CVE-2026-79538
published 2026-09-29CVE-2026-79538: metatool-ai MetaMCP up to and including 2.4.22 is vulnerable to Code Execution in the internal MCP inspector proxy endpoint GET /mcp-proxy/server/stdio…
PriorityP260critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.43%
35.7th percentile
metatool-ai MetaMCP up to and including 2.4.22 is vulnerable to Code Execution in the internal MCP inspector proxy endpoint GET /mcp-proxy/server/stdio (createTransport, STDIO branch, routers/mcp-proxy/server.ts).
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
metatool-ai MetaMCP up to 2.4.22 MCP Inspector Proxy Endpoint server.ts createTransport code injection
vuldb·2026-09-29·CVSS 9.8
CVE-2026-79538 [CRITICAL] metatool-ai MetaMCP up to 2.4.22 MCP Inspector Proxy Endpoint server.ts createTransport code injection
A vulnerability labeled as critical has been found in metatool-ai MetaMCP up to 2.4.22. Affected by this issue is the function createTransport of the file routers/mcp-proxy/server.ts of the component MCP Inspector Proxy Endpoint. Such manipulation leads to code injection.
This vulnerability is traded as CVE-2026-79538. The attack may be launched remotely. There is no exploit available.
GHSA
metatool-ai MetaMCP up to and including 2.4.22 is vulnerable to Code Execution in the internal MCP inspector proxy endpoint GET /mcp-proxy/server/stdio (createTransport, STDIO branch, routers/mcp-prox
ghsa_unreviewed·2026-09-29
CVE-2026-79538 [CRITICAL] CWE-94 metatool-ai MetaMCP up to and including 2.4.22 is vulnerable to Code Execution in the internal MCP inspector proxy endpoint GET /mcp-proxy/server/stdio (createTransport, STDIO branch, routers/mcp-prox
metatool-ai MetaMCP up to and including 2.4.22 is vulnerable to Code Execution in the internal MCP inspector proxy endpoint GET /mcp-proxy/server/stdio (createTransport, STDIO branch, routers/mcp-proxy/server.ts).
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-09-29
Published