{"id":"PYSEC-2026-2628","summary":"MCP Run Python has a Sandbox Escape & Server Takeover Vulnerability","details":"### Impact\n**Critical Sandbox Escape & Server Takeover:**\nA critical security vulnerability exists in `mcp-run-python` due to a lack of isolation between the Python runtime (Pyodide) and the host JavaScript environment.\n\nThe `runPython` and `runPythonAsync` functions execute Python code using Pyodide without restricting access to the JavaScript bridge. This allows any executed Python code—whether from a user or an AI model—to access the `js` module in Pyodide. Through this bridge, the Python code can modify the global JavaScript environment, interact with the Node.js process, and alter the behavior of the MCP server.\n\n**Specific Attack Vector: MCP Tool Shadowing**\nBecause the Python code can modify the JS runtime, an attacker can dynamically overwrite or \"shadow\" existing MCP tools registered on the server. For example, an attacker could replace a secure file-reading tool with a malicious version that exfiltrates data to an external server, all while the MCP server appears to be functioning normally.\n\n### Patches\n**No Patch Available:**\nThe `mcp-run-python` project is currently **archived** and maintainers have indicated it is unlikely to receive a fix.\n\n**Recommendation:**\nUsers are strongly advised to **immediately stop using** this package.\nIf functionality is required, users must migrate to a maintained alternative that implements proper sandboxing (e.g., running Python in a Docker container or a restricted WASM environment with the JS bridge disabled).\n\n### Workarounds\nThere are no configuration-based workarounds. Securing the environment requires modifying the source code to disable the Pyodide-to-JS bridge or moving the execution environment to a fully isolated sandbox (e.g., a separate container).\n\n### Resources\n* [CVE-2026-25905](https://nvd.nist.gov/vuln/detail/CVE-2026-25905)\n* [JFrog Security Analysis: MCP Takeover](https://research.jfrog.com/vulnerabilities/mcp-run-python-lack-of-isolation-mcp-takeover-jfsa-2026-001653030)","aliases":["CVE-2026-25905","GHSA-pfv4-wmph-5gc6"],"modified":"2026-07-13T16:32:13.788582967Z","published":"2026-07-13T14:36:35.284150Z","references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-25905"},{"type":"PACKAGE","url":"https://github.com/pydantic/mcp-run-python"},{"type":"WEB","url":"https://research.jfrog.com/vulnerabilities/mcp-run-python-lack-of-isolation-mcp-takeover-jfsa-2026-001653030"},{"type":"PACKAGE","url":"https://pypi.org/project/mcp-run-python"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-pfv4-wmph-5gc6"}],"affected":[{"package":{"name":"mcp-run-python","ecosystem":"PyPI","purl":"pkg:pypi/mcp-run-python"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"0.0.22"}]}],"versions":["0.0.1","0.0.2","0.0.20","0.0.21","0.0.22"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/mcp-run-python/PYSEC-2026-2628.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L"}]}