Context7 MCP 自定义 AI 指令提示词注入可致凭据外泄与文件删除
原文标题:Context7 MCP Custom AI Instructions Prompt Injection Can Drive Credential Exfiltration and Destructive File Deletion
Context7 MCP 的自定义 AI 指令功能会随正常文档查询返回未净化的攻击者内容,从而把注入指令带进编码智能体的可信上下文,诱导其读取密钥、外传数据或删除文件。
材料拆解了 Context7 MCP 通过自定义指令注入提示词的路径,并给出在工具调用边界加授权门禁的缓解思路。
2026-08-18
HighPrimary
Context7 MCP Custom AI Instructions Prompt Injection Can Drive Credential Exfiltration and Destructive File Deletion
Analysis of CVE-2026-75130, a Context7 MCP prompt-injection flaw that delivered unsanitized Custom AI Instructions to connected coding agents.
Context7 MCP ServerTool execution / MCPMCP-delivered indirect prompt injection through unsanitized custom instructionsDeveloper workstations and repositories connected to affected Context7 MCP versions
What happened
Poisoned Context7 Custom AI Instructions reach a coding agent during a normal documentation query and direct the agent to read secrets, transmit them externally, or delete files.
Why it matters
Potential theft of environment-file credentials and destructive deletion of local project files through the connected agent's tool permissions.
Missing authorization check
Independent authorization for file reads involving credentials, outbound transmission, and destructive filesystem operations initiated from MCP-supplied context.
Would PP block it?
The poisoned documentation response may still reach the model, but each consequential tool call is evaluated outside the model. Calls to read environment files, contact an unapproved endpoint, or delete files would be held or denied without a matching authority receipt.
Incident analysis
Timeline and technical read
Timeline
2026-08-18
CVE-2026-75130 is published for Context7 through version 2.1.2.
2026-08-18
The advisory documents credential-exfiltration and destructive-file-deletion impact through connected coding agents.
Technical breakdown
- Context7's Custom AI Instructions feature returned unsanitized attacker-controlled content with otherwise legitimate documentation results.
- The connected coding agent, rather than the read-only MCP server, supplied the file, shell, and network capabilities needed for impact.
- A routine library lookup was sufficient to introduce the injected instructions into the agent's trusted working context.
- The advisory lists Context7 2.1.2 and earlier as affected; public reporting did not identify a definitive patched version at disclosure time.
Authorization boundary
Where the authorization boundary should have been
This incident is categorized as Tool execution / MCP. The relevant Permission Protocol gate is Tool-Call Gate. The read is conditional: the block only applies where the real action boundary is routed through a gate.
- If enforced at
- MCP client boundary before credential reads, outbound requests, and destructive file tools execute
- Still needs
- The gate limits downstream consequences but does not sanitize the vulnerable Context7 response itself.
- Receipt required for
- Reading environment credentials, sending data to new domains, and deleting workspace files
MCP Guard can treat Context7 output as untrusted and require a signed decision before the connected agent executes credential, network, or deletion tools.
Start small
Put the relevant gate at this action boundary.
This incident maps to Tool-Call Gate. Start with the boundary that controls the actual action, then require a signed receipt before execution.
来源:Permission Protocol · AI Agent Incident Tracker · permissionprotocol.com