CVE-2026-25650
Impact
Disclosure of Salesforce OAuth bearer tokens used by the MCP.
Patches
fix applied in 0.1.10
Workarounds
Rotate any Salesforce tokens/credentials used by MCP-Salesforce.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/smn2gnt/MCP-Salesforce/security/advisories/GHSA-vf6j-c56p-cq58, https://nvd.nist.gov/vuln/detail/CVE-2026-25650, https://github.com/smn2gnt/MCP-Salesforce/commit/a1e3a5a786f48508d066b6d40b58201ebf9b7fd6, https://github.com/smn2gnt/MCP-Salesforce, https://github.com/smn2gnt/MCP-Salesforce/releases/tag/v0.1.10
