Vulnerability EEF-CVE-2026-88257
Summary
beam_mcp: nested tool argument constraints advertised but not enforced
Details
Summary
Improper Input Validation vulnerability in BeamMCP.Schema in ScriptKittyOS beam_mcp allows an MCP client to reach a tool's dispatch function with arguments that violate the input schema the server advertised. BeamMCP.Schema.validate/2 checked type, required, additionalProperties, enum and numeric bounds on the top-level arguments object only. Constraints inside nested objects and on array items (items, minItems, maxItems, minLength, maxLength, pattern, nested required, enum and additionalProperties: false) were advertised by tools/list and never checked at tools/call or prompts/get, and keywords outside the enforced subset (oneOf, anyOf, $ref) were advertised and ignored.
A host whose dispatch code relies on the schema it declared receives values the schema forbids, such as an out-of-range number or an undeclared key inside a nested object. What the host does with such a value decides the impact.
This issue affects beam_mcp: from 0.1.0 before 0.10.1.
Details
1. Advertising. tools/list returns each tool's input_schema verbatim, including nested properties, items and constraint keywords.
2. Validation. BeamMCP.Schema.validate/2 in lib/beam_mcp/schema.ex walks only the first level: check_required/2 and check_additional/3 run on the top-level object, and check_properties/2 applies check_type, check_enum and check_range to each top-level value. A value of type object or array is accepted once its own type matches, and its contents are not visited. Keywords the validator does not know are ignored.
3. Dispatch. BeamMCP.Server.validate_and_dispatch/3 passes the accepted arguments to normalize_arguments/2 and then to the host's dispatch function, so an undeclared key inside a nested object, an out-of-range nested number, or an array item of the wrong type reaches host code that believed the schema excluded it. The same validator runs on prompts/get arguments. The fix in 0.10.1 enforces every keyword of the documented subset at every depth and refuses a schema that uses any other keyword when the catalog is loaded.
Proof of concept
- Declare a tool whose
input_schemahas a nested object propertyoptswith"properties": {"level": {"type": "integer", "maximum": 3}},"required": ["level"]and"additionalProperties": false, and an array propertytagswith"items": {"type": "string"}and"maxItems": 2. - Send
tools/callwith"arguments": {"opts": {"level": 99, "extra": "x"}}. - On beam_mcp 0.10.0 the dispatch function receives
%{opts: %{"extra" => "x", "level" => 99}}. On 0.10.1 the call is refused withinvalid arguments: unknown property: opts.extra. - Send
"arguments": {"tags": [1, 2, 3]}. On 0.10.0 the dispatch function receivestags: [1, 2, 3]. On 0.10.1 the call is refused withtags must have at most 2 items.
Impact
An MCP client can hand a host's tool values the host's declared schema forbids, such as an out-of-range number or an undeclared key inside a nested object. The consequence depends on what the host's dispatch code does with a value it never expected to receive.
Workarounds
Re-validate the arguments inside the host's dispatch function against every constraint the schema declares below the top level, or move each constraint to a top-level property, which the affected versions do enforce.
Related Vulnerabilities
Other vulnerabilities affecting the same packages