CVE-2026-79537: Metatool-ai MetaMCP vulnerability

Published Sep 29, 2026
·
Updated

metatool-ai MetaMCP through 2.4.22 contains an insecure direct object reference (IDOR) in the MCP transport session dispatch. The session store (getSession in session-lifetime-manager.ts) is keyed only by the client-supplied mcp-session-id header with no owner, namespace, or endpoint binding, and the per-endpoint authorization middleware validates only the URL endpoint's owner, never the session. An attacker who supplies another tenant's session id " obtained without authentication from GET /metamcp/health/sessions, which discloses active session IDs and namespace UUIDs " can list and execute the victim tenant's private MCP tools and exfiltrate their data using the victim's forwarded credentials.

Affected Software

1 affected component
metatool-ai MetaMCP<=2.4.22

Event History

Sep 29, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:17 PM
Description

Frequently Asked Questions

1

What does an attacker need to exploit this issue?

An attacker needs to obtain an active victim session ID and then send it in the client-supplied mcp-session-id header. The described health endpoint, GET /metamcp/health/sessions, exposes active session IDs and namespace UUIDs without authentication.

2

Is authentication or access to the victim tenant required?

No. The disclosed session IDs can be obtained without authentication, and session dispatch does not bind the supplied session ID to an owner, namespace, or endpoint. Endpoint authorization checks only the owner of the URL endpoint, not the session being used.

3

What can an attacker do with a stolen session ID?

They can list and execute private MCP tools belonging to the victim tenant and exfiltrate data through the victim's forwarded credentials.

4

How can I determine whether my deployment is exposed?

Check whether GET /metamcp/health/sessions is reachable without authentication and returns active session IDs or namespace UUIDs. Deployments of MetaMCP through 2.4.22 are described as affected.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203