Signature Verification Bypass in Hyper-mcp Affects WebAssembly Plugin Security
CVE-2026-108698
8.3HIGH
What is CVE-2026-108698?
The hyper-mcp product up to version 0.8.3 contains a critical flaw where the signature verification process can be bypassed. This occurs in the load_wasm function, which mistakenly verifies the Cosign signature of a tag that has been resolved separately, rather than the actual loaded manifest. As a result, hackers with control over registry responses can deliver an unsigned malicious manifest while serving a signed one to Cosign. This enables unauthorized execution of unsigned WebAssembly plugins with the privileges configured by the host, potentially compromising system security.
Affected Version(s)
hyper-mcp 0 <= 0.8.3
