Two critical vulnerabilities, CVE-2026-54547 and CVE-2026-54549, have been identified in the Meta Ads MCP server, each with a severity score of 7.4. The first vulnerability allows for server-side request forgery by exploiting a URL parameter that is fetched without proper validation, enabling an attacker to influence where the server connects. The second vulnerability stems from an authorization middleware that incorrectly handles authentication tokens, failing to properly read a primary token and thus allowing unauthorized requests. These issues highlight the importance of validating all tool arguments that become network requests and ensuring middleware correctly processes credentials. AI
IMPACT These vulnerabilities in the Meta Ads MCP server could allow attackers to compromise ad campaign data or redirect server requests, impacting ad delivery and potentially leading to data breaches.
RANK_REASON Security vulnerabilities discovered in a specific server product.
AI-generated summary · Google Gemini · from 1 sources. How we write summaries →