnerability in load_wasm in src/wasm/oci.rs that verifies the Cosign signature of a separately resolved tag rather than the loaded manifest. Attackers controlling registry responses for the tag can serve an unsigned malicious manifest to the loader and a signed one to Cosign, executing unsigned WebAssembly plugins with configured host capabilities.
367
Time-of-check Time-of-use (TOCTOU) Race Condition
IncompleteCommon Consequences
Security Scopes Affected:
Integrity
Other
Non-Repudiation
Potential Impacts:
Alter Execution Logic
Unexpected State
Modify Application Data
Modify Files Or Directories
Modify Memory
Other
Hide Activities
Applicable Platforms
All platforms may be affected
https://github.com/hyper-mcp-rs/hyper-mcp
https://github.com/hyper-mcp-rs/hyper-mcp/blob/v0.8.3/src/wasm/oci.rs#L193-L224
https://github.com/hyper-mcp-rs/hyper-mcp/blob/v0.8.3/src/wasm/oci.rs#L79-L148
https://hackmd.io/@1ExmmukzRMWN7B4gQ4W-4Q/hyper-mcp-oci-signature-manifest-toct…
https://www.vulncheck.com/advisories/hyper-mcp-through-0.8.3-oci-plugin-signatu…