{"api_version":"1","generated_at":"2026-10-08T21:45:31+00:00","cve":"CVE-2026-88257","urls":{"html":"https://cve.report/CVE-2026-88257","api":"https://cve.report/api/cve/CVE-2026-88257.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-88257","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-88257"},"summary":{"title":"beam_mcp: nested tool argument constraints advertised but not enforced","description":"Improper Input Validation vulnerability in BeamMCP.Schema in ScriptKittyOS beam_mcp allows an MCP client to reach a tool's dispatch function with arguments that violate the input schema the server advertised. BeamMCP.Schema.validate/2 checked type, required, additionalProperties, enum and numeric bounds on the top-level arguments object only. Constraints inside nested objects and on array items (items, minItems, maxItems, minLength, maxLength, pattern, nested required, enum and additionalProperties: false) were advertised by tools/list and never checked at tools/call or prompts/get, and keywords outside the enforced subset (oneOf, anyOf, $ref) were advertised and ignored.\n\nA host whose dispatch code relies on the schema it declared receives values the schema forbids, such as an out-of-range number or an undeclared key inside a nested object. What the host does with such a value decides the impact.\n\nThis issue affects beam_mcp: from 0.1.0 before 0.10.1.","state":"PUBLISHED","assigner":"EEF","published_at":"2026-10-08 14:17:01","updated_at":"2026-10-08 21:01:07"},"problem_types":["CWE-20","CWE-20 CWE-20 Improper Input Validation"],"metrics":[{"version":"4.0","source":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db","type":"Secondary","score":"5.3","severity":"MEDIUM","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","data":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}},{"version":"4.0","source":"CNA","type":"CVSS","score":"5.3","severity":"MEDIUM","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","data":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":5.3,"baseSeverity":"MEDIUM","privilegesRequired":"LOW","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"LOW","vulnerabilityResponseEffort":"NOT_DEFINED"}}],"references":[{"url":"https://cna.erlef.org/cves/CVE-2026-88257.html","name":"https://cna.erlef.org/cves/CVE-2026-88257.html","refsource":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/ScriptKittyOS/beam_mcp/commit/083838eb8e17fe5f6fcaf761bdbe203110288b0b","name":"https://github.com/ScriptKittyOS/beam_mcp/commit/083838eb8e17fe5f6fcaf761bdbe203110288b0b","refsource":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/ScriptKittyOS/beam_mcp/commit/289dbdbad641943b29a3b8d1eb36506cc8cec10a","name":"https://github.com/ScriptKittyOS/beam_mcp/commit/289dbdbad641943b29a3b8d1eb36506cc8cec10a","refsource":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/ScriptKittyOS/beam_mcp/security/advisories/GHSA-mrg2-4747-fmpw","name":"https://github.com/ScriptKittyOS/beam_mcp/security/advisories/GHSA-mrg2-4747-fmpw","refsource":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://osv.dev/vulnerability/EEF-CVE-2026-88257","name":"https://osv.dev/vulnerability/EEF-CVE-2026-88257","refsource":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-88257","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-88257","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"ScriptKittyOS","product":"beam_mcp","version":"affected 0.1.0 0.10.1 semver","platforms":[]},{"source":"CNA","vendor":"ScriptKittyOS","product":"beam_mcp","version":"affected 083838eb8e17fe5f6fcaf761bdbe203110288b0b 289dbdbad641943b29a3b8d1eb36506cc8cec10a git","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[{"source":"CNA","title":"","value":"Re-validate the arguments inside the host's dispatch function against every constraint the schema declares below the top level, or move each constraint to a top-level property, which the affected versions do enforce.","time":"","lang":"en"}],"exploits":[],"credits":[{"source":"CNA","value":"Ayla Croft / Script Kitty OS","lang":"en"},{"source":"CNA","value":"Ayla Croft / Script Kitty OS","lang":"en"},{"source":"CNA","value":"Ayla Croft / Script Kitty OS","lang":"en"},{"source":"CNA","value":"Jonatan Männchen / EEF","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-88257","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-10-08T13:59:14.866448Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-10-08T13:59:33.374Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"collectionURL":"https://repo.hex.pm","cpes":["cpe:2.3:a:scriptkittyos:beam_mcp:*:*:*:*:*:*:*:*"],"defaultStatus":"unaffected","modules":["'Elixir.BeamMCP.Schema'","'Elixir.BeamMCP.Server'"],"packageName":"beam_mcp","packageURL":"pkg:hex/beam_mcp","product":"beam_mcp","programFiles":["lib/beam_mcp/schema.ex","lib/beam_mcp/server.ex"],"programRoutines":[{"name":"'Elixir.BeamMCP.Schema':validate/2"},{"name":"'Elixir.BeamMCP.Server':handle_message/2"}],"repo":"https://github.com/ScriptKittyOS/beam_mcp","vendor":"ScriptKittyOS","versions":[{"lessThan":"0.10.1","status":"affected","version":"0.1.0","versionType":"semver"}]},{"collectionURL":"https://github.com","cpes":["cpe:2.3:a:scriptkittyos:beam_mcp:*:*:*:*:*:*:*:*"],"defaultStatus":"unaffected","modules":["'Elixir.BeamMCP.Schema'","'Elixir.BeamMCP.Server'"],"packageName":"scriptkittyos/beam_mcp","packageURL":"pkg:github/scriptkittyos/beam_mcp","product":"beam_mcp","programFiles":["lib/beam_mcp/schema.ex","lib/beam_mcp/server.ex"],"programRoutines":[{"name":"'Elixir.BeamMCP.Schema':validate/2"},{"name":"'Elixir.BeamMCP.Server':handle_message/2"}],"repo":"https://github.com/ScriptKittyOS/beam_mcp","vendor":"ScriptKittyOS","versions":[{"lessThan":"289dbdbad641943b29a3b8d1eb36506cc8cec10a","status":"affected","version":"083838eb8e17fe5f6fcaf761bdbe203110288b0b","versionType":"git"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:a:scriptkittyos:beam_mcp:*:*:*:*:*:*:*:*","versionEndExcluding":"0.10.1","versionStartIncluding":"0.1.0","vulnerable":true}],"negate":false,"operator":"OR"}],"operator":"AND"}],"credits":[{"lang":"en","type":"finder","value":"Ayla Croft / Script Kitty OS"},{"lang":"en","type":"reporter","value":"Ayla Croft / Script Kitty OS"},{"lang":"en","type":"remediation developer","value":"Ayla Croft / Script Kitty OS"},{"lang":"en","type":"coordinator","value":"Jonatan Männchen / EEF"}],"dateAssigned":"2026-10-08T13:40:44.000Z","datePublic":"2026-09-26T00:00:00.000Z","descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>Improper Input Validation vulnerability in <code>BeamMCP.Schema</code> in ScriptKittyOS beam_mcp allows an MCP client to reach a tool's dispatch function with arguments that violate the input schema the server advertised. <code>BeamMCP.Schema.validate/2</code> checked <code>type</code>, <code>required</code>, <code>additionalProperties</code>, <code>enum</code> and numeric bounds on the top-level arguments object only. Constraints inside nested objects and on array items (<code>items</code>, <code>minItems</code>, <code>maxItems</code>, <code>minLength</code>, <code>maxLength</code>, <code>pattern</code>, nested <code>required</code>, <code>enum</code> and <code>additionalProperties: false</code>) were advertised by <code>tools/list</code> and never checked at <code>tools/call</code> or <code>prompts/get</code>, and keywords outside the enforced subset (<code>oneOf</code>, <code>anyOf</code>, <code>$ref</code>) were advertised and ignored.</p>\n<p>A host whose dispatch code relies on the schema it declared receives values the schema forbids, such as an out-of-range number or an undeclared key inside a nested object. What the host does with such a value decides the impact.</p>\n<p>This issue affects beam_mcp: from 0.1.0 before 0.10.1.</p>"},{"base64":false,"type":"text/markdown","value":"Improper Input Validation vulnerability in `BeamMCP.Schema` in ScriptKittyOS beam_mcp allows an MCP client to reach a tool's dispatch function with arguments that violate the input schema the server advertised. `BeamMCP.Schema.validate/2` checked `type`, `required`, `additionalProperties`, `enum` and numeric bounds on the top-level arguments object only. Constraints inside nested objects and on array items (`items`, `minItems`, `maxItems`, `minLength`, `maxLength`, `pattern`, nested `required`, `enum` and `additionalProperties: false`) were advertised by `tools/list` and never checked at `tools/call` or `prompts/get`, and keywords outside the enforced subset (`oneOf`, `anyOf`, `$ref`) were advertised and ignored.\n\nA host whose dispatch code relies on the schema it declared receives values the schema forbids, such as an out-of-range number or an undeclared key inside a nested object. What the host does with such a value decides the impact.\n\nThis issue affects beam_mcp: from 0.1.0 before 0.10.1."}],"value":"Improper Input Validation vulnerability in BeamMCP.Schema in ScriptKittyOS beam_mcp allows an MCP client to reach a tool's dispatch function with arguments that violate the input schema the server advertised. BeamMCP.Schema.validate/2 checked type, required, additionalProperties, enum and numeric bounds on the top-level arguments object only. Constraints inside nested objects and on array items (items, minItems, maxItems, minLength, maxLength, pattern, nested required, enum and additionalProperties: false) were advertised by tools/list and never checked at tools/call or prompts/get, and keywords outside the enforced subset (oneOf, anyOf, $ref) were advertised and ignored.\n\nA host whose dispatch code relies on the schema it declared receives values the schema forbids, such as an out-of-range number or an undeclared key inside a nested object. What the host does with such a value decides the impact.\n\nThis issue affects beam_mcp: from 0.1.0 before 0.10.1."}],"impacts":[{"capecId":"CAPEC-153","descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>An MCP client can hand a host's tool values the host's declared schema forbids, such as an out-of-range number or an undeclared key inside a nested object. The consequence depends on what the host's dispatch code does with a value it never expected to receive.</p>"},{"base64":false,"type":"text/markdown","value":"An MCP client can hand a host's tool values the host's declared schema forbids, such as an out-of-range number or an undeclared key inside a nested object. The consequence depends on what the host's dispatch code does with a value it never expected to receive."}],"value":"An MCP client can hand a host's tool values the host's declared schema forbids, such as an out-of-range number or an undeclared key inside a nested object. The consequence depends on what the host's dispatch code does with a value it never expected to receive."}]}],"metrics":[{"cvssV4_0":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":5.3,"baseSeverity":"MEDIUM","privilegesRequired":"LOW","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"LOW","vulnerabilityResponseEffort":"NOT_DEFINED"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-20","description":"CWE-20 Improper Input Validation","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-10-08T14:09:41.540Z","orgId":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db","shortName":"EEF"},"references":[{"name":"GitHub Advisory","tags":["related","vendor-advisory"],"url":"https://github.com/ScriptKittyOS/beam_mcp/security/advisories/GHSA-mrg2-4747-fmpw"},{"name":"EEF CNA record for CVE-2026-88257","tags":["related"],"url":"https://cna.erlef.org/cves/CVE-2026-88257.html"},{"name":"OSV record EEF-CVE-2026-88257","tags":["related"],"url":"https://osv.dev/vulnerability/EEF-CVE-2026-88257"},{"name":"Introducing commit 083838e in ScriptKittyOS/beam_mcp","tags":["related"],"url":"https://github.com/ScriptKittyOS/beam_mcp/commit/083838eb8e17fe5f6fcaf761bdbe203110288b0b"},{"name":"Fix commit 289dbdb in ScriptKittyOS/beam_mcp","tags":["patch"],"url":"https://github.com/ScriptKittyOS/beam_mcp/commit/289dbdbad641943b29a3b8d1eb36506cc8cec10a"}],"source":{"discovery":"INTERNAL"},"title":"beam_mcp: nested tool argument constraints advertised but not enforced","workarounds":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>Re-validate the arguments inside the host's dispatch function against every constraint the schema declares below the top level, or move each constraint to a top-level property, which the affected versions do enforce.</p>"},{"base64":false,"type":"text/markdown","value":"Re-validate the arguments inside the host's dispatch function against every constraint the schema declares below the top level, or move each constraint to a top-level property, which the affected versions do enforce."}],"value":"Re-validate the arguments inside the host's dispatch function against every constraint the schema declares below the top level, or move each constraint to a top-level property, which the affected versions do enforce."}],"x_proofOfConcept":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<ol>\n<li>Declare a tool whose <code>input_schema</code> has a nested object property <code>opts</code> with <code>\"properties\": {\"level\": {\"type\": \"integer\", \"maximum\": 3}}</code>, <code>\"required\": [\"level\"]</code> and <code>\"additionalProperties\": false</code>, and an array property <code>tags</code> with <code>\"items\": {\"type\": \"string\"}</code> and <code>\"maxItems\": 2</code>.</li>\n<li>Send <code>tools/call</code> with <code>\"arguments\": {\"opts\": {\"level\": 99, \"extra\": \"x\"}}</code>.</li>\n<li>On beam_mcp 0.10.0 the dispatch function receives <code>%{opts: %{\"extra\" =&gt; \"x\", \"level\" =&gt; 99}}</code>. On 0.10.1 the call is refused with <code>invalid arguments: unknown property: opts.extra</code>.</li>\n<li>Send <code>\"arguments\": {\"tags\": [1, 2, 3]}</code>. On 0.10.0 the dispatch function receives <code>tags: [1, 2, 3]</code>. On 0.10.1 the call is refused with <code>tags must have at most 2 items</code>.</li>\n</ol>"},{"base64":false,"type":"text/markdown","value":"1. Declare a tool whose `input_schema` has a nested object property `opts` with `\"properties\": {\"level\": {\"type\": \"integer\", \"maximum\": 3}}`, `\"required\": [\"level\"]` and `\"additionalProperties\": false`, and an array property `tags` with `\"items\": {\"type\": \"string\"}` and `\"maxItems\": 2`.\n2. Send `tools/call` with `\"arguments\": {\"opts\": {\"level\": 99, \"extra\": \"x\"}}`.\n3. On beam_mcp 0.10.0 the dispatch function receives `%{opts: %{\"extra\" => \"x\", \"level\" => 99}}`. On 0.10.1 the call is refused with `invalid arguments: unknown property: opts.extra`.\n4. Send `\"arguments\": {\"tags\": [1, 2, 3]}`. On 0.10.0 the dispatch function receives `tags: [1, 2, 3]`. On 0.10.1 the call is refused with `tags must have at most 2 items`."}],"value":"* Declare a tool whose input_schema has a nested object property opts with \"properties\": {\"level\": {\"type\": \"integer\", \"maximum\": 3}}, \"required\": [\"level\"] and \"additionalProperties\": false, and an array property tags with \"items\": {\"type\": \"string\"} and \"maxItems\": 2.\n* Send tools/call with \"arguments\": {\"opts\": {\"level\": 99, \"extra\": \"x\"}}.\n* On beam_mcp 0.10.0 the dispatch function receives %{opts: %{\"extra\" => \"x\", \"level\" => 99}}. On 0.10.1 the call is refused with invalid arguments: unknown property: opts.extra.\n* Send \"arguments\": {\"tags\": [1, 2, 3]}. On 0.10.0 the dispatch function receives tags: [1, 2, 3]. On 0.10.1 the call is refused with tags must have at most 2 items."}],"x_technicalAnalysis":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p><strong>1. Advertising.</strong> <code>tools/list</code> returns each tool's <code>input_schema</code> verbatim, including nested <code>properties</code>, <code>items</code> and constraint keywords.</p>\n<p><strong>2. Validation.</strong> <code>BeamMCP.Schema.validate/2</code> in <code>lib/beam_mcp/schema.ex</code> walks only the first level: <code>check_required/2</code> and <code>check_additional/3</code> run on the top-level object, and <code>check_properties/2</code> applies <code>check_type</code>, <code>check_enum</code> and <code>check_range</code> to each top-level value. A value of type <code>object</code> or <code>array</code> is accepted once its own type matches, and its contents are not visited. Keywords the validator does not know are ignored.</p>\n<p><strong>3. Dispatch.</strong> <code>BeamMCP.Server.validate_and_dispatch/3</code> passes the accepted arguments to <code>normalize_arguments/2</code> and then to the host's dispatch function, so an undeclared key inside a nested object, an out-of-range nested number, or an array item of the wrong type reaches host code that believed the schema excluded it. The same validator runs on <code>prompts/get</code> arguments. The fix in 0.10.1 enforces every keyword of the documented subset at every depth and refuses a schema that uses any other keyword when the catalog is loaded.</p>"},{"base64":false,"type":"text/markdown","value":"**1. Advertising.** `tools/list` returns each tool's `input_schema` verbatim, including nested `properties`, `items` and constraint keywords.\n\n**2. Validation.** `BeamMCP.Schema.validate/2` in `lib/beam_mcp/schema.ex` walks only the first level: `check_required/2` and `check_additional/3` run on the top-level object, and `check_properties/2` applies `check_type`, `check_enum` and `check_range` to each top-level value. A value of type `object` or `array` is accepted once its own type matches, and its contents are not visited. Keywords the validator does not know are ignored.\n\n**3. Dispatch.** `BeamMCP.Server.validate_and_dispatch/3` passes the accepted arguments to `normalize_arguments/2` and then to the host's dispatch function, so an undeclared key inside a nested object, an out-of-range nested number, or an array item of the wrong type reaches host code that believed the schema excluded it. The same validator runs on `prompts/get` arguments. The fix in 0.10.1 enforces every keyword of the documented subset at every depth and refuses a schema that uses any other keyword when the catalog is loaded."}],"value":"1. Advertising. tools/list returns each tool's input_schema verbatim, including nested properties, items and constraint keywords.\n\n2. Validation. BeamMCP.Schema.validate/2 in lib/beam_mcp/schema.ex walks only the first level: check_required/2 and check_additional/3 run on the top-level object, and check_properties/2 applies check_type, check_enum and check_range to each top-level value. A value of type object or array is accepted once its own type matches, and its contents are not visited. Keywords the validator does not know are ignored.\n\n3. Dispatch. BeamMCP.Server.validate_and_dispatch/3 passes the accepted arguments to normalize_arguments/2 and then to the host's dispatch function, so an undeclared key inside a nested object, an out-of-range nested number, or an array item of the wrong type reaches host code that believed the schema excluded it. The same validator runs on prompts/get arguments. The fix in 0.10.1 enforces every keyword of the documented subset at every depth and refuses a schema that uses any other keyword when the catalog is loaded."}]}},"cveMetadata":{"assignerOrgId":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db","assignerShortName":"EEF","cveId":"CVE-2026-88257","datePublished":"2026-10-08T13:40:55.828Z","dateReserved":"2026-10-07T22:15:01.878Z","dateUpdated":"2026-10-08T14:09:41.540Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-10-08 14:17:01","lastModifiedDate":"2026-10-08 21:01:07","problem_types":["CWE-20","CWE-20 CWE-20 Improper Input Validation"],"metrics":{"cvssMetricV40":[{"source":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-10-08T13:59:14.866448Z","id":"CVE-2026-88257","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"88257","Ordinal":"1","Title":"beam_mcp: nested tool argument constraints advertised but not en","CVE":"CVE-2026-88257","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"88257","Ordinal":"1","NoteData":"Improper Input Validation vulnerability in BeamMCP.Schema in ScriptKittyOS beam_mcp allows an MCP client to reach a tool's dispatch function with arguments that violate the input schema the server advertised. BeamMCP.Schema.validate/2 checked type, required, additionalProperties, enum and numeric bounds on the top-level arguments object only. Constraints inside nested objects and on array items (items, minItems, maxItems, minLength, maxLength, pattern, nested required, enum and additionalProperties: false) were advertised by tools/list and never checked at tools/call or prompts/get, and keywords outside the enforced subset (oneOf, anyOf, $ref) were advertised and ignored.\n\nA host whose dispatch code relies on the schema it declared receives values the schema forbids, such as an out-of-range number or an undeclared key inside a nested object. What the host does with such a value decides the impact.\n\nThis issue affects beam_mcp: from 0.1.0 before 0.10.1.","Type":"Description","Title":"beam_mcp: nested tool argument constraints advertised but not en"}]}}}