CVE-2025-20381
SPL commands allowlist controls bypass in Splunk MCP Server app through "run_splunk_query" MCP tool
Exploited
Not listed
EPSS
0.002
11.4th percentile
Discovered by
Not disclosed
Published
Dec 3, 2025
Assigned by cisco
Description
In Splunk MCP Server app versions below 0.2.4, a user with access to the "run_splunk_query" Model Context Protocol (MCP) tool could bypass the SPL command allowlist controls in MCP by embedding SPL commands as sub-searches, leading to unauthorized actions beyond the intended MCP restrictions.
Weakness: CWE-863
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Cisco | Splunk Apps & Add-ons | SIEM & Log Management | cna-assigner |
Vendor-reported products (1)
- Splunk · Splunk MCP Server
Credit
Saket Pandey, Splunk