Remote Code Execution Vulnerability in LINE Desktop MCP for Windows and Mac
CVE-2026-49357

8.8HIGH

Key Information:

Vendor

Dtwang

Vendor
CVE Published:
19 June 2026

What is CVE-2026-49357?

The LINE Desktop MCP project, intended for integration with the official LINE Desktop application on Windows and Mac, presents a significant security concern. Prior to version 1.1.2, the application allowed unauthorized users to access the MCP /mcp endpoint due to a lack of adequate authentication checks. This flaw enabled any network client to initiate a session and interact with the LINE Desktop app, creating potential risks for exposure of chat histories and unauthorized message sending. Users are encouraged to upgrade to version 1.1.2 or later to mitigate these vulnerabilities.

Affected Version(s)

line-desktop-mcp < 1.1.2

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.