What happened
Multiple high-severity advisories (GHSA-29p3-56wx-ggfh critical for command injection, GHSA-8w8q-fgv9-j286, GHSA-49mq-fc6q-3h46, GHSA-76pc-mqxp-3rq5) were fixed in 5.1.0. The fix eliminates OS command injection across the smart_* tool surface, hardens arg validation, and gates the unauthenticated session-summary/session-events endpoints (CVE-2026-55156).
Why it matters
token-optimizer-mcp is an MCP server that AI coding agents are explicitly wired to call for context optimization; command injection reachable through an agent-invoked tool means a poisoned repo, prompt injection, or already-compromised agent turns into direct host RCE on the developer workstation, exactly the agent-tool-to-RCE blast radius that matters for agentic security.
Attack vector
Command strings built from user/tool-controlled arguments flow into execSync-style shell sinks (getent/grep/cat pipelines) in the smart_user tool; the server's dashboard HTTP endpoints also have no authentication and no session-id validation for path traversal.
Affected systems
ooples/token-optimizer-mcp < 5.1.0 (MCP agent-context optimizer used across 16 CLI clients)
Mitigation
Upgrade to token-optimizer-mcp 5.1.0 (commit b4ee96d), which converts all smart_* tools to argv-mode execFileSafe/spawnSafe execution, validates refs/paths/package specs, adds rate limiting and session-id validation on the web server, and is covered by GHSA-29p3-56wx-ggfh / GHSA-49mq-fc6q-3h46 / GHSA-76pc-mqxp-3rq5.