6.5
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Description
Arcade MCP allows you to to create, deploy, and share MCP Servers. Prior to 1.5.4, the arcade-mcp HTTP server uses a hardcoded default worker secret ("dev") that is never validated or overridden during normal server startup. As a result, any unauthenticated attacker who knows this default key can forge valid JWTs and fully bypass the FastAPI authentication layer. This grants remote access to all worker endpoints—including tool enumeration and tool invocation—without credentials. This vulnerability is fixed in 1.5.4.
Basic Information
ID
CVE-2025-66454
Source
GitHub_M
Published
Dec 2, 2025 at 18:23
Modified
Dec 2, 2025 at 19:28
Affected Product
Vendor
ArcadeAI
Product
arcade-mcp
Version
< 1.5.4
Affected Versions
ArcadeAI arcade-mcp < 1.5.4