ZDS-2025-0137HIGH7.4CWE-200EMBARGOEDdisclosed 2025-04-06

Prompt-injectable cookie exfiltration

/summary

Summary

MCP server returns full document.cookie when LLM is convinced via injected page content. No origin filtering.

/poc

Proof-of-concept

# Reproduction steps redacted under coordinated disclosure.
# Full PoC will be published with the advisory at embargo expiry.

$ zds reproduce ZDS-2025-0137
ZDS-2025-0137 — Prompt-injectable cookie exfiltration · ZeroDayShield