GHSA-pc2w-4mq8-32qw: @dynatrace-oss/dynatrace-mcp-server's create_dynatrace_notebook missing the human-approval gate
A missing human-approval gate on the create_dynatrace_notebook tool allows a caller to create persistent tenant-visible documents containing arbitrary content (including embedded DQL that other users execute when opening the notebook) without operator consent.
References
- github.com/advisories/GHSA-pc2w-4mq8-32qw
- github.com/dynatrace-oss/dynatrace-mcp/commit/2851d3ce29d834c93b67f0db903c10e0b488e7ac
- github.com/dynatrace-oss/dynatrace-mcp/pull/529
- github.com/dynatrace-oss/dynatrace-mcp/releases/tag/v1.8.7
- github.com/dynatrace-oss/dynatrace-mcp/security/advisories/GHSA-pc2w-4mq8-32qw
Code Behaviors & Features
Detect and mitigate GHSA-pc2w-4mq8-32qw with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →