๐Ÿ” CVE Alert

CVE-2026-63646

UNKNOWN 0.0

CordysCRM MCP Form Configuration Endpoint Exposed to Anonymous Users

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior to 1.7.2, GET /mcp/form/config/{formKey} calls McpController.getMcpField without authentication because ShiroFilter.addPublicPathFilters marks /mcp/** as anonymous and the controller has no permission annotation. An unauthenticated caller can obtain field names, types, required flags, default values, options, validation rules, and binding sources for CRM modules, allowing reconstruction of the application data model and more targeted attacks against other inputs. This issue is fixed in version 1.7.2.

CWE CWE-200
Vendor 1panel-dev
Product cordyscrm
Published Sep 18, 2026
Stay Ahead of the Next One

Get instant alerts for 1panel-dev cordyscrm

Be the first to know when new unknown vulnerabilities affecting 1panel-dev cordyscrm are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

1Panel-dev / CordysCRM
< 1.7.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/1Panel-dev/CordysCRM/security/advisories/GHSA-46p5-m7pq-82hm github.com: https://github.com/1Panel-dev/CordysCRM/pull/2725 github.com: https://github.com/1Panel-dev/CordysCRM/commit/ea8d5f128b94659ce881e9d034a37c18fa86bbbc github.com: https://github.com/1Panel-dev/CordysCRM/releases/tag/v1.7.2