Context7 MCP: внедрение промпта через пользовательские ИИ-инструкции может привести к утечке учётных данных и удалению файлов
Оригинальный заголовок: Context7 MCP Custom AI Instructions Prompt Injection Can Drive Credential Exfiltration and Destructive File Deletion
Функция пользовательских ИИ-инструкций в Context7 MCP возвращает неочищенный контент злоумышленника вместе с обычными запросами к документам, из-за чего внедрённые инструкции попадают в доверенный контекст ИИ-агента для разработки и подталкивают его читать ключи, передавать данные наружу или удалять файлы.
В материале разобран путь внедрения промпта через пользовательские инструкции в Context7 MCP и предложен способ снижения риска — добавить контроль авторизации на границах вызовов инструментов.
2026-08-18
HighPrimary
Context7 MCP Custom AI Instructions Prompt Injection Can Drive Credential Exfiltration and Destructive File Deletion
Analysis of CVE-2026-75130, a Context7 MCP prompt-injection flaw that delivered unsanitized Custom AI Instructions to connected coding agents.
Context7 MCP ServerTool execution / MCPMCP-delivered indirect prompt injection through unsanitized custom instructionsDeveloper workstations and repositories connected to affected Context7 MCP versions
What happened
Poisoned Context7 Custom AI Instructions reach a coding agent during a normal documentation query and direct the agent to read secrets, transmit them externally, or delete files.
Why it matters
Potential theft of environment-file credentials and destructive deletion of local project files through the connected agent's tool permissions.
Missing authorization check
Independent authorization for file reads involving credentials, outbound transmission, and destructive filesystem operations initiated from MCP-supplied context.
Would PP block it?
The poisoned documentation response may still reach the model, but each consequential tool call is evaluated outside the model. Calls to read environment files, contact an unapproved endpoint, or delete files would be held or denied without a matching authority receipt.
Incident analysis
Timeline and technical read
Timeline
2026-08-18
CVE-2026-75130 is published for Context7 through version 2.1.2.
2026-08-18
The advisory documents credential-exfiltration and destructive-file-deletion impact through connected coding agents.
Technical breakdown
- Context7's Custom AI Instructions feature returned unsanitized attacker-controlled content with otherwise legitimate documentation results.
- The connected coding agent, rather than the read-only MCP server, supplied the file, shell, and network capabilities needed for impact.
- A routine library lookup was sufficient to introduce the injected instructions into the agent's trusted working context.
- The advisory lists Context7 2.1.2 and earlier as affected; public reporting did not identify a definitive patched version at disclosure time.
Authorization boundary
Where the authorization boundary should have been
This incident is categorized as Tool execution / MCP. The relevant Permission Protocol gate is Tool-Call Gate. The read is conditional: the block only applies where the real action boundary is routed through a gate.
- If enforced at
- MCP client boundary before credential reads, outbound requests, and destructive file tools execute
- Still needs
- The gate limits downstream consequences but does not sanitize the vulnerable Context7 response itself.
- Receipt required for
- Reading environment credentials, sending data to new domains, and deleting workspace files
MCP Guard can treat Context7 output as untrusted and require a signed decision before the connected agent executes credential, network, or deletion tools.
Start small
Put the relevant gate at this action boundary.
This incident maps to Tool-Call Gate. Start with the boundary that controls the actual action, then require a signed receipt before execution.
Источник: Permission Protocol · AI Agent Incident Tracker · permissionprotocol.com