天下漏洞,尽知其名
MEDIUM

CVE-2026-107820 x64dbg-MCP Server 整数溢出漏洞

影响未认证攻击者可远程触发崩溃,导致调试进程终止

AI 研判

x64dbg-MCP Server 是 x64dbg 的原生 MCP 插件,通过 HTTP 暴露调试器功能。1.2 之前版本在解析 Content-Length 时未做边界检查,并在 wsRecv() 中进行未校验的 usize 加法运算,且该运算发生在令牌认证之前。默认监听 0.0.0.0,未认证网络客户端可触发整数溢出 panic。

影响范围

x64dbg-MCP Server

x64dbg-MCP Server 1.2 之前的版本受影响,1.2 版本已修复。

漏洞详情

漏洞类型为整数溢出导致的拒绝服务。parseContentLength() 解析未限制大小的 Content-Length 值,wsRecv() 在认证前对其执行未检查的 usize 加法,超大值会触发运行时整数溢出 panic。溢出值仅用于比较,因此不会造成内存破坏或代码执行,仅导致进程终止。

利用条件与风险

利用前提是攻击者能访问默认监听的 0.0.0.0 端口,无需认证即可触发。实战中可导致整个 x64dbg 进程及实时调试会话被终止,造成拒绝服务。

修复建议

升级至 x64dbg-MCP Server 1.2 或更高版本。临时缓解措施包括限制网络访问、避免将服务暴露在不可信网络,暂无其他公开信息。

原始情报

x64dbg-MCP Server is a native Model Context Protocol (MCP) plugin for x64dbg that exposes the debugger’s full functionality over HTTP. Prior to 1.2, src/core/mcp_server.zig parses an unbounded Content-Length value in parseContentLength() and uses it in unchecked usize addition in wsRecv() before token authentication. The server listens on 0.0.0.0 by default in affected versions. An unauthenticated network client can supply a near-maximum Content-Length value to trigger a runtime integer-overflow panic in Debug and ReleaseSafe builds, terminating the entire x64dbg process and its live debugging session. The overflowed value is used only in a comparison, so the impact is limited to denial of service rather than memory corruption or code execution. This issue is fixed in version 1.2.