CVE-2026-88257
beam_mcp: nested tool argument constraints advertised but not enforced
Improper Input Validation vulnerability in BeamMCP.Schema in ScriptKittyOS beam_mcp allows an MCP client to reach a tool's dispatch function with arguments that violate the input schema the server advertised. BeamMCP.Schema.validate/2 checked type, required, additionalProperties, enum and numeric bounds on the top-level arguments object only. Constraints inside nested objects and on array items (items, minItems, maxItems, minLength, maxLength, pattern, nested required, enum and additionalProperties: false) were advertised by tools/list and never checked at tools/call or prompts/get, and keywords outside the enforced subset (oneOf, anyOf, $ref) were advertised and ignored. A host whose dispatch code relies on the schema it declared receives values the schema forbids, such as an out-of-range number or an undeclared key inside a nested object. What the host does with such a value decides the impact. This issue affects beam_mcp: from 0.1.0 before 0.10.1.
| CWE | CWE-20 |
| Vendor | scriptkittyos |
| Product | beam_mcp |
| Published | Oct 8, 2026 |
| Last Updated | Oct 8, 2026 |
Get instant alerts for scriptkittyos beam_mcp
Be the first to know when new unknown vulnerabilities affecting scriptkittyos beam_mcp are published β delivered to Slack, Telegram or Discord.