Vulnerabilità · 142 giorni fa
L’assunzione errata è che Code Runner MCP Server sia un helper locale. Quando viene avviato con --transport http, espone un endpoint JSON-RPC senza autenticazione che consente a un chiamante remoto di eseguire codice arbitrario come utente del server. Questo trasforma un’interfaccia di comodità in una backdoor a livello di processo per tutto ciò che quell’account può raggiungere.
1 fonte che coprono questa storia
Vulnerability in Code Runner MCP Server project
Missing Authentication for Critical Function vulnerability (CVE-2026-5029) has been found in Code Runner MCP Server software.
Part of the PlainSec briefing for 2026-05-12