Improper Signature Verification in Hyper-MCP Affects WebAssembly Plugins
CVE-2026-108699
8.3HIGH
What is CVE-2026-108699?
The Hyper-MCP tool, up to version 0.8.3, is exposed to an improper signature verification vulnerability that permits malicious actors to load harmful WebAssembly plugins. This occurs because the cosign_verify_args() function accepts any signer identity and OIDC issuer by default. Attackers can exploit this flaw by controlling a plugin image reference, allowing them to sign a malicious image with a free Sigstore keyless certificate. Once executed, these plugins can operate with full access to the host, filesystem, and environment capabilities, posing significant security risks to users.
Affected Version(s)
hyper-mcp 0 <= 0.8.3
