Skip to content

Add MseeP.ai badge#11

Open
mseep-ai wants to merge 1 commit into
Asklear:mainfrom
mseep-ai:add-mseep-badge
Open

Add MseeP.ai badge#11
mseep-ai wants to merge 1 commit into
Asklear:mainfrom
mseep-ai:add-mseep-badge

Conversation

@mseep-ai

@mseep-ai mseep-ai commented Jul 4, 2026

Copy link
Copy Markdown

Hi there,

This pull request shares a security update on Klear-Team-Brain.

We also have an entry for Klear-Team-Brain in our directory, MseeP.ai, where we provide regular security and trust updates on your app.

We invite you to add our badge for your MCP server to your README to help your users learn from a third party that provides ongoing validation of Klear-Team-Brain.

You can easily take control over your listing for free: visit it at https://mseep.ai/app/asklear-klear-team-brain.

Thanks,

The MseeP Team
MCP servers you can trust


MseeP.ai Security Assessment Badge

Here are our latest evaluation results of Klear-Team-Brain

Security Scan Results

Security Score: 81/100

Risk Level: moderate

Scan Date: 2026-07-04

Score starts at 100, deducts points for security issues, and adds points for security best practices

Detected Vulnerabilities

Medium Severity

  • @larksuiteoapi/node-sdk

    • ['axios']
    • Fixed in version: unknown
  • axios

    • [{'source': 1116673, 'name': 'axios', 'dependency': 'axios', 'title': 'Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF', 'url': 'https://github.com/advisories/GHSA-3p68-rc4w-qgx5', 'severity': 'moderate', 'cwe': ['CWE-441', 'CWE-918'], 'cvss': {'score': 4.8, 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N'}, 'range': '>=1.0.0 <1.15.0'}, {'source': 1117574, 'name': 'axios', 'dependency': 'axios', 'title': 'Axios: Authentication Bypass via Prototype Pollution Gadget in validateStatus Merge Strategy', 'url': 'https://github.com/advisories/GHSA-w9j2-pvgh-6h63', 'severity': 'moderate', 'cwe': ['CWE-287', 'CWE-1321'], 'cvss': {'score': 4.8, 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N'}, 'range': '>=1.0.0 <1.15.1'}, {'source': 1117576, 'name': 'axios', 'dependency': 'axios', 'title': 'Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC 1122 Loopback Subnet (127.0.0.0/8) in Axios 1.15.0', 'url': 'https://github.com/advisories/GHSA-pmwg-cvhr-8vh7', 'severity': 'high', 'cwe': ['CWE-183', 'CWE-441', 'CWE-918'], 'cvss': {'score': 7.2, 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}, 'range': '>=1.0.0 <1.15.1'}, {'source': 1117577, 'name': 'axios', 'dependency': 'axios', 'title': 'Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget in parseReviver', 'url': 'https://github.com/advisories/GHSA-3w6x-2g7m-8v23', 'severity': 'moderate', 'cwe': ['CWE-915', 'CWE-1321'], 'cvss': {'score': 6.5, 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N'}, 'range': '>=1.0.0 <1.15.2'}, {'source': 1117580, 'name': 'axios', 'dependency': 'axios', 'title': 'Axios: Null Byte Injection via Reverse-Encoding in AxiosURLSearchParams', 'url': 'https://github.com/advisories/GHSA-xhjh-pmcv-23jw', 'severity': 'low', 'cwe': ['CWE-116', 'CWE-626'], 'cvss': {'score': 3.7, 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N'}, 'range': '>=1.0.0 <1.15.1'}, {'source': 1117581, 'name': 'axios', 'dependency': 'axios', 'title': 'Axios: CRLF Injection in multipart/form-data body via unsanitized blob.type in formDataToStream', 'url': 'https://github.com/advisories/GHSA-445q-vr5w-6q77', 'severity': 'moderate', 'cwe': ['CWE-93'], 'cvss': {'score': 5.3, 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}, 'range': '>=1.0.0 <1.15.1'}, {'source': 1117583, 'name': 'axios', 'dependency': 'axios', 'title': 'Axios: no_proxy bypass via IP alias allows SSRF', 'url': 'https://github.com/advisories/GHSA-m7pr-hjqh-92cm', 'severity': 'moderate', 'cwe': ['CWE-918'], 'cvss': {'score': 6.8, 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N'}, 'range': '>=1.0.0 <1.15.1'}, {'source': 1117587, 'name': 'axios', 'dependency': 'axios', 'title': "Axios' HTTP adapter-streamed uploads bypass maxBodyLength when maxRedirects: 0", 'url': 'https://github.com/advisories/GHSA-5c9x-8gcm-mpgx', 'severity': 'moderate', 'cwe': ['CWE-770'], 'cvss': {'score': 5.3, 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}, 'range': '>=1.0.0 <1.15.1'}, {'source': 1117589, 'name': 'axios', 'dependency': 'axios', 'title': 'Axios: HTTP adapter streamed responses bypass maxContentLength', 'url': 'https://github.com/advisories/GHSA-vf2m-468p-8v99', 'severity': 'moderate', 'cwe': ['CWE-770'], 'cvss': {'score': 5.3, 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}, 'range': '>=1.0.0 <1.15.1'}, {'source': 1117591, 'name': 'axios', 'dependency': 'axios', 'title': 'Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request Hijacking', 'url': 'https://github.com/advisories/GHSA-pf86-5x62-jrwf', 'severity': 'high', 'cwe': ['CWE-1321'], 'cvss': {'score': 7.4, 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}, 'range': '>=1.0.0 <1.15.1'}, {'source': 1117593, 'name': 'axios', 'dependency': 'axios', 'title': 'Axios: Header Injection via Prototype Pollution', 'url': 'https://github.com/advisories/GHSA-6chq-wfr3-2hj9', 'severity': 'high', 'cwe': ['CWE-113', 'CWE-1321'], 'cvss': {'score': 7.4, 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}, 'range': '>=1.0.0 <1.15.1'}, {'source': 1117595, 'name': 'axios', 'dependency': 'axios', 'title': 'Axios: XSRF Token Cross-Origin Leakage via Prototype Pollution Gadget in withXSRFToken Boolean Coercion', 'url': 'https://github.com/advisories/GHSA-xx6v-rp6x-q39c', 'severity': 'moderate', 'cwe': ['CWE-183', 'CWE-201'], 'cvss': {'score': 5.4, 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'}, 'range': '>=1.0.0 <1.15.1'}, {'source': 1118607, 'name': 'axios', 'dependency': 'axios', 'title': 'Axios has prototype pollution read-side gadgets in HTTP adapter that allow credential injection and request hijacking', 'url': 'https://github.com/advisories/GHSA-q8qp-cvcw-x6jj', 'severity': 'high', 'cwe': ['CWE-1321'], 'cvss': {'score': 7.4, 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}, 'range': '>=1.0.0 <1.15.2'}, {'source': 1119404, 'name': 'axios', 'dependency': 'axios', 'title': 'Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain', 'url': 'https://github.com/advisories/GHSA-fvcv-3m26-pcqx', 'severity': 'moderate', 'cwe': ['CWE-113', 'CWE-444', 'CWE-918'], 'cvss': {'score': 4.8, 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N'}, 'range': '>=1.0.0 <1.15.0'}, {'source': 1119667, 'name': 'axios', 'dependency': 'axios', 'title': "axios's shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, allowing NO_PROXY bypass (incomplete fix for CVE-2025-62718)", 'url': 'https://github.com/advisories/GHSA-pjwm-pj3p-43mv', 'severity': 'high', 'cwe': ['CWE-918'], 'cvss': {'score': 8.6, 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'}, 'range': '>=1.0.0 <1.16.0'}, {'source': 1120125, 'name': 'axios', 'dependency': 'axios', 'title': 'Axios: unbounded recursion in toFormData causes DoS via deeply nested request data', 'url': 'https://github.com/advisories/GHSA-62hf-57xw-28j9', 'severity': 'moderate', 'cwe': ['CWE-674'], 'cvss': {'score': 7.5, 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'range': '>=1.0.0 <1.15.1'}, {'source': 1120547, 'name': 'axios', 'dependency': 'axios', 'title': 'Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection', 'url': 'https://github.com/advisories/GHSA-hfxv-24rg-xrqf', 'severity': 'high', 'cwe': ['CWE-400', 'CWE-1333'], 'cvss': {'score': 7.5, 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'range': '>=1.0.0 <1.16.0'}, {'source': 1120643, 'name': 'axios', 'dependency': 'axios', 'title': 'Allocation of Resources Without Limits or Throttling in Axios', 'url': 'https://github.com/advisories/GHSA-777c-7fjr-54vf', 'severity': 'high', 'cwe': ['CWE-770'], 'cvss': {'score': 7.5, 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'range': '>=1.7.0 <1.16.0'}, {'source': 1120645, 'name': 'axios', 'dependency': 'axios', 'title': 'Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redirect in Axios Node.js HTTP Adapter', 'url': 'https://github.com/advisories/GHSA-p92q-9vqr-4j8v', 'severity': 'high', 'cwe': ['CWE-201'], 'cvss': {'score': 0, 'vectorString': None}, 'range': '>=1.0.0 <1.16.0'}, {'source': 1120647, 'name': 'axios', 'dependency': 'axios', 'title': 'Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connection', 'url': 'https://github.com/advisories/GHSA-j5f8-grm9-p9fc', 'severity': 'high', 'cwe': ['CWE-200'], 'cvss': {'score': 7.5, 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'range': '>=1.0.0 <1.16.0'}, {'source': 1120649, 'name': 'axios', 'dependency': 'axios', 'title': 'axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge', 'url': 'https://github.com/advisories/GHSA-3g43-6gmg-66jw', 'severity': 'high', 'cwe': ['CWE-94', 'CWE-1321'], 'cvss': {'score': 7, 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L'}, 'range': '>=1.0.0 <1.15.2'}, {'source': 1120650, 'name': 'axios', 'dependency': 'axios', 'title': 'axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in config.proxy', 'url': 'https://github.com/advisories/GHSA-35jp-ww65-95wh', 'severity': 'high', 'cwe': ['CWE-441', 'CWE-1321'], 'cvss': {'score': 8.7, 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N'}, 'range': '>=1.0.0 <1.16.0'}, {'source': 1120652, 'name': 'axios', 'dependency': 'axios', 'title': 'axios has DoS & Header Injection via Prototype Pollution Read-Side Gadgets in axios merge functions', 'url': 'https://github.com/advisories/GHSA-898c-q2cr-xwhg', 'severity': 'moderate', 'cwe': ['CWE-1321'], 'cvss': {'score': 4.8, 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L'}, 'range': '>=1.0.0 <1.16.0'}]
    • Fixed in version: unknown
  • form-data

    • [{'source': 1120743, 'name': 'form-data', 'dependency': 'form-data', 'title': 'form-data: CRLF injection in form-data via unescaped multipart field names and filenames', 'url': 'https://github.com/advisories/GHSA-hmw2-7cc7-3qxx', 'severity': 'high', 'cwe': ['CWE-93'], 'cvss': {'score': 7.5, 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}, 'range': '>=4.0.0 <4.0.6'}]
    • Fixed in version: unknown
  • ... and 2 more medium severity vulnerabilities

Security Findings

Medium Severity Issues

  • semgrep: Potential NoSQL injection. Validate and sanitize user input.
    • Location: mcp/tools.mjs
    • Line: 130

This security assessment was conducted by MseeP.ai, an independent security validation service for MCP servers. Visit our website to learn more about our security reviews.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant