CVE-2026-107824
x64dbg-MCP Server exposes debugger operations to unauthenticated network clients
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
x64dbg-MCP Server is a native Model Context Protocol (MCP) plugin for x64dbg that exposes the debugger's full functionality over HTTP. Prior to 1.1, x64dbg-MCP Server exposes all MCP debugger tools over HTTP and SSE without authentication while listening on 0.0.0.0 by default. Any unauthenticated network client that can reach the default port, 9094 for x64 or 9095 for x32, can execute arbitrary x64dbg commands, attach to processes by PID, read and write debuggee memory, and write files to arbitrary paths. This issue is fixed in version 1.1.
| CWE | CWE-306 |
| Vendor | duty1g |
| Product | x64dbg-mcp-server |
| Published | Oct 9, 2026 |
Stay Ahead of the Next One
Get instant alerts for duty1g x64dbg-mcp-server
Be the first to know when new unknown vulnerabilities affecting duty1g x64dbg-mcp-server are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
duty1g / x64dbg-mcp-server
< 1.1
References
github.com: https://github.com/duty1g/x64dbg-mcp-server/security/advisories/GHSA-4478-h5jv-647m github.com: https://github.com/duty1g/x64dbg-mcp-server/security/advisories/GHSA-jgj3-97w2-9v9r github.com: https://github.com/duty1g/x64dbg-mcp-server/commit/1aad0f88b9c27233d11dbccf08ca415eb5f49203 github.com: https://github.com/duty1g/x64dbg-mcp-server/commit/e1daba0038959f88d25ff3376b2a7f922ffeb448 github.com: https://github.com/duty1g/x64dbg-mcp-server/releases/tag/1.0 github.com: https://github.com/duty1g/x64dbg-mcp-server/releases/tag/v1.1