CVE-2026-79538: Code Injection
Published Sep 29, 2026
·Updated
metatool-ai MetaMCP up to and including 2.4.22 is vulnerable to Code Execution in the internal MCP inspector proxy endpoint GET /mcp-proxy/server/stdio (createTransport, STDIO branch, routers/mcp-proxy/server.ts).
Affected Software
1 affected component
metatool-ai MetaMCP<=2.4.22
Event History
Sep 29, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which MetaMCP versions should be treated as affected?
metatool-ai MetaMCP versions up to and including 2.4.22 are identified as vulnerable.
2
What component should be prioritized during triage?
Assess the internal MCP inspector proxy endpoint at GET /mcp-proxy/server/stdio, specifically the createTransport STDIO branch in routers/mcp-proxy/server.ts.