CVE-2026-104634
Received Received - Intake

Type Confusion in BeamMCP.Server for ScriptKittyOS

Vulnerability report for CVE-2026-104634, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: EEF

Description

Incorrect Type Conversion or Cast vulnerability in BeamMCP.Server in ScriptKittyOS beam_mcp allows an MCP client's JSON true, false and null tool arguments to reach the host's dispatch function as the strings "true", "false" and "nil". After BeamMCP.Schema.validate/2 accepted a value as a boolean, normalize_arguments/2 passed every argument through to_json_value/1, whose atom clause converts true, false and nil to strings. A string is truthy in Elixir, so a host that tests a boolean argument, for example if args.dry_run, takes the opposite branch for false, and a guard such as confirm: false reads as set. The client controls the argument and could send true directly, so the practical impact is limited to hosts whose behaviour on false differs from their behaviour on true, and to any policy layer in front of the server that permits false but refuses true. The same normalisation applies to prompts/get arguments, which exist from 0.5.0. This issue affects beam_mcp: from 0.1.0 before 0.10.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
ScriptKittyOS beam_mcp 0.1.0
ScriptKittyOS beam_mcp 083838eb8e17fe5f6fcaf761bdbe203110288b0b

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-704 The product does not correctly convert an object, resource, or structure from one type to a different type.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves incorrect type conversion in BeamMCP.Server where boolean values true, false, and null from MCP clients are converted to strings 'true', 'false', and 'nil' in the host's dispatch function. In Elixir, strings are truthy, so a condition like if args.dry_run would take the opposite branch for false, leading to unexpected behavior.

Detection Guidance

To detect this vulnerability, check the version of beam_mcp installed on your system. If it is between 0.1.0 and 0.10.0, it is vulnerable. Run: mix deps | grep beam_mcp or check your mix.lock file for the version.

Impact Analysis

The impact is limited unless hosts behave differently for false versus true. For example, a guard like confirm: false would be treated as set, potentially causing incorrect logic execution. The client controls the argument, so hosts with strict policy checks may mitigate risks.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR or HIPAA as it involves incorrect type conversion in a software library (beam_mcp) rather than data exposure or privacy violations. The issue could indirectly impact compliance if hosts relying on this library mishandle boolean arguments, leading to incorrect processing of user consent or data handling flags, but no direct regulatory impact is documented.

Mitigation Strategies

Update beam_mcp to version 0.10.1 or later to address the incorrect type conversion issue. Review any code that relies on boolean arguments passed via MCP clients to ensure proper handling of true, false, and null values.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104634. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart