Two vulnerabilities patched in Meta Ads MCP server
The Meta Ads MCP server has been affected by two vulnerabilities, each with a severity score of 7.4. One flaw, CVE-2026-54549, allows a server-side request forgery via an unvalidated image URL parameter. The other, CVE-2026-54547, stems from a middleware bug that incorrectly validates authorization headers. Together, they could allow unauthorized access and remote code execution. The maintainers have released fixed versions and advise users to upgrade.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in