CVE-2026-25650: SMN2GNT Mcp Salesforce Connector
High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.
MCP Salesforce Connector is a Model Context Protocol (MCP) server implementation for Salesforce integration. Prior to 0.1.10, arbitrary attribute access leads to disclosure of Salesforce auth token. This vulnerability is fixed in 0.1.10.
Affected products
- SMN2GNT Mcp Salesforce Connector: before 0.1.10 (fixed in 0.1.10)
Published 2026-02-06. Last modified 2026-06-17.