Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-vrxg-gm77-7q5g | Windows-MCP: HTTP transports expose unauthenticated PowerShell control with wildcard CORS |
Sun, 21 Jun 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cursortouch
Cursortouch windows-mcp |
|
| Vendors & Products |
Cursortouch
Cursortouch windows-mcp |
Thu, 18 Jun 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 18 Jun 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Windows-MCP is an open-source project that integrates AI agents with Windows. In versions prior to 0.7.5, certain HTTP modes exposed the MCP control plane without authentication while enabling wildcard CORS (allow_origins=*, allow_methods=*, allow_headers=*). Because the same server also exposed a PowerShell tool that executes caller-controlled commands as the Windows user running Windows-MCP, attackers could reach the control plane from arbitrary origins or non-browser clients and achieve arbitrary PowerShell execution. This issue was fixed in version 0.7.5. | |
| Title | Windows-MCP: HTTP transports expose unauthenticated PowerShell control with wildcard CORS | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-18T15:44:08.967Z
Reserved: 2026-05-26T23:26:07.975Z
Link: CVE-2026-48989
Updated: 2026-06-18T15:44:04.160Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-20T22:57:01Z
Github GHSA