CVE-2026-13341
KongHQ mcp-konnect
A vulnerability exists in the Kong Konnect Model Context Protocol (MCP) server prior to version 1.0.0, which could allow a remote attacker to perform an indirect prompt injection attack and execute unintended API requests.
- CVSS
- 7.4
- EPSS
- 0.26% 17.5% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.03