Executive brief
line-desktop-mcp is an MCP integration tool that allows AI applications to read LINE chat history and send messages through a logged-in LINE Desktop application. In HTTP mode, the server binds to all network interfaces (0.0.0.0) and exposes MCP tools without requiring authentication, allowing any network-reachable client to read private conversations or send messages as the logged-in user. This is particularly dangerous in multi-user or cloud environments where the HTTP port may be accessible to untrusted parties.
Technical details
The vulnerability is a missing authentication check (CWE-306, CWE-862) in the Streamable HTTP mode implementation. When started with --http-mode, the Express.js server in src/server.js binds to 0.0.0.0 and exposes the /mcp endpoint via Streamable HTTP transport. The code creates MCP sessions and invokes tool handlers (including get_line_chatroom_history_* and send_message_*) without verifying caller identity or authorization. An unauthenticated network client that can reach the port can initialize a session, enumerate tools, and execute them to exfiltrate LINE chat history or send messages as the logged-in desktop user. No authentication is required—only network reachability to the MCP HTTP port. The vulnerability was patched in v1.1.2 by introducing optional Bearer Token authentication via --token flag and changing the default bind address to 127.0.0.1 to require explicit opt-in for network exposure.
Affected products
- dtwang line-desktop-mcp <= 1.1.1
Timeline
- 2026-06-26: disclosed: Advisory GHSA-4hf8-5mjm-rfgq published
- 2026-05-25: patched: Fix released in v1.1.2 with Bearer Token authentication and secure defaults