Litmus maintains a narrowly scoped vulnerability footprint centered on its MCP Server product, with the durable signal concentrated around authentication and access-control weaknesses affecting critical functions. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Litmus over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-56405HIGH An issue was discovered in litmusautomation litmus-mcp-server thru 0.0.1 allowing unauthorized attackers to control the target's MCP service through the SSE protocol. | Sep 10, 2025 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Litmus.
Media articles that mention a CVE ID that affects a product developed by Litmus — matched by CVE ID, not by vendor name.