Перейти к содержимому
Оригинал
Permission Protocol · AI Agent Incident Tracker·· 18.08.2026Избранное редакциейОценка ИИ78

Context7 MCP: внедрение промпта через пользовательские ИИ-инструкции может привести к утечке учётных данных и удалению файлов

Оригинальный заголовок: Context7 MCP Custom AI Instructions Prompt Injection Can Drive Credential Exfiltration and Destructive File Deletion

Краткий обзор ИИ

Функция пользовательских ИИ-инструкций в Context7 MCP возвращает неочищенный контент злоумышленника вместе с обычными запросами к документам, из-за чего внедрённые инструкции попадают в доверенный контекст ИИ-агента для разработки и подталкивают его читать ключи, передавать данные наружу или удалять файлы.

Почему это важно

В материале разобран путь внедрения промпта через пользовательские инструкции в Context7 MCP и предложен способ снижения риска — добавить контроль авторизации на границах вызовов инструментов.

Полный текст · Оригинал

Back to incident tracker

2026-08-18

HighPrimary

Context7 MCP Custom AI Instructions Prompt Injection Can Drive Credential Exfiltration and Destructive File Deletion

Analysis of CVE-2026-75130, a Context7 MCP prompt-injection flaw that delivered unsanitized Custom AI Instructions to connected coding agents.

Context7 MCP ServerTool execution / MCPMCP-delivered indirect prompt injection through unsanitized custom instructionsDeveloper workstations and repositories connected to affected Context7 MCP versions

What happened

Poisoned Context7 Custom AI Instructions reach a coding agent during a normal documentation query and direct the agent to read secrets, transmit them externally, or delete files.

Why it matters

Potential theft of environment-file credentials and destructive deletion of local project files through the connected agent's tool permissions.

Missing authorization check

Independent authorization for file reads involving credentials, outbound transmission, and destructive filesystem operations initiated from MCP-supplied context.

Would PP block it?

The poisoned documentation response may still reach the model, but each consequential tool call is evaluated outside the model. Calls to read environment files, contact an unapproved endpoint, or delete files would be held or denied without a matching authority receipt.

Incident analysis

Timeline and technical read

Timeline

  1. 2026-08-18

    CVE-2026-75130 is published for Context7 through version 2.1.2.

  2. 2026-08-18

    The advisory documents credential-exfiltration and destructive-file-deletion impact through connected coding agents.

Technical breakdown

  • Context7's Custom AI Instructions feature returned unsanitized attacker-controlled content with otherwise legitimate documentation results.
  • The connected coding agent, rather than the read-only MCP server, supplied the file, shell, and network capabilities needed for impact.
  • A routine library lookup was sufficient to introduce the injected instructions into the agent's trusted working context.
  • The advisory lists Context7 2.1.2 and earlier as affected; public reporting did not identify a definitive patched version at disclosure time.

Authorization boundary

Where the authorization boundary should have been

This incident is categorized as Tool execution / MCP. The relevant Permission Protocol gate is Tool-Call Gate. The read is conditional: the block only applies where the real action boundary is routed through a gate.

If enforced at
MCP client boundary before credential reads, outbound requests, and destructive file tools execute
Still needs
The gate limits downstream consequences but does not sanitize the vulnerable Context7 response itself.
Receipt required for
Reading environment credentials, sending data to new domains, and deleting workspace files

MCP Guard can treat Context7 output as untrusted and require a signed decision before the connected agent executes credential, network, or deletion tools.

Start small

Put the relevant gate at this action boundary.

This incident maps to Tool-Call Gate. Start with the boundary that controls the actual action, then require a signed receipt before execution.

Replay this incident with a signer in the loop

Источник: Permission Protocol · AI Agent Incident Tracker · permissionprotocol.com