Context7 MCP documentation-server prompt injection (CVE-2026-75130)
Disclosed vulnerability18 Aug 2026A real NVD-tracked prompt-injection CVE in a mainstream MCP server, versus prior PoC and benchmark work in the library, demonstrating the low-privilege-server to high-privilege-agent trust-delegation gap and the critical-CVE-with-no-documented-fix problem in the MCP ecosystem. CVSS and affected version are per NVD.
Risks it illustrates
Sources
Practise the risk class — related scenarios
Interactive simulations of the risk class this case illustrates (not a re-enactment of this specific event).
An 'Ask AI' button quietly plants a permanent 'trusted source' rule in your assistant's memory
A support email hides instructions — and the assistant obeys them
A poisoned issue makes the agent lie to the human who approves its actions
Compromise the pipeline that builds agents, and every new worker is born malicious
An auto-approving coding agent reads a poisoned page — and executes code it never should have
A fake Sentry error report hijacks a developer's coding agent into running a shell command
The forensic record is itself the attack surface — an agent's log is poisoned, then quietly rewritten
A newsletter the user asked to summarise quietly writes a false 'fact' into the agent's long-term memory — and it detonates weeks later
A shopping page tells the agent to do something the user never asked for
One click provisions an attacker-configured agent inside your own workspace
An attacker plants prompt injection in the audit trail — so the LLM that hunts them erases the evidence
A single poisoned document plants a standing instruction that survives every reset
Encoded public text is laundered across an agent handoff into an on-chain transfer
A cost-saving open-weights swap quietly ships a model with its safety surgically removed
A screenshot that's harmless at full size becomes an order once the system shrinks it
A capable third-party model that behaves perfectly — until it sees the trigger
A trusted MCP email tool quietly BCCs every message to an attacker
The eval gate that was supposed to catch the agent is itself the thing being attacked
A poisoned web page hijacks a research agent — and the planner acts on its behalf
An inbox summary quietly ships a secret to an attacker's server