High SEVERITY — Vulnerability

CVE-2026-49357 — Line Desktop MCP is a project that, while unaffiliated with the official line-bot-mcp-server, allows users to directly o

Line Desktop MCP is a project that, while unaffiliated with the official line-bot-mcp-server, allows users to directly operate the LINE Desktop application on Windows or Mac via MCP. `line-desktop-mcp` supports a `--http-mode` Streamable HTTP transport for use with clients such as n8n. In this mode the server binds to `0.0.0.0` and exposes the MCP `\/mcp` endpoint without an MCP-layer authentication check. Prior to version 1.1.2, any network client that can reach the port can

Platform
Windows Server
CVE Record
CVE-2026-49357
CVSS Score
8.8/10
Published
19 June 2026
Views
3
Primary source: Review the official advisory at nvd.nist.gov Kaynağa Git

Summary

Line Desktop MCP is a project that, while unaffiliated with the official line-bot-mcp-server, allows users to directly operate the LINE Desktop application on Windows or Mac via MCP. line-desktop-mcp supports a --http-mode Streamable HTTP transport for use with clients such as n8n. In this mode the server binds to 0.0.0.0 and exposes the MCP \/mcp endpoint without an MCP-layer authentication check. Prior to version 1.1.2, any network client that can reach the port can initialize a session, list tools, and call tools that read LINE Desktop chat history or send LINE messages through the already logged-in desktop application. Version 1.1.2 fixes the issue.

Assessment

  • CVE: CVE-2026-49357
  • CVSS base score: 8.8
  • Vector: CVSS:4.0\/AV:N\/AC:L\/AT:N\/PR:N\/UI:N\/VC:H\/VI:L\/VA:N\/SC:N\/SI:N\/SA:N\/E:X\/CR:X\/IR:X\/AR:X\/MAV:X\/MAC:X\/MAT:X\/MPR:X\/MUI:X\/MVC:X\/MVI:X\/MVA:X\/MSC:X\/MSI:X\/MSA:X\/S:X\/AU:X\/R:X\/V:X\/RE:X\/U:X
  • Source: [NVD entry](https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-49357)

References

  • [github.com](https:\/\/github.com\/dtwang\/line-desktop-mcp\/commit\/680617894981ea93f8f6ceb51ecde7519754d501)
  • [github.com](https:\/\/github.com\/dtwang\/line-desktop-mcp\/security\/advisories\/GHSA-4hf8-5mjm-rfgq)

Actions

  • Verify affected systems in your inventory
  • Apply the vendor patch during a maintenance window
  • Restrict network-layer access until the patch is applied

Windows Server — Related Advisories

VIEW ALL →