CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 5.4. See the original NVD description below for full technical details.
CVE
CVE-2025-20381
Severity
MEDIUM
CVSS
5.4
EPSS
0.22%
Original NVD Description
In Splunk MCP Server app versions below 0.2.4, a user with access to the "run_splunk_query" Model Context Protocol (MCP) tool could bypass the SPL command allowlist controls in MCP by embedding SPL commands as sub-searches, leading to unauthorized actions beyond the intended MCP restrictions.