{"id":"CVE-2026-88257","summary":"beam_mcp: nested tool argument constraints advertised but not enforced","details":"Improper Input Validation vulnerability in BeamMCP.Schema in ScriptKittyOS beam_mcp allows an MCP client to reach a tool's dispatch function with arguments that violate the input schema the server advertised. BeamMCP.Schema.validate/2 checked type, required, additionalProperties, enum and numeric bounds on the top-level arguments object only. Constraints inside nested objects and on array items (items, minItems, maxItems, minLength, maxLength, pattern, nested required, enum and additionalProperties: false) were advertised by tools/list and never checked at tools/call or prompts/get, and keywords outside the enforced subset (oneOf, anyOf, $ref) were advertised and ignored.\n\nA host whose dispatch code relies on the schema it declared receives values the schema forbids, such as an out-of-range number or an undeclared key inside a nested object. What the host does with such a value decides the impact.\n\nThis issue affects beam_mcp: from 0.1.0 before 0.10.1.","aliases":["EEF-CVE-2026-88257","GHSA-mrg2-4747-fmpw"],"modified":"2026-10-09T02:49:26.379609281Z","published":"2026-10-08T13:40:55.828Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/88xxx/CVE-2026-88257.json","cna_assigner":"EEF","cwe_ids":["CWE-20"]},"references":[{"type":"WEB","url":"https://cna.erlef.org/cves/CVE-2026-88257.html"},{"type":"WEB","url":"https://github.com"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/88xxx/CVE-2026-88257.json"},{"type":"PACKAGE","url":"https://github.com/ScriptKittyOS/beam_mcp"},{"type":"FIX","url":"https://github.com/ScriptKittyOS/beam_mcp/commit/083838eb8e17fe5f6fcaf761bdbe203110288b0b"},{"type":"FIX","url":"https://github.com/ScriptKittyOS/beam_mcp/commit/289dbdbad641943b29a3b8d1eb36506cc8cec10a"},{"type":"ADVISORY","url":"https://github.com/ScriptKittyOS/beam_mcp/security/advisories/GHSA-mrg2-4747-fmpw"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-88257"},{"type":"WEB","url":"https://osv.dev/vulnerability/EEF-CVE-2026-88257"},{"type":"WEB","url":"https://repo.hex.pm"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/ScriptKittyOS/beam_mcp","events":[{"introduced":"083838eb8e17fe5f6fcaf761bdbe203110288b0b"},{"fixed":"289dbdbad641943b29a3b8d1eb36506cc8cec10a"}]}],"versions":["v0.10.0","v0.9.0","v0.8.0","v0.7.0","v0.6.0","v0.5.0","v0.4.0","v0.3.1","v0.3.0","v0.2.0","v0.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-88257.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/scriptkittyos/beam_mcp","events":[{"introduced":"2add129e65d04759ce67c77520208b854c05dcee"},{"fixed":"04548e143256729eb2cc99690861037c5372dbe8"}],"database_specific":{"extracted_events":[{"introduced":"0.1.0"},{"fixed":"0.10.1"}],"source":"AFFECTED_FIELD"}}],"versions":["v0.10.0","v0.9.0","v0.8.0","v0.7.0","v0.6.0","v0.5.0","v0.4.0","v0.3.1","v0.3.0","v0.2.0","v0.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-88257.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"}]}