THREAT OPS › Threat News › [GHSA] GHSA-pc2w-4mq8-32qw (low) — @dynatrace-oss/dynatrace-mcp-server's create_dynatrace_notebook missing the human-approval gate
[GHSA] GHSA-pc2w-4mq8-32qw (low) — @dynatrace-oss/dynatrace-mcp-server's create_dynatrace_notebook missing the human-approval gate
GHSA-pc2w-4mq8-32qw Severity: low CVE: None
@dynatrace-oss/dynatrace-mcp-server's create_dynatrace_notebook missing the human-approval gate
### Summary A missing human-approval gate on the `create_dynatrace_notebook` tool allows a caller to create persistent tenant-visible documents containing arbitrary content (including embedded DQL that other users execute when opening the notebook) without o
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- http://127.0.0.1:3000/url
- apps.dynatrace.comdomain
Original source: https://github.com/advisories/GHSA-pc2w-4mq8-32qw