Smithery.ai
Disclosed Oct 22, 202511 months agoUnverified
Path traversal in MCP hosting registry exposed admin token to 3,000+ hosted AI servers
GitGuardian found a Docker build path traversal in Smithery.ai that exposed an overprivileged fly.io token granting code execution on more than 3,000 hosted MCP servers and access to customers' API keys and secrets. Smithery patched it after disclosure and no exploitation was found.
What is known
| People affected | Not stated in the sources we have |
|---|---|
| Disclosed | Oct 22, 2025 |
| Attack | Exposed data |
| Data exposed | API keys, Credentials and tokens |
| Sector | AI |
| Status | Unverified: not yet confirmed by an official notice, a filing or the organization |
Sources
| Source | |
|---|---|
| From Path Traversal to Supply Chain Compromise: Breaking MCP Server Hostingblog.gitguardian.com · News | News |
Notices filed
| Where | Filed | People |
|---|---|---|
| Researchtotal | Oct 22, 2025 |
History of this record
- 2026-09-25 · added · seed source
First seen 2026-09-25 (Research). Record counts are as reported. Not legal advice.