Ad

CVE-2026-31841

MEDIUM CVSS 3.1: 6.5 EPSS 0.04%
Updated Mar 19, 2026
Hyperterse
Parameter Value
CVSS 6.5 (MEDIUM)
Affected Versions before 2.2.0
Fixed In 2.2.0
Type CWE-433
Vendor Hyperterse
Public PoC No

Hyperterse is a tool-first MCP framework for building AI-ready backend surfaces from declarative config. Prior to v2.2.0, the search tool allows LLMs to search for tools using natural language. While returning results, Hyperterse also returned the raw SQL queries, exposing statements which were supposed to be executed under the hood, and protected from being displayed publicly.

This issue has been fixed as of v2.2.0.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
Low
Partial data leak
Integrity
Low
Partial data modification
Availability
None
No disruption

CVSS Vector v3.1

Weakness Type (CWE)

Vulnerable Products 1

Configuration From (including) Up to (excluding)
Hyperterse Hyperterse
cpe:2.3:a:hyperterse:hyperterse:*:*:*:*:*:*:*:*
2.2.0