Add MseeP.ai badge#11
Open
mseep-ai wants to merge 1 commit into
Open
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Hi there,
This pull request shares a security update on Klear-Team-Brain.
We also have an entry for Klear-Team-Brain in our directory, MseeP.ai, where we provide regular security and trust updates on your app.
We invite you to add our badge for your MCP server to your README to help your users learn from a third party that provides ongoing validation of Klear-Team-Brain.
You can easily take control over your listing for free: visit it at https://mseep.ai/app/asklear-klear-team-brain.
Thanks,
The MseeP Team
MCP servers you can trust
Here are our latest evaluation results of Klear-Team-Brain
Security Scan Results
Security Score: 81/100
Risk Level: moderate
Scan Date: 2026-07-04
Score starts at 100, deducts points for security issues, and adds points for security best practices
Detected Vulnerabilities
Medium Severity
@larksuiteoapi/node-sdk
axios
validateStatusMerge Strategy', 'url': 'https://github.com/advisories/GHSA-w9j2-pvgh-6h63', 'severity': 'moderate', 'cwe': ['CWE-287', 'CWE-1321'], 'cvss': {'score': 4.8, 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N'}, 'range': '>=1.0.0 <1.15.1'}, {'source': 1117576, 'name': 'axios', 'dependency': 'axios', 'title': 'Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC 1122 Loopback Subnet (127.0.0.0/8) in Axios 1.15.0', 'url': 'https://github.com/advisories/GHSA-pmwg-cvhr-8vh7', 'severity': 'high', 'cwe': ['CWE-183', 'CWE-441', 'CWE-918'], 'cvss': {'score': 7.2, 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}, 'range': '>=1.0.0 <1.15.1'}, {'source': 1117577, 'name': 'axios', 'dependency': 'axios', 'title': 'Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget inparseReviver', 'url': 'https://github.com/advisories/GHSA-3w6x-2g7m-8v23', 'severity': 'moderate', 'cwe': ['CWE-915', 'CWE-1321'], 'cvss': {'score': 6.5, 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N'}, 'range': '>=1.0.0 <1.15.2'}, {'source': 1117580, 'name': 'axios', 'dependency': 'axios', 'title': 'Axios: Null Byte Injection via Reverse-Encoding in AxiosURLSearchParams', 'url': 'https://github.com/advisories/GHSA-xhjh-pmcv-23jw', 'severity': 'low', 'cwe': ['CWE-116', 'CWE-626'], 'cvss': {'score': 3.7, 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N'}, 'range': '>=1.0.0 <1.15.1'}, {'source': 1117581, 'name': 'axios', 'dependency': 'axios', 'title': 'Axios: CRLF Injection in multipart/form-data body via unsanitized blob.type in formDataToStream', 'url': 'https://github.com/advisories/GHSA-445q-vr5w-6q77', 'severity': 'moderate', 'cwe': ['CWE-93'], 'cvss': {'score': 5.3, 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}, 'range': '>=1.0.0 <1.15.1'}, {'source': 1117583, 'name': 'axios', 'dependency': 'axios', 'title': 'Axios: no_proxy bypass via IP alias allows SSRF', 'url': 'https://github.com/advisories/GHSA-m7pr-hjqh-92cm', 'severity': 'moderate', 'cwe': ['CWE-918'], 'cvss': {'score': 6.8, 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N'}, 'range': '>=1.0.0 <1.15.1'}, {'source': 1117587, 'name': 'axios', 'dependency': 'axios', 'title': "Axios' HTTP adapter-streamed uploads bypass maxBodyLength when maxRedirects: 0", 'url': 'https://github.com/advisories/GHSA-5c9x-8gcm-mpgx', 'severity': 'moderate', 'cwe': ['CWE-770'], 'cvss': {'score': 5.3, 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}, 'range': '>=1.0.0 <1.15.1'}, {'source': 1117589, 'name': 'axios', 'dependency': 'axios', 'title': 'Axios: HTTP adapter streamed responses bypass maxContentLength', 'url': 'https://github.com/advisories/GHSA-vf2m-468p-8v99', 'severity': 'moderate', 'cwe': ['CWE-770'], 'cvss': {'score': 5.3, 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}, 'range': '>=1.0.0 <1.15.1'}, {'source': 1117591, 'name': 'axios', 'dependency': 'axios', 'title': 'Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request Hijacking', 'url': 'https://github.com/advisories/GHSA-pf86-5x62-jrwf', 'severity': 'high', 'cwe': ['CWE-1321'], 'cvss': {'score': 7.4, 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}, 'range': '>=1.0.0 <1.15.1'}, {'source': 1117593, 'name': 'axios', 'dependency': 'axios', 'title': 'Axios: Header Injection via Prototype Pollution', 'url': 'https://github.com/advisories/GHSA-6chq-wfr3-2hj9', 'severity': 'high', 'cwe': ['CWE-113', 'CWE-1321'], 'cvss': {'score': 7.4, 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}, 'range': '>=1.0.0 <1.15.1'}, {'source': 1117595, 'name': 'axios', 'dependency': 'axios', 'title': 'Axios: XSRF Token Cross-Origin Leakage via Prototype Pollution Gadget inwithXSRFTokenBoolean Coercion', 'url': 'https://github.com/advisories/GHSA-xx6v-rp6x-q39c', 'severity': 'moderate', 'cwe': ['CWE-183', 'CWE-201'], 'cvss': {'score': 5.4, 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'}, 'range': '>=1.0.0 <1.15.1'}, {'source': 1118607, 'name': 'axios', 'dependency': 'axios', 'title': 'Axios has prototype pollution read-side gadgets in HTTP adapter that allow credential injection and request hijacking', 'url': 'https://github.com/advisories/GHSA-q8qp-cvcw-x6jj', 'severity': 'high', 'cwe': ['CWE-1321'], 'cvss': {'score': 7.4, 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}, 'range': '>=1.0.0 <1.15.2'}, {'source': 1119404, 'name': 'axios', 'dependency': 'axios', 'title': 'Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain', 'url': 'https://github.com/advisories/GHSA-fvcv-3m26-pcqx', 'severity': 'moderate', 'cwe': ['CWE-113', 'CWE-444', 'CWE-918'], 'cvss': {'score': 4.8, 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N'}, 'range': '>=1.0.0 <1.15.0'}, {'source': 1119667, 'name': 'axios', 'dependency': 'axios', 'title': "axios's shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, allowing NO_PROXY bypass (incomplete fix for CVE-2025-62718)", 'url': 'https://github.com/advisories/GHSA-pjwm-pj3p-43mv', 'severity': 'high', 'cwe': ['CWE-918'], 'cvss': {'score': 8.6, 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'}, 'range': '>=1.0.0 <1.16.0'}, {'source': 1120125, 'name': 'axios', 'dependency': 'axios', 'title': 'Axios: unbounded recursion in toFormData causes DoS via deeply nested request data', 'url': 'https://github.com/advisories/GHSA-62hf-57xw-28j9', 'severity': 'moderate', 'cwe': ['CWE-674'], 'cvss': {'score': 7.5, 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'range': '>=1.0.0 <1.15.1'}, {'source': 1120547, 'name': 'axios', 'dependency': 'axios', 'title': 'Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection', 'url': 'https://github.com/advisories/GHSA-hfxv-24rg-xrqf', 'severity': 'high', 'cwe': ['CWE-400', 'CWE-1333'], 'cvss': {'score': 7.5, 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'range': '>=1.0.0 <1.16.0'}, {'source': 1120643, 'name': 'axios', 'dependency': 'axios', 'title': 'Allocation of Resources Without Limits or Throttling in Axios', 'url': 'https://github.com/advisories/GHSA-777c-7fjr-54vf', 'severity': 'high', 'cwe': ['CWE-770'], 'cvss': {'score': 7.5, 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'range': '>=1.7.0 <1.16.0'}, {'source': 1120645, 'name': 'axios', 'dependency': 'axios', 'title': 'Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redirect in Axios Node.js HTTP Adapter', 'url': 'https://github.com/advisories/GHSA-p92q-9vqr-4j8v', 'severity': 'high', 'cwe': ['CWE-201'], 'cvss': {'score': 0, 'vectorString': None}, 'range': '>=1.0.0 <1.16.0'}, {'source': 1120647, 'name': 'axios', 'dependency': 'axios', 'title': 'Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connection', 'url': 'https://github.com/advisories/GHSA-j5f8-grm9-p9fc', 'severity': 'high', 'cwe': ['CWE-200'], 'cvss': {'score': 7.5, 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'range': '>=1.0.0 <1.16.0'}, {'source': 1120649, 'name': 'axios', 'dependency': 'axios', 'title': 'axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge', 'url': 'https://github.com/advisories/GHSA-3g43-6gmg-66jw', 'severity': 'high', 'cwe': ['CWE-94', 'CWE-1321'], 'cvss': {'score': 7, 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L'}, 'range': '>=1.0.0 <1.15.2'}, {'source': 1120650, 'name': 'axios', 'dependency': 'axios', 'title': 'axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget inconfig.proxy', 'url': 'https://github.com/advisories/GHSA-35jp-ww65-95wh', 'severity': 'high', 'cwe': ['CWE-441', 'CWE-1321'], 'cvss': {'score': 8.7, 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N'}, 'range': '>=1.0.0 <1.16.0'}, {'source': 1120652, 'name': 'axios', 'dependency': 'axios', 'title': 'axios has DoS & Header Injection via Prototype Pollution Read-Side Gadgets in axios merge functions', 'url': 'https://github.com/advisories/GHSA-898c-q2cr-xwhg', 'severity': 'moderate', 'cwe': ['CWE-1321'], 'cvss': {'score': 4.8, 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L'}, 'range': '>=1.0.0 <1.16.0'}]form-data
... and 2 more medium severity vulnerabilities
Security Findings
Medium Severity Issues
This security assessment was conducted by MseeP.ai, an independent security validation service for MCP servers. Visit our website to learn more about our security reviews.