Vulnerabilità ed exploit
L’assunzione errata è che Code Runner MCP Server sia un helper locale. Quando viene avviato con --transport http, espone un endpoint JSON-RPC senza autenticazione che consente a un chiamante remoto di eseguire codice arbitrario come utente del server. Questo trasforma un’interfaccia di comodità in una backdoor a livello di processo per tutto ciò che quell’account può raggiungere.
1 fonte · 12 mag
CERT Polska
Vulnerability in Code Runner MCP Server project
Missing Authentication for Critical Function vulnerability (CVE-2026-5029) has been found in Code Runner MCP Server software.
originalePart of the PlainSec briefing for 2026-05-12
Every edition of this story: La modalità HTTP trasforma Code Runner in una superficie di codice remoto