Fetching from the wire…
Public story · 2026-08-23 · high
CVE-2026-75130 hits one of the most installed MCP servers in coding agents, and Upstash hasn't shipped a fix.
Why now: NVD published CVE-2026-75130 on August 18, and no fix was documented as of August 23.
Context7's MCP server exfiltrates .env files during a routine documentation lookup, per an NVD advisory published August 18. CVE-2026-75130 covers Upstash's Context7 through version 2.1.2, and Context7 is one of the most commonly installed MCP servers in coding agents. No fix is documented as of August 23.
The Custom AI Instructions feature serves unsanitized content through the MCP server. Poisoned instructions riding along with that content can exfiltrate credentials from environment files to an attacker-controlled service, then delete files.
NVD's own listing carries a CVSS 4.0 base score of 6.4 from VulnCheck, with high subsequent-system impact factored in. Secondary coverage quotes 9.0 under the older CVSS 3.1 scale for the same bug.
The trigger is a standard library documentation request, the same call Context7 exists to answer, not a malicious prompt or pasted-in script.
Upstash hasn't published a patch. A server-side sanitization fix and a configuration workaround pushed onto agent operators would leave very different amounts of exposure behind.
Each link below shares sources, entities, or timing with this story.
Claude Code uses MCP / Shared entities / Shared topic / Earlier coverage
Linked by a graph relationship (Claude Code uses MCP); both cover August, CVE, CVSS, NVD; overlapping topics (agent, credential, cvss, instruction).
Claude uses MCP / Shared entities / Same source domain / Shared topic / What happened next
Linked by a graph relationship (Claude uses MCP); both cover August, CVE, CVSS, NVD; reported by the same outlet (nvd.nist.gov).
Cloudflare supports MCP / Shared entities / Shared topic / Earlier coverage
Linked by a graph relationship (Cloudflare supports MCP); both cover August, CVE, CVSS, MCP; overlapping topics (august, cvss, server).
MCP uses OAuth / Shared entities / Shared topic / Earlier coverage
Linked by a graph relationship (MCP uses OAuth); both cover August, Context7, MCP; overlapping topics (august, context7, credential).
MCP partners with Linux Foundation / Shared entities / Shared topic / Earlier coverage
Linked by a graph relationship (MCP partners with Linux Foundation); both cover Context7, MCP, Upstash; overlapping topics (agent, context7, server).
MCP uses Docker / Shared entities / Shared topic / Earlier coverage
Linked by a graph relationship (MCP uses Docker); both cover August, CVE, MCP; overlapping topics (agent, august).
Google released MCP / Shared entities / Shared topic / Earlier coverage
Linked by a graph relationship (Google released MCP); both cover CVE, CVSS, MCP; overlapping topics (agent, server).
Claude Code uses MCP / Shared entities / Shared topic / Earlier coverage
Linked by a graph relationship (Claude Code uses MCP); both cover CVE, CVSS, MCP; overlapping topics (cvss, server).