Skip to content

Smithery.ai

Disclosed Oct 22, 202511 months agoUnverified

Path traversal in MCP hosting registry exposed admin token to 3,000+ hosted AI servers

GitGuardian found a Docker build path traversal in Smithery.ai that exposed an overprivileged fly.io token granting code execution on more than 3,000 hosted MCP servers and access to customers' API keys and secrets. Smithery patched it after disclosure and no exploitation was found.

What is known

People affectedNot stated in the sources we have
DisclosedOct 22, 2025
AttackExposed data
Data exposedAPI keys, Credentials and tokens
SectorAI
StatusUnverified: not yet confirmed by an official notice, a filing or the organization

Sources

Notices filed

WhereFiledPeople
ResearchtotalOct 22, 2025
History of this record
  • 2026-09-25 · added · seed source

First seen 2026-09-25 (Research). Record counts are as reported. Not legal advice.

Everything about Smithery.ai

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.