Junglewise Threat Intelligence

Dynatrace MCP Server template injection in create_workflow_for_notification

Severity: low · CVSS 3.1 · Published 2026-07-31

Technologies: @dynatrace-oss/dynatrace-mcp-server (npm). Vendors: npm, Dynatrace.

Executive brief

The Dynatrace MCP Server is a tool that integrates with Dynatrace's monitoring and automation platform. An attacker can inject malicious template code into workflow creation parameters, causing the Dynatrace workflow engine to evaluate arbitrary expressions at runtime and exfiltrate sensitive event data through persistent workflows that remain active even after the MCP session ends.

Technical details

The vulnerability is a template injection flaw in the create_workflow_for_notification tool. The tool concatenates user-supplied parameters (teamName, problemType, channel) directly into a Jinja2 template without validation, and these expressions are evaluated at workflow runtime by the Dynatrace Automation API. An attacker with access to the MCP server can supply payloads like teamName="{{ event() }}" to execute arbitrary Jinja2 expressions. The channel parameter is particularly dangerous as it is nested inside an existing {{ "..." }} context, allowing expression escape. The created workflows persist in the tenant indefinitely and fire on every matching problem condition, enabling sustained data exfiltration. No authentication is required beyond access to the MCP server itself. Patches are available in version 2.0.0 and later.

Affected products

  • Dynatrace @dynatrace-oss/dynatrace-mcp-server up to and including 1.8.5

Timeline

  • 2026-06-09: disclosed: Advisory published on GitHub
  • 2026-07-31: advisory: Published to OSV database
  • 2026: patched: Fixed in version 2.0.0 and later

References

Related threats