CVE-2026-79537: Metatool-ai MetaMCP vulnerability
metatool-ai MetaMCP through 2.4.22 contains an insecure direct object reference (IDOR) in the MCP transport session dispatch. The session store (getSession in session-lifetime-manager.ts) is keyed only by the client-supplied mcp-session-id header with no owner, namespace, or endpoint binding, and the per-endpoint authorization middleware validates only the URL endpoint's owner, never the session. An attacker who supplies another tenant's session id " obtained without authentication from GET /metamcp/health/sessions, which discloses active session IDs and namespace UUIDs " can list and execute the victim tenant's private MCP tools and exfiltrate their data using the victim's forwarded credentials.
Affected Software
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
An attacker needs to obtain an active victim session ID and then send it in the client-supplied mcp-session-id header. The described health endpoint, GET /metamcp/health/sessions, exposes active session IDs and namespace UUIDs without authentication.
Is authentication or access to the victim tenant required?
No. The disclosed session IDs can be obtained without authentication, and session dispatch does not bind the supplied session ID to an owner, namespace, or endpoint. Endpoint authorization checks only the owner of the URL endpoint, not the session being used.
What can an attacker do with a stolen session ID?
They can list and execute private MCP tools belonging to the victim tenant and exfiltrate data through the victim's forwarded credentials.
How can I determine whether my deployment is exposed?
Check whether GET /metamcp/health/sessions is reachable without authentication and returns active session IDs or namespace UUIDs. Deployments of MetaMCP through 2.4.22 are described as affected.