Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-27549 | An issue was discovered in mcp-neo4j 0.3.0 allowing attackers to obtain sensitive information or execute arbitrary commands via the SSE service. NOTE: the Supplier's position is that authentication is not mandatory for MCP servers, and the mcp-neo4j MCP server is only intended for use in a local environment where authentication realistically would not be needed. Also, the Supplier provides middleware to help isolate the MCP server from external access (if needed). |
Tue, 16 Sep 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue was discovered in mcp-neo4j 0.3.0 allowing attackers to gain sensitive information or execute arbitrary commands via the SSE service. | An issue was discovered in mcp-neo4j 0.3.0 allowing attackers to obtain sensitive information or execute arbitrary commands via the SSE service. NOTE: the Supplier's position is that authentication is not mandatory for MCP servers, and the mcp-neo4j MCP server is only intended for use in a local environment where authentication realistically would not be needed. Also, the Supplier provides middleware to help isolate the MCP server from external access (if needed). |
| References |
|
Fri, 12 Sep 2025 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Neo4j
Neo4j neo4j Neo4j-contrib Neo4j-contrib mcp-neo4j |
|
| Vendors & Products |
Neo4j
Neo4j neo4j Neo4j-contrib Neo4j-contrib mcp-neo4j |
Wed, 10 Sep 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-200 CWE-284 CWE-77 |
|
| Metrics |
cvssV3_1
|
Wed, 10 Sep 2025 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue was discovered in mcp-neo4j 0.3.0 allowing attackers to gain sensitive information or execute arbitrary commands via the SSE service. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-09-16T12:59:07.639Z
Reserved: 2025-08-16T00:00:00.000Z
Link: CVE-2025-56406
Updated: 2025-09-10T14:00:04.154Z
Status : Deferred
Published: 2025-09-10T14:15:39.567
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-56406
No data.
OpenCVE Enrichment
Updated: 2025-09-12T09:11:28Z
EUVD