Vicious Circle

What is Vicious Circle?

Vicious Circle is the name Pluto Security Research gave to a critical, CVSS 10.0-rated remote code execution vulnerability found in CircleCI’s MCP server. It is published as a 4,500-word technical disclosure.

Why the severity rating matters

A CVSS score of 10.0 is the maximum possible rating under CVSS, reserved for vulnerabilities that are both trivially exploitable and capable of full system compromise. Finding a vulnerability with this rating in a CI/CD platform’s MCP server specifically underscores the level of access an MCP integration can potentially provide: CI/CD systems typically hold deployment credentials and can provide access to pipeline codebases, repositories, and other deployment resources, creating a significant downstream blast radius if an MCP server is compromised. maximum-severity finding in this specific location represents a worst-case combination: the highest possible exploitability paired with one of the highest-value targets an attacker could reach through an MCP integration.

Why this is a supply chain finding, not just a single-product bug

CircleCI’s MCP server is used across multiple organizations that did not build or independently review the component themselves. A single critical vulnerability in a widely adopted MCP server can therefore represent a supply chain risk: the same underlying flaw does not just affect one company; it potentially affects every organization that adopted the server without an independent security review, all at once, the moment the underlying flaw becomes known.

Why this finding had so little internal visibility on Pluto’s own site

Despite being the most severe disclosure in Pluto’s research history, this finding has had essentially no internal links pointing to or from it on pluto.security. This means neither search engines nor readers browsing related content are likely to encounter it. Correcting that is a low-effort, high-value fix independent of anything covered in this glossary entry: linking to it from the MCP Security page, from Shadow MCP Server, and from any future MCP-focused content.

FAQs

1. What is the exact CVE for this finding?

See the full Vicious Circle research write-up for the CVE identifier and remediation timeline.

2. Has CircleCI fixed this?

See the full research write-up for disclosure and patch status.

3. Why is this called a supply chain finding rather than just a CircleCI bug?

Because the vulnerable component, an MCP server, is adopted by multiple organizations as a third-party dependency rather than built in-house. Vulnerabilities in such components can affect organizations that deploy them, depending on their configuration and permissions.

4. Is a CVSS 10.0 rating common?

No. It’s the maximum possible CVSS score and is reserved for vulnerabilities that combine trivial exploitability with complete system compromise. This makes it a genuinely rare rating even across a large volume of published vulnerabilities.