Junglewise Threat Intelligence

Labs64 netlicensing-mcp path traversal in netlicensing_get_product

Severity: critical · CVSS 9.6 · Published 2026-06-18

Technologies: netlicensing-mcp (PyPI). Vendors: PyPI.

Executive brief

Labs64 netlicensing-mcp is a library used to interact with the NetLicensing REST API. A vulnerability in how it handles product identifiers allows an authenticated user to trick the system into accessing sensitive security tokens instead of product data. This can lead to the exposure of plaintext administrative API keys, potentially giving an attacker full control over the NetLicensing account.

Technical details

The vulnerability is a path traversal (CWE-22) in the `netlicensing_get_product` tool within `netlicensing-mcp`. The `product_number` argument is interpolated directly into a REST URL path without validation. By providing a payload like `../token`, an attacker exploits `httpx` URL normalization to redirect the request from the product endpoint to the token endpoint. Because the response is processed by a generic JSON wrapper rather than the token-specific redaction wrapper, sensitive fields such as APIKEY `number` and SHOP `shopURL` are returned in plaintext. An authenticated attacker can use this to escalate privileges to `ROLE_APIKEY_ADMIN`. The issue is fixed in version 0.1.8 by implementing path segment validation.

Affected products

  • Labs64 netlicensing-mcp <= 0.1.5

Timeline

  • 2026-06-18: advisory
  • 2026-06-18: disclosed
  • 2026-06-18: patched: Fixed in version 0.1.8

References

Related threats