Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 11 Oct 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | hyper-mcp through 0.8.3 contains a signature verification bypass vulnerability in load_wasm in src/wasm/oci.rs that verifies the Cosign signature of a separately resolved tag rather than the loaded manifest. Attackers controlling registry responses for the tag can serve an unsigned malicious manifest to the loader and a signed one to Cosign, executing unsigned WebAssembly plugins with configured host capabilities. | |
| Title | hyper-mcp through 0.8.3 OCI Plugin Signature Verification TOCTOU Race Condition | |
| Weaknesses | CWE-367 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-11T13:25:58.805Z
Reserved: 2026-10-10T23:08:36.107Z
Link: CVE-2026-108698
No data.
Status : Received
Published: 2026-10-11T14:17:04.113
Modified: 2026-10-11T14:17:04.113
Link: CVE-2026-108698
No data.
OpenCVE Enrichment
No data.
-
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition