{"id":"CVE-2026-48989","aliases":["GHSA-vrxg-gm77-7q5g","PYSEC-2026-3425"],"url":"https://o3.security/vulnerability/CVE-2026-48989","summary":"Windows-MCP: HTTP transports expose unauthenticated PowerShell control with wildcard CORS","details":"Windows-MCP is an open-source project that integrates AI agents with Windows. In versions prior to 0.7.5, certain HTTP modes exposed the MCP control plane without authentication while enabling wildcard CORS (allow_origins=*, allow_methods=*, allow_headers=*). Because the same server also exposed a PowerShell tool that executes caller-controlled commands as the Windows user running Windows-MCP, attackers could reach the control plane from arbitrary origins or non-browser clients and achieve arbitrary PowerShell execution. This issue was fixed in version 0.7.5.","published":"2026-06-17T21:02:15.047Z","modified":"2026-08-12T03:51:14.188528271Z","cvss":null,"epss":{"score":0.00397,"percentile":0.32476,"asOf":"2026-08-10"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"windows-mcp","fixedVersion":"0.7.5"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/CursorTouch/Windows-MCP/releases/tag/v0.7.5"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/48xxx/CVE-2026-48989.json"},{"type":"ADVISORY","url":"https://github.com/CursorTouch/Windows-MCP/security/advisories/GHSA-vrxg-gm77-7q5g"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48989"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:14.188528271Z"}}