Vulnerability Description
CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior to 1.7.2, GET /mcp/form/config/{formKey} calls McpController.getMcpField without authentication because ShiroFilter.addPublicPathFilters marks /mcp/** as anonymous and the controller has no permission annotation. An unauthenticated caller can obtain field names, types, required flags, default values, options, validation rules, and binding sources for CRM modules, allowing reconstruction of the application data model and more targeted attacks against other inputs. This issue is fixed in version 1.7.2.
Related Weaknesses (CWE)
References
- https://github.com/1Panel-dev/CordysCRM/commit/ea8d5f128b94659ce881e9d034a37c18f
- https://github.com/1Panel-dev/CordysCRM/pull/2725
- https://github.com/1Panel-dev/CordysCRM/releases/tag/v1.7.2
- https://github.com/1Panel-dev/CordysCRM/security/advisories/GHSA-46p5-m7pq-82hm
FAQ
What is CVE-2026-63646?
CVE-2026-63646 is a documented vulnerability. CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior to 1.7.2, GET /mcp/form/config/{formKey} calls McpController.getMcpField without ...
How severe is CVE-2026-63646?
CVSS scoring is not yet available for CVE-2026-63646. Check NVD for updates.
Is there a patch for CVE-2026-63646?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.