Vulnerability  ·  2026-09-30

MetaMCP critical unauthenticated code execution via internal MCP inspector proxy endpoint

VulnerabilityHigh impactGlobalCVE-2026-79538
NVD published CVE-2026-79538 (CVSS 9.8, Critical) on 2026-09-29. MetaMCP's internal MCP inspector proxy endpoint GET /mcp-proxy/server/stdio (routers/mcp-proxy/server.ts, createTransport STDIO branch) allows code execution. CISA SSVC marks automatable 'yes', technical impact 'total'.
MetaMCP is an MCP-based agent platform; the inspector proxy endpoint is reachable over the network and lets an unauthenticated attacker execute commands on the host running the agent/MCP infrastructure, giving control over connected MCP tools, sessions, and the AI agents they power.
Remote, unauthenticated GET to /mcp-proxy/server/stdio (createTransport STDIO branch) in the MCP inspector proxy; the proxy spawns/executes commands through the STDIO transport, yielding code execution.
metatool-ai MetaMCP up to and including 2.4.22
Audit/replace the inspector proxy endpoint; restrict network access to /mcp-proxy paths; wait on MetaMCP patch (advisory by TraceForce: https://www.traceforce.ai/security-advisories/cve-2026-79538).
NVD CVE-2026-79538TraceForce advisory
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →