Junglewise Threat Intelligence

CVE-2026-49357: dtwang line-desktop-mcp missing authentication in Streamable HTTP mode

CVE-2026-49357 · Severity: high · CVSS 4 · Published 2026-06-19

Executive brief

line-desktop-mcp is an MCP integration tool that allows AI applications to read LINE chat history and send messages through a logged-in LINE Desktop application. In HTTP mode, the server binds to all network interfaces (0.0.0.0) and exposes MCP tools without requiring authentication, allowing any network-reachable client to read private conversations or send messages as the logged-in user. This is particularly dangerous in multi-user or cloud environments where the HTTP port may be accessible to untrusted parties.

Technical details

The vulnerability is a missing authentication check (CWE-306, CWE-862) in the Streamable HTTP mode implementation. When started with --http-mode, the Express.js server in src/server.js binds to 0.0.0.0 and exposes the /mcp endpoint via Streamable HTTP transport. The code creates MCP sessions and invokes tool handlers (including get_line_chatroom_history_* and send_message_*) without verifying caller identity or authorization. An unauthenticated network client that can reach the port can initialize a session, enumerate tools, and execute them to exfiltrate LINE chat history or send messages as the logged-in desktop user. No authentication is required—only network reachability to the MCP HTTP port. The vulnerability was patched in v1.1.2 by introducing optional Bearer Token authentication via --token flag and changing the default bind address to 127.0.0.1 to require explicit opt-in for network exposure.

Affected products

  • dtwang line-desktop-mcp <= 1.1.1

Timeline

  • 2026-06-26: disclosed: Advisory GHSA-4hf8-5mjm-rfgq published
  • 2026-05-25: patched: Fix released in v1.1.2 with Bearer Token authentication and secure defaults

References