Skip to main content
VerifiedInjection

A widely installed documentation MCP server carried a prompt injection into connected coding agents

CVE-2026-75130, published on 18 August 2026, records that Context7 through version 2.1.2 contains a prompt injection that allows attackers to execute malicious instructions in connected AI coding agents by injecting unsanitised content through its custom instructions feature, served by its MCP server. The record carries a critical score under one scoring version.

The verdict

Verified

The document exists. The ledger fetched it at its publisher and quotes it.

Key facts

What the sources say

Record ID
AIL-2026-0025
Kind
Injection
Jurisdiction
Global
Last verified
Added
  • The CVE record states that the product contains a prompt injection allowing attackers to execute malicious instructions in connected AI coding agents.
  • The injection arrives through unsanitised content in the custom instructions feature served by the MCP server.
  • Affected versions are everything through 2.1.2 according to the CVE record.
  • The record carries two scores from different versions of the scoring system, which is why published severities for it differ.
  • The record was assigned by a vulnerability numbering authority rather than by the product's own vendor.

Dimension by dimension

5 dimensions, each one stated, silent or open

Identity, Authorization, Limits, Accountability, Revocation. Stated means the document you can open below says it; silent means the ledger read the document and it does not.

IdentitySilent
Content served by a documentation tool reached the agent with the standing of an instruction.CVE Program record, CVE-2026-75130, primary source, 18 August 2026.
AuthorizationSilent
The record states the injected instructions execute in connected coding agents, which hold the developer's own reach.CVE Program record, CVE-2026-75130, primary source, 18 August 2026.
LimitsSilent
The record describes unsanitised content, so no filtering bounded what could arrive.CVE Program record, CVE-2026-75130, primary source, 18 August 2026.
AccountabilityStated
A public CVE record exists with an assigning authority, an affected range and published scores.CVE Program record, CVE-2026-75130, primary source, 18 August 2026.
RevocationOpen
The record names an affected range and the public documentation of a fixed release was not established here.CVE Program record, CVE-2026-75130, primary source, 18 August 2026.

Figures

Every number, with who measured it and when

  1. 9 CVSS base score

    CVSS version 3.1 base score on the CVE record

    CVE Program record, CVE-2026-75130, primary source, as of .

  2. 6.4 CVSS base score

    CVSS version 4.0 base score on the same CVE record

    CVE Program record, CVE-2026-75130, primary source, as of .

What it changes

For a team deploying an agent

A documentation server looks like the safest thing you can connect to a coding agent, and it is an instruction channel. Keep an inventory of every MCP server your developers run, with its version and who publishes it, and subscribe to CVE feeds for each one. Treat everything a server returns as untrusted content, and never let a documentation tool's output reach an agent that can write code unreviewed.

Sources

What this record was verified against

  1. CVE Program record, CVE-2026-75130Primary · 18 August 2026

Related

Cite this record

Free to reuse under CC BY 4.0, with attribution. The record ID AIL-2026-0025 is permanent and is never reused.

In a sentence
According to the GAGE Agent Incident Ledger (as of 15 September 2026), a widely installed documentation mcp server carried a prompt injection into connected coding agents.
APA
GAGE (Global Academy of Generative-AI Education). (2026). A widely installed documentation MCP server carried a prompt injection into connected coding agents. Agent Incident Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0025-context7-mcp-documentation-server-prompt-injection-cve
MLA
"A widely installed documentation MCP server carried a prompt injection into connected coding agents." Agent Incident Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0025-context7-mcp-documentation-server-prompt-injection-cve.
Chicago
GAGE (Global Academy of Generative-AI Education). "A widely installed documentation MCP server carried a prompt injection into connected coding agents." Agent Incident Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0025-context7-mcp-documentation-server-prompt-injection-cve.
Permalink
https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0025-context7-mcp-documentation-server-prompt-injection-cve

Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any vendor disclosure.

Back to the full ledger, or every record for Global and every injection record.

GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.