smn2gnt

1 exploit Active since Feb 2026
CVE-2026-25650 WRITEUP HIGH WRITEUP
mcp-salesforce-connector < 0.1.10 - Exposure of Sensitive Information via Arbitrary Attribute Access
MCP Salesforce Connector is a Model Context Protocol (MCP) server implementation for Salesforce integration. Prior to 0.1.10, arbitrary attribute access leads to disclosure of Salesforce auth token. This vulnerability is fixed in 0.1.10.
CVSS 7.5