CVE-2026-25650: SMN2GNT Mcp Salesforce Connector

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

MCP Salesforce Connector is a Model Context Protocol (MCP) server implementation for Salesforce integration. Prior to 0.1.10, arbitrary attribute access leads to disclosure of Salesforce auth token. This vulnerability is fixed in 0.1.10.

Affected products

  • SMN2GNT Mcp Salesforce Connector: before 0.1.10 (fixed in 0.1.10)

Published 2026-02-06. Last modified 2026-06-17.