Vulnerability EEF-CVE-2026-88257

Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
9 hours ago
October 08, 2026 at 01:40 PM UTC
beam_mcp: nested tool argument constraints advertised but not enforced
0.1.0 - 0.10.0
0.1.0 - 0.10.0

Summary

beam_mcp: nested tool argument constraints advertised but not enforced

Details

Summary

Improper Input Validation vulnerability in BeamMCP.Schema in ScriptKittyOS beam_mcp allows an MCP client to reach a tool's dispatch function with arguments that violate the input schema the server advertised. BeamMCP.Schema.validate/2 checked type, required, additionalProperties, enum and numeric bounds on the top-level arguments object only. Constraints inside nested objects and on array items (items, minItems, maxItems, minLength, maxLength, pattern, nested required, enum and additionalProperties: false) were advertised by tools/list and never checked at tools/call or prompts/get, and keywords outside the enforced subset (oneOf, anyOf, $ref) were advertised and ignored.

A host whose dispatch code relies on the schema it declared receives values the schema forbids, such as an out-of-range number or an undeclared key inside a nested object. What the host does with such a value decides the impact.

This issue affects beam_mcp: from 0.1.0 before 0.10.1.

Details

1. Advertising. tools/list returns each tool's input_schema verbatim, including nested properties, items and constraint keywords.

2. Validation. BeamMCP.Schema.validate/2 in lib/beam_mcp/schema.ex walks only the first level: check_required/2 and check_additional/3 run on the top-level object, and check_properties/2 applies check_type, check_enum and check_range to each top-level value. A value of type object or array is accepted once its own type matches, and its contents are not visited. Keywords the validator does not know are ignored.

3. Dispatch. BeamMCP.Server.validate_and_dispatch/3 passes the accepted arguments to normalize_arguments/2 and then to the host's dispatch function, so an undeclared key inside a nested object, an out-of-range nested number, or an array item of the wrong type reaches host code that believed the schema excluded it. The same validator runs on prompts/get arguments. The fix in 0.10.1 enforces every keyword of the documented subset at every depth and refuses a schema that uses any other keyword when the catalog is loaded.

Proof of concept

  1. Declare a tool whose input_schema has a nested object property opts with "properties": {"level": {"type": "integer", "maximum": 3}}, "required": ["level"] and "additionalProperties": false, and an array property tags with "items": {"type": "string"} and "maxItems": 2.
  2. Send tools/call with "arguments": {"opts": {"level": 99, "extra": "x"}}.
  3. On beam_mcp 0.10.0 the dispatch function receives %{opts: %{"extra" => "x", "level" => 99}}. On 0.10.1 the call is refused with invalid arguments: unknown property: opts.extra.
  4. Send "arguments": {"tags": [1, 2, 3]}. On 0.10.0 the dispatch function receives tags: [1, 2, 3]. On 0.10.1 the call is refused with tags must have at most 2 items.

Impact

An MCP client can hand a host's tool values the host's declared schema forbids, such as an out-of-range number or an undeclared key inside a nested object. The consequence depends on what the host's dispatch code does with a value it never expected to receive.

Workarounds

Re-validate the arguments inside the host's dispatch function against every constraint the schema declares below the top level, or move each constraint to a top-level property, which the affected versions do enforce.

Impacted packages

Timeline

Published
9 hours ago
October 08, 2026 at 01:40 PM UTC
Fixed (0.10.1)
12 days ago
September 26, 2026 at 07:12 PM UTC
Last Modified
8 hours ago
October 08, 2026 at 02:15 PM UTC