Vulnerabilità · 142 giorni fa

La modalità HTTP trasforma Code Runner in una superficie di codice remoto

L’assunzione errata è che Code Runner MCP Server sia un helper locale. Quando viene avviato con --transport http, espone un endpoint JSON-RPC senza autenticazione che consente a un chiamante remoto di eseguire codice arbitrario come utente del server. Questo trasforma un’interfaccia di comodità in una backdoor a livello di processo per tutto ciò che quell’account può raggiungere.

CVE-2026-5029

NVD KEV

Cronologia

Fonti

1 fonte che coprono questa storia

Entità

Part of the PlainSec briefing for 2026-05-12

Editions

Storie correlate