Source · DiggingBeagle record
HTTP transports expose unauthenticated PowerShell control with wildcard CORS
Maintainer advisory for the Windows-MCP HTTP transport vulnerability later assigned CVE-2026-48989.
- Published
- May 14, 2026
- Accessed
- Sep 14, 2026
- Publisher
- CursorTouch / GitHub Security Advisory
- Source type
- primary
- Version
- 2026-05-14
- Rights
- Public web source; citation and short excerpt only.
Each support, contradiction or context label applies to a cited Claim, not to a whole Case.
Source record
Before 0.7.5, documented HTTP modes could expose an unauthenticated MCP control plane with wildcard CORS while also exposing a PowerShell tool.
Claim-level citations (3)
- supportsWindows-MCP HTTP modes exposed PowerShell behind a weak control plane: The maintainer advisory reports that Windows-MCP HTTP transports before 0.7.5 exposed the MCP control plane without authentication and used wildcard CORS.
Advisory description
- supportsWindows-MCP HTTP modes exposed PowerShell behind a weak control plane: The advisory states that the default stdio transport was not affected.
Advisory scope
- supportsWindows-MCP HTTP modes exposed PowerShell behind a weak control plane: The same server exposed a PowerShell tool that executed caller-controlled commands as the Windows user running Windows-MCP.
Advisory description
Cite this record
DiggingBeagle. “HTTP transports expose unauthenticated PowerShell control with wildcard CORS.” Published May 14, 2026 · Accessed Sep 14, 2026. https://diggingbeagle.com/sources/http-transports-expose-unauthenticated-powershell-control-with-wildcard-cors/
Citation guidance