
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-25905 is a lack-of-isolation vulnerability in the mcp-run-python package that allows Python code executed via runPython or runPythonAsync to access Pyodide APIs and modify the JavaScript environment, enabling MCP server takeover. It was discovered by Natan Nehorai of the JFrog Security Research Team and published on February 9, 2026. All versions of mcp-run-python are affected; the project has since been archived and is unlikely to receive a patch. It carries a CVSS v3.1 base score of 5.8 (Medium) (JFrog Research, Red Hat CVE).
The root cause is classified as CWE-653 (Improper Isolation or Compartmentalization): Python code submitted to the run_python_code tool runs inside a Pyodide WebAssembly environment but is not sandboxed from the surrounding JavaScript context. Because Pyodide exposes a js module and pyodide_js bindings, malicious Python can call js.eval() to inject arbitrary JavaScript functions, including monkey-patching built-ins such as JSON.stringify. This allows an attacker to intercept and manipulate all JSON-RPC messages exchanged between the MCP server and its clients. A full proof-of-concept demonstrating MCP tool shadowing (renaming tools and injecting fake server metadata) was published by JFrog alongside the advisory (JFrog Research).
Successful exploitation allows an attacker to hijack the MCP server by modifying its JavaScript runtime environment, enabling MCP tool shadowing — where legitimate tools are replaced or renamed with attacker-controlled counterparts. This compromises confidentiality (low), integrity (low), and availability (low) of the MCP server and any AI agent or client relying on it, and the changed scope means impacts extend beyond the vulnerable component itself. In a corporate or agentic AI context, a compromised MCP server could serve as a backdoor, redirecting AI tool calls to malicious endpoints or exfiltrating data processed by the server (JFrog Research, Red Hat CVE).
A public proof-of-concept exploit was released by JFrog at the time of disclosure (February 9, 2026), demonstrating full MCP tool shadowing with a self-contained Python payload. Exploitation requires network access, user interaction (a client must connect and invoke the tool), and high attack complexity, but no privileges are required. The EPSS score is approximately 0.032% (0.000320), indicating low current automated exploitation probability. No CISA KEV listing or confirmed in-the-wild exploitation has been reported as of the available data (JFrog Research, Feedly).
mcp-run-python server using uvx mcp-run-python --port 3001 --verbose streamable-http.set MCP_AUTO_OPEN_ENABLED=false && npx @modelcontextprotocol/inspector) and connect to http://localhost:3001/mcp using the Streamable HTTP transport type in Firefox.run_python_code tool is available.pyodide_js and js, then uses js.eval() to define a JavaScript function that monkey-patches JSON.stringify. The injected function intercepts JSON-RPC responses and modifies tool listings (e.g., renaming run_python_code to Hijacked Tool) and server metadata.notifications/tools/list_changed notification to the client.Hijacked Tool), and the server identity has been replaced with attacker-supplied metadata, demonstrating full MCP server hijack (JFrog Research).notifications/tools/list_changed JSON-RPC notifications from the MCP server shortly after a run_python_code tool invocation; MCP server responses containing modified serverInfo fields (e.g., unexpected version strings like 9.9.99 or server names like MCP Run Python 1337).console.log output containing stringify called with param: y= — a marker left by the PoC payload; tool list responses where tool names or titles differ from the originally registered tools.js.eval() calls originating from within the Pyodide Python execution context; JSON.stringifyOriginal property being set on the JSON global object in the server's JS environment, indicating monkey-patching has occurred.run_python_code containing import pyodide_js or import js combined with js.eval( patterns, which are not typical for legitimate use cases (JFrog Research).No official patch exists and none is expected, as the mcp-run-python project has been archived by its maintainers. JFrog explicitly states no mitigations are supplied for this issue. Organizations using mcp-run-python should immediately discontinue its use and migrate to an actively maintained MCP Python execution alternative that enforces proper sandbox isolation. As a compensating control, restrict network access to MCP server endpoints and audit all Python code submitted to run_python_code for use of pyodide_js or js module imports (JFrog Research, GitLab Advisory).
JFrog Security Research published the initial advisory and PoC on February 9, 2026, framing the issue as a significant risk in the emerging MCP/agentic AI ecosystem (JFrog Research). Security blogger Kai Security AI published multiple dev.to articles contextualizing CVE-2026-25905 alongside related MCP vulnerabilities, describing the pattern as "when the Python sandbox becomes the weapon" and warning about MCP servers becoming corporate backdoors (dev.to Kai Security). A Telegraph post titled "When the Sandbox Is the Vulnerability" further amplified community concern about the broader class of MCP isolation failures. Red Hat tracked the CVE but assigned no specific product impact, reflecting the niche but growing relevance of MCP tooling in enterprise AI deployments.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."