Executive brief
Windows-MCP is a tool that allows other applications to interact with Windows systems. A security flaw in its HTTP transport modes allows unauthorized users to remotely execute PowerShell commands on the host computer. This could lead to a complete system takeover, data theft, or service disruption by any attacker who can reach the network service.
Technical details
A vulnerability exists in the SSE and Streamable HTTP transport modes of Windows-MCP due to the absence of an authentication provider combined with a permissive wildcard CORS policy (allow_origins='*'). The FastMCP instance is initialized without security middleware, exposing the MCP control plane to any network-reachable client or cross-origin browser request. An attacker can initialize a session and invoke the 'PowerShell' tool to execute arbitrary commands as the user running the service. This issue affects versions prior to 0.7.5; the default stdio transport is not impacted.
Affected products
- CursorTouch windows-mcp < 0.7.5
Timeline
- 2026-05-14: disclosed
- 2026-05-21: advisory: GitHub Advisory published
- 2026-05-21: patched: Version 0.7.5 released