Junglewise Threat Intelligence

CursorTouch Windows-MCP unauthenticated RCE in HTTP transports

Severity: high · CVSS 8.9 · Published 2026-05-21

Vendors: PyPI.

Executive brief

Windows-MCP is a tool that allows other applications to interact with Windows systems. A security flaw in its HTTP transport modes allows unauthorized users to remotely execute PowerShell commands on the host computer. This could lead to a complete system takeover, data theft, or service disruption by any attacker who can reach the network service.

Technical details

A vulnerability exists in the SSE and Streamable HTTP transport modes of Windows-MCP due to the absence of an authentication provider combined with a permissive wildcard CORS policy (allow_origins='*'). The FastMCP instance is initialized without security middleware, exposing the MCP control plane to any network-reachable client or cross-origin browser request. An attacker can initialize a session and invoke the 'PowerShell' tool to execute arbitrary commands as the user running the service. This issue affects versions prior to 0.7.5; the default stdio transport is not impacted.

Affected products

  • CursorTouch windows-mcp < 0.7.5

Timeline

  • 2026-05-14: disclosed
  • 2026-05-21: advisory: GitHub Advisory published
  • 2026-05-21: patched: Version 0.7.5 released

References

Related threats