Skip to content
Original
Permission Protocol · AI Agent Incident Tracker·· 08/18/2026SelectedAI score78

Context7 MCP custom AI instruction prompt injection can leak credentials and delete files

Original title: Context7 MCP Custom AI Instructions Prompt Injection Can Drive Credential Exfiltration and Destructive File Deletion

AI overview

Context7 MCP's custom AI instruction feature returns unsanitized attacker content alongside normal document queries, carrying injected instructions into the coding agent's trusted context and tricking it into reading keys, exfiltrating data, or deleting files.

Why it matters

The material breaks down how Context7 MCP injects prompts through custom instructions, and offers a mitigation approach: adding an authorization gate at the tool invocation boundary.

Full text

Back to incident tracker

2026-08-18

HighPrimary

Context7 MCP Custom AI Instructions Prompt Injection Can Drive Credential Exfiltration and Destructive File Deletion

Analysis of CVE-2026-75130, a Context7 MCP prompt-injection flaw that delivered unsanitized Custom AI Instructions to connected coding agents.

Context7 MCP ServerTool execution / MCPMCP-delivered indirect prompt injection through unsanitized custom instructionsDeveloper workstations and repositories connected to affected Context7 MCP versions

What happened

Poisoned Context7 Custom AI Instructions reach a coding agent during a normal documentation query and direct the agent to read secrets, transmit them externally, or delete files.

Why it matters

Potential theft of environment-file credentials and destructive deletion of local project files through the connected agent's tool permissions.

Missing authorization check

Independent authorization for file reads involving credentials, outbound transmission, and destructive filesystem operations initiated from MCP-supplied context.

Would PP block it?

The poisoned documentation response may still reach the model, but each consequential tool call is evaluated outside the model. Calls to read environment files, contact an unapproved endpoint, or delete files would be held or denied without a matching authority receipt.

Incident analysis

Timeline and technical read

Timeline

  1. 2026-08-18

    CVE-2026-75130 is published for Context7 through version 2.1.2.

  2. 2026-08-18

    The advisory documents credential-exfiltration and destructive-file-deletion impact through connected coding agents.

Technical breakdown

  • Context7's Custom AI Instructions feature returned unsanitized attacker-controlled content with otherwise legitimate documentation results.
  • The connected coding agent, rather than the read-only MCP server, supplied the file, shell, and network capabilities needed for impact.
  • A routine library lookup was sufficient to introduce the injected instructions into the agent's trusted working context.
  • The advisory lists Context7 2.1.2 and earlier as affected; public reporting did not identify a definitive patched version at disclosure time.

Authorization boundary

Where the authorization boundary should have been

This incident is categorized as Tool execution / MCP. The relevant Permission Protocol gate is Tool-Call Gate. The read is conditional: the block only applies where the real action boundary is routed through a gate.

If enforced at
MCP client boundary before credential reads, outbound requests, and destructive file tools execute
Still needs
The gate limits downstream consequences but does not sanitize the vulnerable Context7 response itself.
Receipt required for
Reading environment credentials, sending data to new domains, and deleting workspace files

MCP Guard can treat Context7 output as untrusted and require a signed decision before the connected agent executes credential, network, or deletion tools.

Start small

Put the relevant gate at this action boundary.

This incident maps to Tool-Call Gate. Start with the boundary that controls the actual action, then require a signed receipt before execution.

Replay this incident with a signer in the loop

Source: Permission Protocol · AI Agent Incident Tracker · permissionprotocol.com