CVE-2026-27203 | YosefHayim ebay-mcp up to 1.7.2 Environment Variable src/auth/oauth.ts updateEnvFile external control of setting (GHSA-97rm-xj73-33jh)
A vulnerability was found in YosefHayim ebay-mcp up to 1.7.2. It has been classified as critical. Affected is the function updateEnvFile of the file src/auth/oauth.ts of the component Environment Variable Handler. Performing a manipulation results in external control of system or configuration setting.
This vulnerability is reported as CVE-2026-27203. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to apply a patch to fix this issue.