{"affected":[{"package":{"ecosystem":"Hex","name":"beam_mcp","purl":"pkg:hex/beam_mcp"},"ranges":[{"events":[{"introduced":"0.1.0"},{"fixed":"0.10.1"}],"type":"SEMVER"}],"versions":["0.1.0","0.2.0","0.3.0","0.3.1","0.4.0","0.5.0","0.6.0","0.7.0","0.8.0","0.9.0","0.10.0"]},{"ranges":[{"events":[{"introduced":"083838eb8e17fe5f6fcaf761bdbe203110288b0b"},{"fixed":"289dbdbad641943b29a3b8d1eb36506cc8cec10a"}],"repo":"https://github.com/ScriptKittyOS/beam_mcp","type":"GIT"}]}],"aliases":["GHSA-mrg2-4747-fmpw","CVE-2026-88257"],"credits":[{"name":"Ayla Croft / Script Kitty OS","type":"FINDER"},{"name":"Ayla Croft / Script Kitty OS","type":"REPORTER"},{"name":"Ayla Croft / Script Kitty OS","type":"REMEDIATION_DEVELOPER"},{"name":"Jonatan Männchen / EEF","type":"COORDINATOR"}],"database_specific":{"capec_ids":["CAPEC-153"],"cpe_ids":["cpe:2.3:a:scriptkittyos:beam_mcp:*:*:*:*:*:*:*:*"],"cwe_ids":["CWE-20"]},"details":"## Summary\n\nImproper Input Validation vulnerability in `BeamMCP.Schema` in ScriptKittyOS beam_mcp allows an MCP client to reach a tool's dispatch function with arguments that violate the input schema the server advertised. `BeamMCP.Schema.validate/2` checked `type`, `required`, `additionalProperties`, `enum` and numeric bounds on the top-level arguments object only. Constraints inside nested objects and on array items (`items`, `minItems`, `maxItems`, `minLength`, `maxLength`, `pattern`, nested `required`, `enum` and `additionalProperties: false`) were advertised by `tools/list` and never checked at `tools/call` or `prompts/get`, and keywords outside the enforced subset (`oneOf`, `anyOf`, `$ref`) were advertised and ignored.\n\nA host whose dispatch code relies on the schema it declared receives values the schema forbids, such as an out-of-range number or an undeclared key inside a nested object. What the host does with such a value decides the impact.\n\nThis issue affects beam_mcp: from 0.1.0 before 0.10.1.\n\n## Details\n\n**1. Advertising.** `tools/list` returns each tool's `input_schema` verbatim, including nested `properties`, `items` and constraint keywords.\n\n**2. Validation.** `BeamMCP.Schema.validate/2` in `lib/beam_mcp/schema.ex` walks only the first level: `check_required/2` and `check_additional/3` run on the top-level object, and `check_properties/2` applies `check_type`, `check_enum` and `check_range` to each top-level value. A value of type `object` or `array` is accepted once its own type matches, and its contents are not visited. Keywords the validator does not know are ignored.\n\n**3. Dispatch.** `BeamMCP.Server.validate_and_dispatch/3` passes the accepted arguments to `normalize_arguments/2` and then to the host's dispatch function, so an undeclared key inside a nested object, an out-of-range nested number, or an array item of the wrong type reaches host code that believed the schema excluded it. The same validator runs on `prompts/get` arguments. The fix in 0.10.1 enforces every keyword of the documented subset at every depth and refuses a schema that uses any other keyword when the catalog is loaded.\n\n## Proof of concept\n\n1. Declare a tool whose `input_schema` has a nested object property `opts` with `\"properties\": {\"level\": {\"type\": \"integer\", \"maximum\": 3}}`, `\"required\": [\"level\"]` and `\"additionalProperties\": false`, and an array property `tags` with `\"items\": {\"type\": \"string\"}` and `\"maxItems\": 2`.\n2. Send `tools/call` with `\"arguments\": {\"opts\": {\"level\": 99, \"extra\": \"x\"}}`.\n3. On beam_mcp 0.10.0 the dispatch function receives `%{opts: %{\"extra\" => \"x\", \"level\" => 99}}`. On 0.10.1 the call is refused with `invalid arguments: unknown property: opts.extra`.\n4. Send `\"arguments\": {\"tags\": [1, 2, 3]}`. On 0.10.0 the dispatch function receives `tags: [1, 2, 3]`. On 0.10.1 the call is refused with `tags must have at most 2 items`.\n\n## Impact\n\nAn MCP client can hand a host's tool values the host's declared schema forbids, such as an out-of-range number or an undeclared key inside a nested object. The consequence depends on what the host's dispatch code does with a value it never expected to receive.\n\n## Workarounds\n\nRe-validate the arguments inside the host's dispatch function against every constraint the schema declares below the top level, or move each constraint to a top-level property, which the affected versions do enforce.","id":"EEF-CVE-2026-88257","modified":"2026-10-08T14:09:41.914693Z","published":"2026-10-08T13:40:55.828Z","references":[{"type":"ADVISORY","url":"https://github.com/ScriptKittyOS/beam_mcp/security/advisories/GHSA-mrg2-4747-fmpw"},{"type":"WEB","url":"https://cna.erlef.org/cves/CVE-2026-88257.html"},{"type":"WEB","url":"https://github.com/ScriptKittyOS/beam_mcp/commit/083838eb8e17fe5f6fcaf761bdbe203110288b0b"},{"type":"FIX","url":"https://github.com/ScriptKittyOS/beam_mcp/commit/289dbdbad641943b29a3b8d1eb36506cc8cec10a"},{"type":"PACKAGE","url":"https://hex.pm/packages/beam_mcp"}],"related":[],"schema_version":"1.7.3","severity":[{"score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","type":"CVSS_V4"}],"summary":"beam_mcp: nested tool argument constraints advertised but not enforced","upstream":[]}