VYPR

metamcp

by Metatool AI

CVEs (2)

  • CVE-2026-79538CriSep 29, 2026
    risk 0.64cvss 9.8epss —

    metatool-ai MetaMCP up to and including 2.4.22 is vulnerable to Code Execution in the internal MCP inspector proxy endpoint GET /mcp-proxy/server/stdio (createTransport, STDIO branch, routers/mcp-proxy/server.ts).

  • CVE-2026-79537Sep 29, 2026
    risk 0.00cvss —epss —

    metatool-ai MetaMCP through 2.4.22 contains an insecure direct object reference (IDOR) in the MCP transport session dispatch. The session store (getSession in session-lifetime-manager.ts) is keyed only by the client-supplied mcp-session-id header with no owner, namespace, or…