CVE-2026-79538

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

metatool-ai MetaMCP up to and including 2.4.22 is vulnerable to Code Execution in the internal MCP inspector proxy endpoint GET /mcp-proxy/server/stdio (createTransport, STDIO branch, routers/mcp-proxy/server.ts).

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-08: 110-08
Full discourse1 post
  • IA en Bruto@IAenBruto

    MetaMCP (el gateway que junta varios MCP servers detrás de un endpoint) tiene 2 CVE críticos sin parche hasta la 2.4.22. • CVE-2026-79538: /mcp-proxy/server/stdio arranca procesos con parámetros del usuario. El registro viene abierto por defecto, así que cualquiera se crea cuenta y ejecuta comandos en el contenedor. • CVE-2026-79537: las sesiones solo se identifican por su ID, y /metamcp/health/sessions las lista sin auth. Resultado: usás las tools de otro tenant con sus credenciales. Si lo tenés expuesto, hoy: 1. Bloqueá /mcp-proxy/ y /metamcp/health/sessions en el reverse proxy 2. Apagá el auto-registro 3. Rotá los secretos de ese contenedor Check: curl -s https://TU-HOST/metamcp/health/sessions ¿Te devuelve sesiones sin login?

    0000034
    126 followersView on X

Explore more