Sceawere

Vulnerability Detail

CVE-2026-108699UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Improper Signature Verification in hyper-mcp

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
3h ago
Vendor
hyper-mcp-rs
Product
hyper-mcp
Attack Type
Improper Verification of Cryptographic Signature
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N
Attack Complexity
HIGH

Narrative and Response

Description

hyper-mcp through 0.8.3 contains an improper signature verification vulnerability that allows attackers to load malicious WebAssembly plugins because cosign_verify_args() accepts any signer identity and OIDC issuer by default. Attackers controlling a plugin image reference can sign a malicious image with a free Sigstore keyless certificate to execute plugins with configured host, filesystem, and environment capabilities.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-10-11T14:17:04.257Z",
  "pubdate": "2026-10-11T14:17:04.257Z",
  "executiveSummary": "hyper-mcp versions through 0.8.3 are susceptible to an improper signature verification vulnerability due to overly permissive configuration in the plugin verification logic.\nThe vulnerability resides in the cosign_verify_args() function, which fails to enforce strict identity validation for OIDC issuers and signer identities when processing WebAssembly (Wasm) plugins.\nThis flaw allows an attacker to bypass security controls by signing malicious Wasm plugin images with valid, publicly obtainable Sigstore keyless certificates.\nBy controlling the plugin image reference, an attacker can force the host environment to load and execute arbitrary, unsigned or maliciously signed code.\nSuccessful exploitation grants the attacker the ability to inherit the host environment's configured capabilities, including access to local filesystem resources, host-level environment variables, and network communication privileges.\nThis represents a critical security risk as it undermines the integrity of the plugin ecosystem, allowing for unauthorized code execution within the hyper-mcp runtime context without requiring compromised private keys or high-level system privileges beyond the ability to reference a malicious image.",
  "technicalDetails": "The root cause of the vulnerability is an insecure implementation of the Sigstore verification process within the cosign_verify_args() function. In the affected versions of hyper-mcp (through 0.8.3), the function lacks mandatory parameters or configuration constraints to validate the identity of the signer or the trusted OIDC issuer chain.\nWhen a plugin is requested, the system attempts to verify the signature of the O3-containerized Wasm artifact. Because the verification logic accepts any signer identity and any OIDC issuer by default, it effectively treats a validly formatted Sigstore keyless signature—regardless of the actual identity—as a trusted assertion of provenance.\nThe attack flow proceeds as follows: First, the attacker develops a malicious Wasm payload designed to leverage the host's granted permissions. Second, the attacker pushes this payload as an image to an accessible container registry. Third, the attacker signs this image using the standard Sigstore keyless workflow (e.g., using a personal Google, GitHub, or Microsoft OIDC identity). Because the verification logic does not verify the subject field (the email or identity) or the issuer against a whitelist, the hyper-mcp runtime evaluates the signature as legitimate.\nUpon calling the plugin, hyper-mcp executes the cosign_verify_args() function, which returns a successful validation status despite the image not originating from a trusted, authorized source. The Wasm runtime then initializes the plugin with the permissions configured for the host environment. This allows the malicious code to perform operations such as unauthorized file access, data exfiltration, or interactions with the host filesystem.\nThe exploitation does not require the attacker to compromise a specific organization's signing infrastructure; it only requires the attacker to control the plugin image reference provided to the hyper-mcp instance. Once the malicious plugin is initialized, the payload operates with the full context of the host's capabilities, potentially leading to a complete compromise of the hyper-mcp runtime environment.\nThis vulnerability is particularly impactful because it bypasses the security intent of using Sigstore keyless signing, which is designed to ensure provenance, by rendering the 'identity' component of the verification process completely optional and functionally ignored."
}
CVE-2026-108699: Improper Signature Verification in hyper-mcp (MEDIUM Severity, CVSS: 6.5) | Sceawere