Junglewise Threat Intelligence

CVE-2026-81101: Airtable MCP CLI credential leakage via unchecked endpoint configuration

CVE-2026-81101 · Severity: medium · CVSS 6.5 · Published 2026-08-27

Executive brief

The Airtable MCP CLI's configure command accepts any endpoint URL and stores it alongside the user's personal access token. An attacker can trick a user into configuring a malicious endpoint, causing the CLI to send the user's authentication credentials to that attacker-controlled server on every subsequent use. This could lead to account compromise and unauthorized access to the user's Airtable resources.

Technical details

The vulnerability is an insufficient input validation flaw in the configure command (ConfigureCommand.execute in src/cli.ts). The endpoint URL option is stored directly in the user profile without validation against an allowlist, unlike the same setting when configured via environment variables which is restricted to Airtable's own hosts via the createSafeUrl helper in src/config.ts. Because the MCP connection handler (src/mcp.ts) attaches the stored personal access token as a bearer credential on every request to the configured endpoint, an attacker can socially engineer a user to run configure with a malicious endpoint URL, exfiltrating the token on each subsequent CLI invocation. Version 0.2.5 applies the same createSafeUrl validation to the configure command's endpoint option.

Affected products

  • Airtable MCP CLI before 0.2.5

Timeline

  • 2026-08-27: disclosed
  • 2026-06-09: patched: Fix released in version 0.2.5

References