Vulnerability  ·  2026-09-30

SurfSense MCP connector test endpoint command injection (public exploit)

VulnerabilityHigh impactGlobalCVE-2026-102243
NVD published CVE-2026-102243 (CVSS 7.4 v3.1) on 2026-09-29. SurfSense (an AI search/RAG platform with MCP connector integration) runs a command-injection sink in the MCP connector test handler; the exploit is public and vendor did not respond. No fix release noted as of publication.
SurfSense is a GenAI search/RAG product whose whole point is connecting to external data sources via MCP connectors; command injection in the connector-test path means an authenticated user can achieve OS-level command execution on the AI platform host, from where model data, ingested documents, credentials, and the agent environment are reachable.
Remote authenticated attacker invokes the MCP connector test endpoint /api/search-source/connectors/mcp/test with crafted input that reaches a shell command path (CWE-77 command injection); exploit is publicly available (SSVC exploitation='poc').
MODSetter SurfSense up to 2.0.3 (MCP Connector Integration, /api/search-source/connectors/mcp/test)
No vendor fix as of publication; restrict/disable the MCP connector test endpoint, apply network segmentation, and monitor for patched releases (VulDB entries for submit/411141).
NVD CVE-2026-102243Public gist (PoC)
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →