THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-xrmj-5g4g-8987 (medium) — @dynatrace-oss/dynatrace-mcp-server has a workflow template injection via create_workflow_for_notification

[GHSA] GHSA-xrmj-5g4g-8987 (medium) — @dynatrace-oss/dynatrace-mcp-server has a workflow template injection via create_workflow_for_notification

highgithub_advisoriesPublished 2026-07-31

GHSA-xrmj-5g4g-8987 Severity: medium CVE: None

@dynatrace-oss/dynatrace-mcp-server has a workflow template injection via create_workflow_for_notification

### Summary A template injection vulnerability in the `create_workflow_for_notification` tool lets a caller embed Jinja2 expressions that the Dynatrace workflow engine evaluates at runtime, exfiltrating event data to attacker-controlled destina

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-xrmj-5g4g-8987