CVE-2026-104634: beam_mcp: JSON boolean and null tool arguments reach dispatch as strings

Published Oct 8, 2026
·
Updated

Incorrect Type Conversion or Cast vulnerability in BeamMCP.Server in ScriptKittyOS beammcp allows an MCP client's JSON true, false and null tool arguments to reach the host's dispatch function as the strings "true", "false" and "nil". After BeamMCP.Schema.validate/2 accepted a value as a boolean, normalizearguments/2 passed every argument through tojsonvalue/1, whose atom clause converts true, false and nil to strings. A string is truthy in Elixir, so a host that tests a boolean argument, for example if args.dryrun, takes the opposite branch for false, and a guard such as confirm: false reads as set.

The client controls the argument and could send true directly, so the practical impact is limited to hosts whose behaviour on false differs from their behaviour on true, and to any policy layer in front of the server that permits false but refuses true. The same normalisation applies to prompts/get arguments, which exist from 0.5.0.

This issue affects beammcp: from 0.1.0 before 0.10.1.

Affected Software

1 affected component
hex/beam_mcp>=0.1.0<0.10.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade beam_mcp to a version that resolves this vulnerability.

    Fixed in 0.10.1

Event History

Oct 8, 2026
CVE Published
via MITRE·01:41 PM
Data Sourced
via MITRE·01:41 PM
DescriptionWeakness
Data Sourced
via NVD·02:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are affected?

beam_mcp versions from 0.1.0 before 0.10.1 are affected. The prompts/get argument path is affected only where that functionality is present, which is from version 0.5.0.

2

When does this create a meaningful security impact?

Impact depends on host dispatch code treating a boolean argument differently when it is false versus true. For example, a false value can arrive as the truthy Elixir string "false", causing a conditional such as if args.dry_run to take the enabled branch.

3

Can an unauthenticated client exploit this behavior?

The CVSS vector specifies low privileges required. Exploitation also requires the attacker to control a tool or prompts/get argument and a vulnerable host behavior or policy distinction involving false and true.

4

Are policy controls affected as well as host handlers?

Yes. A policy layer in front of the server may be bypassed if it permits false but rejects true, because the server can subsequently dispatch false as the string "false".

5

What is the available remediation?

Upgrade beam_mcp to version 0.10.1 or later. Until upgrading, review handlers and any front-end policy layers that rely on boolean false, null, or truthiness checks for tool and prompts/get arguments.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203