跳到正文
原文
Permission Protocol · AI Agent Incident Tracker·· 2026/08/18精选AI 评分78

Context7 MCP 自定义 AI 指令提示词注入可致凭据外泄与文件删除

原文标题:Context7 MCP Custom AI Instructions Prompt Injection Can Drive Credential Exfiltration and Destructive File Deletion

AI 导读

Context7 MCP 的自定义 AI 指令功能会随正常文档查询返回未净化的攻击者内容,从而把注入指令带进编码智能体的可信上下文,诱导其读取密钥、外传数据或删除文件。

推荐理由

材料拆解了 Context7 MCP 通过自定义指令注入提示词的路径,并给出在工具调用边界加授权门禁的缓解思路。

正文 · 原文

Back to incident tracker

2026-08-18

HighPrimary

Context7 MCP Custom AI Instructions Prompt Injection Can Drive Credential Exfiltration and Destructive File Deletion

Analysis of CVE-2026-75130, a Context7 MCP prompt-injection flaw that delivered unsanitized Custom AI Instructions to connected coding agents.

Context7 MCP ServerTool execution / MCPMCP-delivered indirect prompt injection through unsanitized custom instructionsDeveloper workstations and repositories connected to affected Context7 MCP versions

What happened

Poisoned Context7 Custom AI Instructions reach a coding agent during a normal documentation query and direct the agent to read secrets, transmit them externally, or delete files.

Why it matters

Potential theft of environment-file credentials and destructive deletion of local project files through the connected agent's tool permissions.

Missing authorization check

Independent authorization for file reads involving credentials, outbound transmission, and destructive filesystem operations initiated from MCP-supplied context.

Would PP block it?

The poisoned documentation response may still reach the model, but each consequential tool call is evaluated outside the model. Calls to read environment files, contact an unapproved endpoint, or delete files would be held or denied without a matching authority receipt.

Incident analysis

Timeline and technical read

Timeline

  1. 2026-08-18

    CVE-2026-75130 is published for Context7 through version 2.1.2.

  2. 2026-08-18

    The advisory documents credential-exfiltration and destructive-file-deletion impact through connected coding agents.

Technical breakdown

  • Context7's Custom AI Instructions feature returned unsanitized attacker-controlled content with otherwise legitimate documentation results.
  • The connected coding agent, rather than the read-only MCP server, supplied the file, shell, and network capabilities needed for impact.
  • A routine library lookup was sufficient to introduce the injected instructions into the agent's trusted working context.
  • The advisory lists Context7 2.1.2 and earlier as affected; public reporting did not identify a definitive patched version at disclosure time.

Authorization boundary

Where the authorization boundary should have been

This incident is categorized as Tool execution / MCP. The relevant Permission Protocol gate is Tool-Call Gate. The read is conditional: the block only applies where the real action boundary is routed through a gate.

If enforced at
MCP client boundary before credential reads, outbound requests, and destructive file tools execute
Still needs
The gate limits downstream consequences but does not sanitize the vulnerable Context7 response itself.
Receipt required for
Reading environment credentials, sending data to new domains, and deleting workspace files

MCP Guard can treat Context7 output as untrusted and require a signed decision before the connected agent executes credential, network, or deletion tools.

Start small

Put the relevant gate at this action boundary.

This incident maps to Tool-Call Gate. Start with the boundary that controls the actual action, then require a signed receipt before execution.

Replay this incident with a signer in the loop

来源:Permission Protocol · AI Agent Incident Tracker · permissionprotocol.com