CVE-2026-88257
Received Received - Intake

Improper Input Validation in BeamMCP.Schema for ScriptKittyOS

Vulnerability report for CVE-2026-88257, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: EEF

Description

Improper Input Validation vulnerability in BeamMCP.Schema in ScriptKittyOS beam_mcp allows an MCP client to reach a tool's dispatch function with arguments that violate the input schema the server advertised. BeamMCP.Schema.validate/2 checked type, required, additionalProperties, enum and numeric bounds on the top-level arguments object only. Constraints inside nested objects and on array items (items, minItems, maxItems, minLength, maxLength, pattern, nested required, enum and additionalProperties: false) were advertised by tools/list and never checked at tools/call or prompts/get, and keywords outside the enforced subset (oneOf, anyOf, $ref) were advertised and ignored. A host whose dispatch code relies on the schema it declared receives values the schema forbids, such as an out-of-range number or an undeclared key inside a nested object. What the host does with such a value decides the impact. This issue affects beam_mcp: from 0.1.0 before 0.10.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
ScriptKittyOS beam_mcp 0.1.0
ScriptKittyOS beam_mcp 083838eb8e17fe5f6fcaf761bdbe203110288b0b

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-20 The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an Improper Input Validation issue in BeamMCP.Schema of ScriptKittyOS beam_mcp. The tool advertises input constraints for nested objects and arrays but only enforces them at the top level. Invalid values like out-of-range numbers or undeclared keys in nested objects can bypass validation and reach the host's dispatch function.

Detection Guidance

Check the version of beam_mcp installed on your system. If it is below 0.10.1, the system is vulnerable. Run: beam_mcp --version or check package managers like mix deps or rebar3.

Impact Analysis

The impact depends on how the host processes invalid inputs. Attackers could send values violating the schema, such as out-of-range numbers or extra keys in nested objects, potentially causing unexpected behavior or low integrity risks for the system.

Mitigation Strategies

Upgrade beam_mcp to version 0.10.1 or later. If upgrading is not immediately possible, implement a workaround by re-validating arguments within the host's dispatch function to enforce schema constraints.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-88257. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart