Executive brief
A vulnerability in the Dynatrace MCP Server allows attackers to inject malicious code into automated workflows. This could lead to the permanent exfiltration of sensitive event data and environment metadata to unauthorized external destinations. Because these workflows are persistent, the data theft can continue even after the attacker's initial session has ended or the server has been uninstalled.
Technical details
A Server-Side Template Injection (SSTI) vulnerability exists in the `create_workflow_for_notification` tool within `@dynatrace-oss/dynatrace-mcp-server`. The tool fails to sanitize the `teamName`, `problemType`, and `channel` parameters before interpolating them into a Dynatrace Workflow definition that utilizes Jinja2 templating. An attacker can supply malicious Jinja2 expressions (e.g., `{{ event() }}`) which are evaluated at runtime by the Dynatrace workflow engine. This allows for the exfiltration of full event objects and environment metadata to attacker-controlled Slack channels. The vulnerability is particularly severe because the resulting workflows are persistent within the Dynatrace tenant and continue to execute indefinitely. The issue is fixed in version 2.0.0.
Affected products
- Dynatrace dynatrace-mcp-server < 2.0.0
Timeline
- 2026-06-09: patched: Version 2.0.0 released
- 2026-07-31: advisory: GitHub Advisory published
References
- https://api.github.com/users/yotampe-pluto
- https://github.com/yotampe-pluto
- https://api.github.com/users/yotampe-pluto/gists%7B/gist_id%7D
- https://api.github.com/users/yotampe-pluto/repos
- https://avatars.githubusercontent.com/u/252890338?v=4
- https://api.github.com/users/yotampe-pluto/events%7B/privacy%7D