Aias00 opened a new issue, #6666:
URL: https://github.com/apache/shenyu/issues/6666

   - Severity: High
   - Location:
   
`shenyu-client/shenyu-client-mcp/shenyu-client-mcp-common/src/main/java/org/apache/shenyu/client/mcp/generator/McpOpenApiGenerator.java:51`
   - 
   Description:
   Line 51 does `server.addProperty(OPEN_API_SERVER_URL_KEY, 
definition.servers()[0].url());` with no length check. 
`@ShenyuMcpTool.definition()` defaults to `@OpenAPIDefinition`, whose 
`servers()` defaults to `{}` (empty). The sibling method 
`McpServiceEventListener.buildApiSuperPath` (`:306-309`) explicitly handles 
`servers.length == 0` by returning `""`, so the empty-servers case is both 
reachable and anticipated — yet `generateOpenApiJson` was not given the same 
guard. A bare `@ShenyuMcpTool` on a controller class uses the empty default; 
`generateOpenApiJson` is reached via `buildMcpToolsRegisterDTO` → 
`McpServiceEventListener.handleMethod` whenever `superPath` does not contain 
`"*"` (the common case), and crashes immediately.
   - 
   Impact:
   Any MCP controller using `@ShenyuMcpTool` without explicitly declaring 
`@OpenAPIDefinition(servers = {@Server(url=...)})` crashes at context refresh 
with `ArrayIndexOutOfBoundsException`, making the MCP client unusable in its 
default-annotation form.
   - 
   Suggested fix:
   Guard `definition.servers()` for emptiness in `generateOpenApiJson` (skip 
the server block or throw a descriptive `IllegalArgumentException`), mirroring 
`buildApiSuperPath`.
   - 
   Confidence: High
   - Related existing: none — #6113/6117/6134 cover other MCP tool issues.
   
   ---
   _Identified during the 2026-08-02 deep re-scan; full list in 
[`docs/scan2-2026-08-02/00-consolidated-critical-high.md`](docs/scan2-2026-08-02/00-consolidated-critical-high.md)._


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to