Loading market data...
← Back to CVE feed

CVE-2026-93982

LOW CVSS 3.3 View on NVD ↗

Description

OpenPanel through commit bad75bdd writes Model Context Protocol authentication tokens from URL query parameters to plaintext application logs without redaction. Attackers with access to application stdout or centralized logging systems can capture base64-encoded credentials to replay MCP requests and access project analytics.

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Published: Sep 19, 2026 12:16 UTC Modified: Sep 19, 2026 12:16 UTC