meta-ads-mcp Package Auth Bypass Vulnerability: Early Warning
An early warning has been issued regarding an authentication bypass vulnerability in the meta-ads-mcp package, which affects various versions and could allow unauthorized access to Meta Ads data.
What happened
Reportedly, the meta-ads-mcp package contains an authentication bypass vulnerability where the X-Pipeboard-Token header is not properly recognized, enabling unauthenticated access to Meta Ads data. This vulnerability impacts a wide range of versions from 0 to 1.0.115, among others. Users of the meta-ads-mcp package are advised to monitor for updates and consider upgrading to a fixed version once available to mitigate potential risks.
How 0Day mitigates this
meta-ads-mcp is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.