CVE-2026-88257: beam_mcp: nested tool argument constraints advertised but not enforced
Improper Input Validation vulnerability in BeamMCP.Schema in ScriptKittyOS beammcp allows an MCP client to reach a tool's dispatch function with arguments that violate the input schema the server advertised. BeamMCP.Schema.validate/2 checked type, required, additionalProperties, enum and numeric bounds on the top-level arguments object only. Constraints inside nested objects and on array items (items, minItems, maxItems, minLength, maxLength, pattern, nested required, enum and additionalProperties: false) were advertised by tools/list and never checked at tools/call or prompts/get, and keywords outside the enforced subset (oneOf, anyOf, $ref) were advertised and ignored.
A host whose dispatch code relies on the schema it declared receives values the schema forbids, such as an out-of-range number or an undeclared key inside a nested object. What the host does with such a value decides the impact.
This issue affects beammcp: from 0.1.0 before 0.10.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
beam_mcpto a version that resolves this vulnerability.Fixed in 0.10.1
Event History
Frequently Asked Questions
Which releases require an update?
beam_mcp versions from 0.1.0 through versions before 0.10.1 are affected. Updating to 0.10.1 or later addresses the issue.
What access does an attacker need to exploit this?
The attacker needs the ability to act as an MCP client and invoke the affected operations. The CVSS vector indicates low privileges are required and no user interaction is required.
Which tool schemas create the greatest exposure?
Exposure is highest where dispatch code trusts constraints inside nested objects or array items, including nested required fields, enums, additionalProperties: false, numeric or string limits, patterns, and item-count limits. Schemas using oneOf, anyOf, or $ref are also affected because those advertised keywords were ignored.
Are all declared schema checks bypassed?
No. Validation checked the top-level arguments object for type, required fields, additionalProperties, enums, and numeric bounds. The missing enforcement applied to nested constraints and array-item constraints, and to unsupported advertised keywords.
Which MCP operations can receive schema-violating values?
The affected validation behavior applies to tools/call and prompts/get. Affected hosts may receive values that their advertised schemas prohibit, and the resulting impact depends on how their dispatch code handles those values.