A host whose dispatch code relies on the schema it declared receives values the schema forbids, such as an out-of-range number or an undeclared key inside a nested object. What the host does with such a value decides the impact.
This issue affects beam_mcp: from 0.1.0 before 0.10.1.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Re-validate the arguments inside the host's dispatch function against every constraint the schema declares below the top level, or move each constraint to a top-level property, which the affected versions do enforce.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 08 Oct 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 08 Oct 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Input Validation vulnerability in BeamMCP.Schema in ScriptKittyOS beam_mcp allows an MCP client to reach a tool's dispatch function with arguments that violate the input schema the server advertised. BeamMCP.Schema.validate/2 checked type, required, additionalProperties, enum and numeric bounds on the top-level arguments object only. Constraints inside nested objects and on array items (items, minItems, maxItems, minLength, maxLength, pattern, nested required, enum and additionalProperties: false) were advertised by tools/list and never checked at tools/call or prompts/get, and keywords outside the enforced subset (oneOf, anyOf, $ref) were advertised and ignored. A host whose dispatch code relies on the schema it declared receives values the schema forbids, such as an out-of-range number or an undeclared key inside a nested object. What the host does with such a value decides the impact. This issue affects beam_mcp: from 0.1.0 before 0.10.1. | |
| Title | beam_mcp: nested tool argument constraints advertised but not enforced | |
| First Time appeared |
Scriptkittyos
Scriptkittyos beam Mcp |
|
| Weaknesses | CWE-20 | |
| CPEs | cpe:2.3:a:scriptkittyos:beam_mcp:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Scriptkittyos
Scriptkittyos beam Mcp |
|
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: EEF
Published:
Updated: 2026-10-08T14:09:41.540Z
Reserved: 2026-10-07T22:15:01.878Z
Link: CVE-2026-88257
Updated: 2026-10-08T13:59:26.255Z
Status : Received
Published: 2026-10-08T14:17:01.613
Modified: 2026-10-08T15:17:56.367
Link: CVE-2026-88257
No data.
OpenCVE Enrichment
No data.
-
CWE-20
Improper Input Validation