CVE-2026-25650: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-25650 is an information disclosure vulnerability in MCP Salesforce Connector (pip package mcp-salesforce-connector), a Model Context Protocol (MCP) server implementation for Salesforce integration. Arbitrary attribute access in the server's tool handler allows unauthenticated remote attackers to obtain Salesforce OAuth bearer tokens. All versions prior to 0.1.10 are affected. The vulnerability was published on February 6, 2026, with a fix released the same day. It carries a CVSS v3.1 score of 7.5 (High) and a CVSS v4.0 score of 8.7 (High) (Github Advisory, GitHub Security Advisory).

Technical details

The root cause is improper input validation when resolving Salesforce object names via Python's getattr() function (CWE-200: Exposure of Sensitive Information to an Unauthorized Actor). In the vulnerable handle_call_tool function in src/salesforce/server.py, the object_name parameter supplied by a caller was passed directly to getattr(sf_client.sf, object_name) without first verifying that the resolved attribute was a valid SFType Salesforce object. An attacker could supply an arbitrary attribute name — such as one referencing internal authentication state — causing the server to return the Salesforce OAuth bearer token in its response. The fix in version 0.1.10 adds a type check (isinstance(sf_object, SFType)) before the getattr call, rejecting any attribute that is not a legitimate Salesforce object type (GitHub Commit, Github Advisory).

Impact

Successful exploitation results in full disclosure of the Salesforce OAuth bearer token used by the MCP server, with no impact on integrity or availability of the connector itself. An attacker who obtains this token can authenticate directly to the victim's Salesforce environment, potentially accessing, exfiltrating, or modifying sensitive CRM data (contacts, opportunities, financial records, etc.) and performing unauthorized actions within the Salesforce tenant. Because the attack requires no authentication, no user interaction, and is reachable over the network, the exposure risk is significant for any organization running the vulnerable connector with network-accessible endpoints (Github Advisory, GitHub Security Advisory).

Exploitability

No public proof-of-concept exploit code has been identified, and there is no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.04% (0.000400), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Github Advisory).

Exploitation steps

  1. Reconnaissance: Identify deployments of mcp-salesforce-connector versions prior to 0.1.10 that are accessible over the network, using package version enumeration or MCP endpoint discovery.
  2. Craft malicious MCP tool call: Send a call_tool MCP request to the connector's server endpoint, targeting a tool that invokes handle_call_tool with an object_name parameter.
  3. Supply arbitrary attribute name: Set object_name to an internal attribute of the simple_salesforce.Salesforce client object that holds authentication credentials (e.g., the session ID or access token attribute), rather than a valid Salesforce object type.
  4. Receive token disclosure: Because the vulnerable code calls getattr(sf_client.sf, object_name) without type validation, the server resolves and returns the value of the specified attribute — including the OAuth bearer token — in the tool response.
  5. Leverage stolen token: Use the obtained Salesforce OAuth bearer token to authenticate directly to the victim's Salesforce API, enabling unauthorized data access or manipulation within the Salesforce environment (Github Advisory, GitHub Commit).

Indicators of compromise

  • Network: Unexpected or anomalous MCP tool call requests to the mcp-salesforce-connector service with non-standard object_name values (e.g., attribute names that do not correspond to Salesforce object types such as Account, Contact, Opportunity).
  • Logs: MCP server logs showing handle_call_tool invocations with object_name values that triggered ValueError: Invalid Salesforce object name (post-patch) or returned unexpected data types (pre-patch).
  • Salesforce Audit Logs: Salesforce login history or API activity logs showing access from unexpected IP addresses or user agents using the connector's OAuth token, particularly after the connector was exposed to untrusted networks.
  • Network: Outbound API calls to login.salesforce.com or Salesforce instance URLs originating from unexpected sources using the connector's session credentials.

Mitigation and workarounds

Upgrade mcp-salesforce-connector to version 0.1.10 or later, which introduces a type validation check to prevent arbitrary attribute access. As an immediate workaround for systems that cannot be patched immediately, rotate all Salesforce OAuth tokens and credentials used by the MCP-Salesforce connector to invalidate any tokens that may have been exposed. Additionally, restrict network access to the MCP Salesforce Connector service to only authorized and trusted hosts (Github Advisory, GitHub Release).

Community reactions

The vulnerability was noted in the context of a broader pattern of security issues in MCP ecosystem connectors. Community commentary highlighted CVE-2026-25650 as part of a wave of MCP-related CVEs, with articles discussing how MCP integrations can become "corporate backdoors" when authentication credentials are improperly protected. Researchers observed that CVSS scores may underrepresent the real-world risk of MCP token disclosure vulnerabilities given their potential for downstream Salesforce data access (dev.to/kai_security_ai, Telegraph).

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management