Описание
MCP-Salesforce's arbitrary attribute access leads to disclosure of Salesforce auth token
Impact
Disclosure of Salesforce OAuth bearer tokens used by the MCP.
Patches
fix applied in 0.1.10
Workarounds
Rotate any Salesforce tokens/credentials used by MCP-Salesforce.
Пакеты
Наименование
mcp-salesforce-connector
pip
Затронутые версииВерсия исправления
< 0.1.10
0.1.10