MCP-Salesforce's arbitrary attribute access leads to disclosure of Salesforce auth token
Description
Published to the GitHub Advisory Database
Feb 6, 2026
Reviewed
Feb 6, 2026
Published by the National Vulnerability Database
Feb 6, 2026
Last updated
Feb 8, 2026
Impact
Disclosure of Salesforce OAuth bearer tokens used by the MCP.
Patches
fix applied in 0.1.10
Workarounds
Rotate any Salesforce tokens/credentials used by MCP-Salesforce.
References