CVE-2026-25905: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-25905 is a lack-of-isolation vulnerability in the mcp-run-python package that allows Python code executed via runPython or runPythonAsync to access Pyodide APIs and modify the JavaScript environment, enabling MCP server takeover. It was discovered by Natan Nehorai of the JFrog Security Research Team and published on February 9, 2026. All versions of mcp-run-python are affected; the project has since been archived and is unlikely to receive a patch. It carries a CVSS v3.1 base score of 5.8 (Medium) (JFrog Research, Red Hat CVE).

Technical details

The root cause is classified as CWE-653 (Improper Isolation or Compartmentalization): Python code submitted to the run_python_code tool runs inside a Pyodide WebAssembly environment but is not sandboxed from the surrounding JavaScript context. Because Pyodide exposes a js module and pyodide_js bindings, malicious Python can call js.eval() to inject arbitrary JavaScript functions, including monkey-patching built-ins such as JSON.stringify. This allows an attacker to intercept and manipulate all JSON-RPC messages exchanged between the MCP server and its clients. A full proof-of-concept demonstrating MCP tool shadowing (renaming tools and injecting fake server metadata) was published by JFrog alongside the advisory (JFrog Research).

Impact

Successful exploitation allows an attacker to hijack the MCP server by modifying its JavaScript runtime environment, enabling MCP tool shadowing — where legitimate tools are replaced or renamed with attacker-controlled counterparts. This compromises confidentiality (low), integrity (low), and availability (low) of the MCP server and any AI agent or client relying on it, and the changed scope means impacts extend beyond the vulnerable component itself. In a corporate or agentic AI context, a compromised MCP server could serve as a backdoor, redirecting AI tool calls to malicious endpoints or exfiltrating data processed by the server (JFrog Research, Red Hat CVE).

Exploitability

A public proof-of-concept exploit was released by JFrog at the time of disclosure (February 9, 2026), demonstrating full MCP tool shadowing with a self-contained Python payload. Exploitation requires network access, user interaction (a client must connect and invoke the tool), and high attack complexity, but no privileges are required. The EPSS score is approximately 0.032% (0.000320), indicating low current automated exploitation probability. No CISA KEV listing or confirmed in-the-wild exploitation has been reported as of the available data (JFrog Research, Feedly).

Exploitation steps

  1. Setup: Run the vulnerable mcp-run-python server using uvx mcp-run-python --port 3001 --verbose streamable-http.
  2. Connect a client: Launch the MCP Inspector tool (set MCP_AUTO_OPEN_ENABLED=false && npx @modelcontextprotocol/inspector) and connect to http://localhost:3001/mcp using the Streamable HTTP transport type in Firefox.
  3. Enumerate tools: In the Tools tab, click "List Tools" to confirm the run_python_code tool is available.
  4. Inject malicious Python payload: Paste a Python script into the tool input that imports pyodide_js and js, then uses js.eval() to define a JavaScript function that monkey-patches JSON.stringify. The injected function intercepts JSON-RPC responses and modifies tool listings (e.g., renaming run_python_code to Hijacked Tool) and server metadata.
  5. Trigger tool shadowing: Click "Run Tool". The server sends a notifications/tools/list_changed notification to the client.
  6. Verify takeover: Click "Clear" then "List Tools" — the tool name now reflects the attacker-controlled value (Hijacked Tool), and the server identity has been replaced with attacker-supplied metadata, demonstrating full MCP server hijack (JFrog Research).

Indicators of compromise

  • Network: Unexpected notifications/tools/list_changed JSON-RPC notifications from the MCP server shortly after a run_python_code tool invocation; MCP server responses containing modified serverInfo fields (e.g., unexpected version strings like 9.9.99 or server names like MCP Run Python 1337).
  • Logs: MCP server verbose logs showing console.log output containing stringify called with param: y= — a marker left by the PoC payload; tool list responses where tool names or titles differ from the originally registered tools.
  • Process/Runtime: Evidence of js.eval() calls originating from within the Pyodide Python execution context; JSON.stringifyOriginal property being set on the JSON global object in the server's JS environment, indicating monkey-patching has occurred.
  • File System: Presence of Python scripts submitted to run_python_code containing import pyodide_js or import js combined with js.eval( patterns, which are not typical for legitimate use cases (JFrog Research).

Mitigation and workarounds

No official patch exists and none is expected, as the mcp-run-python project has been archived by its maintainers. JFrog explicitly states no mitigations are supplied for this issue. Organizations using mcp-run-python should immediately discontinue its use and migrate to an actively maintained MCP Python execution alternative that enforces proper sandbox isolation. As a compensating control, restrict network access to MCP server endpoints and audit all Python code submitted to run_python_code for use of pyodide_js or js module imports (JFrog Research, GitLab Advisory).

Community reactions

JFrog Security Research published the initial advisory and PoC on February 9, 2026, framing the issue as a significant risk in the emerging MCP/agentic AI ecosystem (JFrog Research). Security blogger Kai Security AI published multiple dev.to articles contextualizing CVE-2026-25905 alongside related MCP vulnerabilities, describing the pattern as "when the Python sandbox becomes the weapon" and warning about MCP servers becoming corporate backdoors (dev.to Kai Security). A Telegraph post titled "When the Sandbox Is the Vulnerability" further amplified community concern about the broader class of MCP isolation failures. Red Hat tracked the CVE but assigned no specific product impact, reflecting the niche but growing relevance of MCP tooling in enterprise AI deployments.

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management