Executive brief
HashiCorp consul-mcp-server is a tool that allows AI agents to interact with Consul infrastructure. A security flaw in how the server handles user sessions means that one user's secret authentication token could be accidentally reused for a different user's request. This could allow an unauthorized person to perform actions or access data in the Consul cluster using someone else's identity.
Technical details
The vulnerability is a session isolation failure (CWE-488) within the consul-mcp-server when configured in stateless transport mode. The server maintains a per-session cache of authenticated Consul clients but fails to correctly segregate these sessions in stateless mode. As a result, an authenticated Consul client object (and its associated token) belonging to one session may be reused for subsequent requests from a different client. An attacker can exploit this to execute tool calls or Consul API requests using the credentials of another active user. The issue is resolved in version 0.1.4; stateful mode deployments are not affected.
Affected products
- HashiCorp consul-mcp-server 0.1.0 to 0.1.3
Timeline
- 2026-07-29: disclosed
- 2026-07-29: advisory
- 2026-07-29: patched: Fixed in version 0.1.4