{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-88257","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-10-08T13:59:14.866448Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-10-08T13:59:33.374Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"collectionURL":"https://repo.hex.pm","cpes":["cpe:2.3:a:scriptkittyos:beam_mcp:*:*:*:*:*:*:*:*"],"defaultStatus":"unaffected","modules":["'Elixir.BeamMCP.Schema'","'Elixir.BeamMCP.Server'"],"packageName":"beam_mcp","packageURL":"pkg:hex/beam_mcp","product":"beam_mcp","programFiles":["lib/beam_mcp/schema.ex","lib/beam_mcp/server.ex"],"programRoutines":[{"name":"'Elixir.BeamMCP.Schema':validate/2"},{"name":"'Elixir.BeamMCP.Server':handle_message/2"}],"repo":"https://github.com/ScriptKittyOS/beam_mcp","vendor":"ScriptKittyOS","versions":[{"lessThan":"0.10.1","status":"affected","version":"0.1.0","versionType":"semver"}]},{"collectionURL":"https://github.com","cpes":["cpe:2.3:a:scriptkittyos:beam_mcp:*:*:*:*:*:*:*:*"],"defaultStatus":"unaffected","modules":["'Elixir.BeamMCP.Schema'","'Elixir.BeamMCP.Server'"],"packageName":"scriptkittyos/beam_mcp","packageURL":"pkg:github/scriptkittyos/beam_mcp","product":"beam_mcp","programFiles":["lib/beam_mcp/schema.ex","lib/beam_mcp/server.ex"],"programRoutines":[{"name":"'Elixir.BeamMCP.Schema':validate/2"},{"name":"'Elixir.BeamMCP.Server':handle_message/2"}],"repo":"https://github.com/ScriptKittyOS/beam_mcp","vendor":"ScriptKittyOS","versions":[{"lessThan":"289dbdbad641943b29a3b8d1eb36506cc8cec10a","status":"affected","version":"083838eb8e17fe5f6fcaf761bdbe203110288b0b","versionType":"git"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:a:scriptkittyos:beam_mcp:*:*:*:*:*:*:*:*","versionEndExcluding":"0.10.1","versionStartIncluding":"0.1.0","vulnerable":true}],"negate":false,"operator":"OR"}],"operator":"AND"}],"credits":[{"lang":"en","type":"finder","value":"Ayla Croft / Script Kitty OS"},{"lang":"en","type":"reporter","value":"Ayla Croft / Script Kitty OS"},{"lang":"en","type":"remediation developer","value":"Ayla Croft / Script Kitty OS"},{"lang":"en","type":"coordinator","value":"Jonatan Männchen / EEF"}],"dateAssigned":"2026-10-08T13:40:44.000Z","datePublic":"2026-09-26T00:00:00.000Z","descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>Improper Input Validation vulnerability in <code>BeamMCP.Schema</code> in ScriptKittyOS beam_mcp allows an MCP client to reach a tool's dispatch function with arguments that violate the input schema the server advertised. <code>BeamMCP.Schema.validate/2</code> checked <code>type</code>, <code>required</code>, <code>additionalProperties</code>, <code>enum</code> and numeric bounds on the top-level arguments object only. Constraints inside nested objects and on array items (<code>items</code>, <code>minItems</code>, <code>maxItems</code>, <code>minLength</code>, <code>maxLength</code>, <code>pattern</code>, nested <code>required</code>, <code>enum</code> and <code>additionalProperties: false</code>) were advertised by <code>tools/list</code> and never checked at <code>tools/call</code> or <code>prompts/get</code>, and keywords outside the enforced subset (<code>oneOf</code>, <code>anyOf</code>, <code>$ref</code>) were advertised and ignored.</p>\n<p>A host whose dispatch code relies on the schema it declared receives values the schema forbids, such as an out-of-range number or an undeclared key inside a nested object. What the host does with such a value decides the impact.</p>\n<p>This issue affects beam_mcp: from 0.1.0 before 0.10.1.</p>"},{"base64":false,"type":"text/markdown","value":"Improper Input Validation vulnerability in `BeamMCP.Schema` in ScriptKittyOS beam_mcp allows an MCP client to reach a tool's dispatch function with arguments that violate the input schema the server advertised. `BeamMCP.Schema.validate/2` checked `type`, `required`, `additionalProperties`, `enum` and numeric bounds on the top-level arguments object only. Constraints inside nested objects and on array items (`items`, `minItems`, `maxItems`, `minLength`, `maxLength`, `pattern`, nested `required`, `enum` and `additionalProperties: false`) were advertised by `tools/list` and never checked at `tools/call` or `prompts/get`, and keywords outside the enforced subset (`oneOf`, `anyOf`, `$ref`) were advertised and ignored.\n\nA host whose dispatch code relies on the schema it declared receives values the schema forbids, such as an out-of-range number or an undeclared key inside a nested object. What the host does with such a value decides the impact.\n\nThis issue affects beam_mcp: from 0.1.0 before 0.10.1."}],"value":"Improper Input Validation vulnerability in BeamMCP.Schema in ScriptKittyOS beam_mcp allows an MCP client to reach a tool's dispatch function with arguments that violate the input schema the server advertised. BeamMCP.Schema.validate/2 checked type, required, additionalProperties, enum and numeric bounds on the top-level arguments object only. Constraints inside nested objects and on array items (items, minItems, maxItems, minLength, maxLength, pattern, nested required, enum and additionalProperties: false) were advertised by tools/list and never checked at tools/call or prompts/get, and keywords outside the enforced subset (oneOf, anyOf, $ref) were advertised and ignored.\n\nA host whose dispatch code relies on the schema it declared receives values the schema forbids, such as an out-of-range number or an undeclared key inside a nested object. What the host does with such a value decides the impact.\n\nThis issue affects beam_mcp: from 0.1.0 before 0.10.1."}],"impacts":[{"capecId":"CAPEC-153","descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>An MCP client can hand a host's tool values the host's declared schema forbids, such as an out-of-range number or an undeclared key inside a nested object. The consequence depends on what the host's dispatch code does with a value it never expected to receive.</p>"},{"base64":false,"type":"text/markdown","value":"An MCP client can hand a host's tool values the host's declared schema forbids, such as an out-of-range number or an undeclared key inside a nested object. The consequence depends on what the host's dispatch code does with a value it never expected to receive."}],"value":"An MCP client can hand a host's tool values the host's declared schema forbids, such as an out-of-range number or an undeclared key inside a nested object. The consequence depends on what the host's dispatch code does with a value it never expected to receive."}]}],"metrics":[{"cvssV4_0":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":5.3,"baseSeverity":"MEDIUM","privilegesRequired":"LOW","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"LOW","vulnerabilityResponseEffort":"NOT_DEFINED"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-20","description":"CWE-20 Improper Input Validation","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-10-08T14:09:41.540Z","orgId":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db","shortName":"EEF"},"references":[{"name":"GitHub Advisory","tags":["related","vendor-advisory"],"url":"https://github.com/ScriptKittyOS/beam_mcp/security/advisories/GHSA-mrg2-4747-fmpw"},{"name":"EEF CNA record for CVE-2026-88257","tags":["related"],"url":"https://cna.erlef.org/cves/CVE-2026-88257.html"},{"name":"OSV record EEF-CVE-2026-88257","tags":["related"],"url":"https://osv.dev/vulnerability/EEF-CVE-2026-88257"},{"name":"Introducing commit 083838e in ScriptKittyOS/beam_mcp","tags":["related"],"url":"https://github.com/ScriptKittyOS/beam_mcp/commit/083838eb8e17fe5f6fcaf761bdbe203110288b0b"},{"name":"Fix commit 289dbdb in ScriptKittyOS/beam_mcp","tags":["patch"],"url":"https://github.com/ScriptKittyOS/beam_mcp/commit/289dbdbad641943b29a3b8d1eb36506cc8cec10a"}],"source":{"discovery":"INTERNAL"},"title":"beam_mcp: nested tool argument constraints advertised but not enforced","workarounds":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>Re-validate the arguments inside the host's dispatch function against every constraint the schema declares below the top level, or move each constraint to a top-level property, which the affected versions do enforce.</p>"},{"base64":false,"type":"text/markdown","value":"Re-validate the arguments inside the host's dispatch function against every constraint the schema declares below the top level, or move each constraint to a top-level property, which the affected versions do enforce."}],"value":"Re-validate the arguments inside the host's dispatch function against every constraint the schema declares below the top level, or move each constraint to a top-level property, which the affected versions do enforce."}],"x_proofOfConcept":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<ol>\n<li>Declare a tool whose <code>input_schema</code> has a nested object property <code>opts</code> with <code>\"properties\": {\"level\": {\"type\": \"integer\", \"maximum\": 3}}</code>, <code>\"required\": [\"level\"]</code> and <code>\"additionalProperties\": false</code>, and an array property <code>tags</code> with <code>\"items\": {\"type\": \"string\"}</code> and <code>\"maxItems\": 2</code>.</li>\n<li>Send <code>tools/call</code> with <code>\"arguments\": {\"opts\": {\"level\": 99, \"extra\": \"x\"}}</code>.</li>\n<li>On beam_mcp 0.10.0 the dispatch function receives <code>%{opts: %{\"extra\" =&gt; \"x\", \"level\" =&gt; 99}}</code>. On 0.10.1 the call is refused with <code>invalid arguments: unknown property: opts.extra</code>.</li>\n<li>Send <code>\"arguments\": {\"tags\": [1, 2, 3]}</code>. On 0.10.0 the dispatch function receives <code>tags: [1, 2, 3]</code>. On 0.10.1 the call is refused with <code>tags must have at most 2 items</code>.</li>\n</ol>"},{"base64":false,"type":"text/markdown","value":"1. Declare a tool whose `input_schema` has a nested object property `opts` with `\"properties\": {\"level\": {\"type\": \"integer\", \"maximum\": 3}}`, `\"required\": [\"level\"]` and `\"additionalProperties\": false`, and an array property `tags` with `\"items\": {\"type\": \"string\"}` and `\"maxItems\": 2`.\n2. Send `tools/call` with `\"arguments\": {\"opts\": {\"level\": 99, \"extra\": \"x\"}}`.\n3. On beam_mcp 0.10.0 the dispatch function receives `%{opts: %{\"extra\" => \"x\", \"level\" => 99}}`. On 0.10.1 the call is refused with `invalid arguments: unknown property: opts.extra`.\n4. Send `\"arguments\": {\"tags\": [1, 2, 3]}`. On 0.10.0 the dispatch function receives `tags: [1, 2, 3]`. On 0.10.1 the call is refused with `tags must have at most 2 items`."}],"value":"* Declare a tool whose input_schema has a nested object property opts with \"properties\": {\"level\": {\"type\": \"integer\", \"maximum\": 3}}, \"required\": [\"level\"] and \"additionalProperties\": false, and an array property tags with \"items\": {\"type\": \"string\"} and \"maxItems\": 2.\n* Send tools/call with \"arguments\": {\"opts\": {\"level\": 99, \"extra\": \"x\"}}.\n* On beam_mcp 0.10.0 the dispatch function receives %{opts: %{\"extra\" => \"x\", \"level\" => 99}}. On 0.10.1 the call is refused with invalid arguments: unknown property: opts.extra.\n* Send \"arguments\": {\"tags\": [1, 2, 3]}. On 0.10.0 the dispatch function receives tags: [1, 2, 3]. On 0.10.1 the call is refused with tags must have at most 2 items."}],"x_technicalAnalysis":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p><strong>1. Advertising.</strong> <code>tools/list</code> returns each tool's <code>input_schema</code> verbatim, including nested <code>properties</code>, <code>items</code> and constraint keywords.</p>\n<p><strong>2. Validation.</strong> <code>BeamMCP.Schema.validate/2</code> in <code>lib/beam_mcp/schema.ex</code> walks only the first level: <code>check_required/2</code> and <code>check_additional/3</code> run on the top-level object, and <code>check_properties/2</code> applies <code>check_type</code>, <code>check_enum</code> and <code>check_range</code> to each top-level value. A value of type <code>object</code> or <code>array</code> is accepted once its own type matches, and its contents are not visited. Keywords the validator does not know are ignored.</p>\n<p><strong>3. Dispatch.</strong> <code>BeamMCP.Server.validate_and_dispatch/3</code> passes the accepted arguments to <code>normalize_arguments/2</code> and then to the host's dispatch function, so an undeclared key inside a nested object, an out-of-range nested number, or an array item of the wrong type reaches host code that believed the schema excluded it. The same validator runs on <code>prompts/get</code> arguments. The fix in 0.10.1 enforces every keyword of the documented subset at every depth and refuses a schema that uses any other keyword when the catalog is loaded.</p>"},{"base64":false,"type":"text/markdown","value":"**1. Advertising.** `tools/list` returns each tool's `input_schema` verbatim, including nested `properties`, `items` and constraint keywords.\n\n**2. Validation.** `BeamMCP.Schema.validate/2` in `lib/beam_mcp/schema.ex` walks only the first level: `check_required/2` and `check_additional/3` run on the top-level object, and `check_properties/2` applies `check_type`, `check_enum` and `check_range` to each top-level value. A value of type `object` or `array` is accepted once its own type matches, and its contents are not visited. Keywords the validator does not know are ignored.\n\n**3. Dispatch.** `BeamMCP.Server.validate_and_dispatch/3` passes the accepted arguments to `normalize_arguments/2` and then to the host's dispatch function, so an undeclared key inside a nested object, an out-of-range nested number, or an array item of the wrong type reaches host code that believed the schema excluded it. The same validator runs on `prompts/get` arguments. The fix in 0.10.1 enforces every keyword of the documented subset at every depth and refuses a schema that uses any other keyword when the catalog is loaded."}],"value":"1. Advertising. tools/list returns each tool's input_schema verbatim, including nested properties, items and constraint keywords.\n\n2. Validation. BeamMCP.Schema.validate/2 in lib/beam_mcp/schema.ex walks only the first level: check_required/2 and check_additional/3 run on the top-level object, and check_properties/2 applies check_type, check_enum and check_range to each top-level value. A value of type object or array is accepted once its own type matches, and its contents are not visited. Keywords the validator does not know are ignored.\n\n3. Dispatch. BeamMCP.Server.validate_and_dispatch/3 passes the accepted arguments to normalize_arguments/2 and then to the host's dispatch function, so an undeclared key inside a nested object, an out-of-range nested number, or an array item of the wrong type reaches host code that believed the schema excluded it. The same validator runs on prompts/get arguments. The fix in 0.10.1 enforces every keyword of the documented subset at every depth and refuses a schema that uses any other keyword when the catalog is loaded."}]}},"cveMetadata":{"assignerOrgId":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db","assignerShortName":"EEF","cveId":"CVE-2026-88257","datePublished":"2026-10-08T13:40:55.828Z","dateReserved":"2026-10-07T22:15:01.878Z","dateUpdated":"2026-10-08T14:09:41.540Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"}