The client controls the argument and could send true directly, so the practical impact is limited to hosts whose behaviour on false differs from their behaviour on true, and to any policy layer in front of the server that permits false but refuses true. The same normalisation applies to prompts/get arguments, which exist from 0.5.0.
This issue affects beam_mcp: from 0.1.0 before 0.10.1.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
In the host's dispatch function, compare boolean arguments against both forms, for example args.flag in [true, "true"] and args.flag in [false, "false"], and treat the string "nil" as null where the schema admits null.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 08 Oct 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incorrect Type Conversion or Cast vulnerability in BeamMCP.Server in ScriptKittyOS beam_mcp allows an MCP client's JSON true, false and null tool arguments to reach the host's dispatch function as the strings "true", "false" and "nil". After BeamMCP.Schema.validate/2 accepted a value as a boolean, normalize_arguments/2 passed every argument through to_json_value/1, whose atom clause converts true, false and nil to strings. A string is truthy in Elixir, so a host that tests a boolean argument, for example if args.dry_run, takes the opposite branch for false, and a guard such as confirm: false reads as set. The client controls the argument and could send true directly, so the practical impact is limited to hosts whose behaviour on false differs from their behaviour on true, and to any policy layer in front of the server that permits false but refuses true. The same normalisation applies to prompts/get arguments, which exist from 0.5.0. This issue affects beam_mcp: from 0.1.0 before 0.10.1. | |
| Title | beam_mcp: JSON boolean and null tool arguments reach dispatch as strings | |
| First Time appeared |
Scriptkittyos
Scriptkittyos beam Mcp |
|
| Weaknesses | CWE-704 | |
| CPEs | cpe:2.3:a:scriptkittyos:beam_mcp:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Scriptkittyos
Scriptkittyos beam Mcp |
|
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: EEF
Published:
Updated: 2026-10-08T13:58:34.464Z
Reserved: 2026-10-04T16:00:02.420Z
Link: CVE-2026-104634
No data.
No data.
No data.
OpenCVE Enrichment
No data.
-
CWE-704
Incorrect Type Conversion or Cast