Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-2v2f-mvfg-ph56 | meta-ads-mcp: X-Pipeboard-Token Header Auth Bypass Reuses Operator Meta Token |
Tue, 15 Sep 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pipeboard-co
Pipeboard-co meta-ads-mcp |
|
| Vendors & Products |
Pipeboard-co
Pipeboard-co meta-ads-mcp |
Tue, 15 Sep 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.115, AuthInjectionMiddleware in meta_ads_mcp/core/http_auth_integration.py rejects HTTP MCP requests only when both auth_token and pipeboard_token are absent, while extract_token_from_headers() does not recognize X-Pipeboard-Token as a primary credential. A network caller using the streamable-http transport can therefore send any X-Pipeboard-Token value, pass the guard without establishing authentication context, and cause get_auth_token() to fall back to the server operator's META_ACCESS_TOKEN. Subsequent MCP tools execute with the operator's Meta credentials and can read or modify the operator's Meta Ads data. Deployments using the default stdio transport or without META_ACCESS_TOKEN are not affected. This issue is fixed in version 1.0.115. | |
| Title | Meta Ads MCP: X-Pipeboard-Token Header Auth Bypass Reuses Operator Meta Token | |
| Weaknesses | CWE-287 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-15T17:17:17.216Z
Reserved: 2026-06-15T19:04:14.456Z
Link: CVE-2026-54547
No data.
Status : Received
Published: 2026-09-15T18:17:22.927
Modified: 2026-09-15T18:17:22.927
Link: CVE-2026-54547
No data.
OpenCVE Enrichment
Updated: 2026-09-15T21:00:17Z

Github GHSA