Skip to content

MCPwatch.tech

  • Home
  • MCP Watch
  • Exposure Ledger
  • Products
  • Blog
  • About
  • Contact

cve-2026-58500

CVE-2026-58500: MCP Appium Fixes XSS in Locator Generator UI

July 18, 2026 by MCPwatch Editorial Desk
mobile agent free stock image for MCPwatch editorial use

A high-severity XSS in MCP Appium’s createLocatorGeneratorUI lets attacker-controlled mobile-app element attributes drive arbitrary tool execution through the MCP-UI resource. Review the affected versions, fix, and exposure conditions.

Categories CVE Watch Tags appium-mcp, CVE, cve-2026-58500, MCP, mcp-ui, mobile-automation, Model Context Protocol, xss Leave a comment

Recent Posts

  • cloud infrastructure free stock image for MCPwatch editorial use
    CVE-2026-15829: MCP Toolbox BigQuery Forecast Query Boundary Bypass
  • api network free stock image for MCPwatch editorial use
    CVE-2026-54549: meta-ads-mcp SSRF in upload_ad_image Fetch
  • audit desk free stock image for MCPwatch editorial use
    CVE-2026-44653: LibreChat MCP Views Expose Decrypted Secrets
  • authentication free stock image for MCPwatch editorial use
    CVE-2026-15583: Grafana MCP Fixes Credentialed SSRF
  • identity access free stock image for MCPwatch editorial use
    CVE-2026-54449: LangBot MCP Authenticated RCE
© 2026 MCPwatch.tech • Built with GeneratePress