CVE Explorer
CVE-2026-31841
Hyperterse is a tool-first MCP framework for building AI-ready backend surfaces from declarative config. Prior to v2.2.0, the search tool allows LLMs to search for tools using natural language. While returning results, Hyperterse also returned the raw SQL queries, exposing statements which were supposed to be executed under the hood, and protected from being displayed publicly. This issue has been fixed as of v2.2.0.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"hyperterse","vendor":"hyperterse","versions":[{"status":"affected","version":">= 2.0.0, < 2.2.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:86b5e92665805579dcf6921cc19d7570c2e84a461ecc375872cef8bf46277a56 · sha256:073dfc3f89cb5f09… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:86b5e92665805579dcf6921cc19d7570c2e84a461ecc375872cef8bf46277a56 · sha256:073dfc3f89cb5f09… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-433","description":"CWE-433: Unparsed Raw Web Content Delivery","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:86b5e92665805579dcf6921cc19d7570c2e84a461ecc375872cef8bf46277a56 · sha256:073dfc3f89cb5f09… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/hyperterse/hyperterse/releases/tag/v2.2.0","tags":["x_refsource_MISC"],"url":"https://github.com/hyperterse/hyperterse/releases/tag/v2.2.0"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:86b5e92665805579dcf6921cc19d7570c2e84a461ecc375872cef8bf46277a56 · sha256:073dfc3f89cb5f09… · /containers/cna/references/1
{"name":"https://github.com/hyperterse/hyperterse/security/advisories/GHSA-92gp-jfgx-9qpv","tags":["x_refsource_CONFIRM"],"url":"https://github.com/hyperterse/hyperterse/security/advisories/GHSA-92gp-jfgx-9qpv"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:86b5e92665805579dcf6921cc19d7570c2e84a461ecc375872cef8bf46277a56 · sha256:073dfc3f89cb5f09… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.