meta-ads-mcp
PyPI3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting meta-ads-mcppage 1 of 1
- CVE-2026-48039CRITICALCVSS 9.1EG 9.1✓ Fixed in 1.0.1092026-06-11
vulnerable: 0.1.0 ... 1.0.99 (167 versions)
Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.109, `AuthInjectionMiddleware.dispatch()` at `http_auth_integration.py:272` unconditionally forwards unauthenticated Streamabl…
- CVE-2026-54547HIGHCVSS 7.4EG 7.4✓ Fixed in 1.0.1152026-07-17
vulnerable: 0.1.0 ... 1.0.99 (172 versions)
Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.115, AuthInjectionMiddleware in meta_ads_mcp/core/http_auth_integration.py rejects HTTP MCP requests only when both auth_token…
- CVE-2026-54549HIGHCVSS 8.3EG 8.3✓ Fixed in 1.0.1152026-07-17
vulnerable: 0.1.0 ... 1.0.99 (172 versions)
Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.115, the upload_ad_image tool in meta_ads_mcp/core/ads.py passes an attacker-controlled image_url to try_multiple_download_met…
Check whether meta-ads-mcp is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for meta-ads-mcp CVEs against the assets you own.
Start Free Scan →