Security Advisories

Vulnerability Research

Advisory cover image
Latest Advisory

CVE-2026-79538 : Authenticated OS command injection and container RCE in metatool-ai/metamcp

MetaMCP's inspector proxy accepts user-controlled process parameters. An authenticated user may be able to execute commands inside the application container.
calendar
September 22, 2026
Read advisory
Read advisory
blog bg

Explore Advisories

Advisory cover image
Critical
calendar
September 22, 2026
CVE-2026-79538 : Authenticated OS command injection and container RCE in metatool-ai/metamcp
CVE-2026-79538
CWE-78
Advisory cover image
High
calendar
September 22, 2026
CVE-2026-79537 : Cross-tenant session hijack in metatool-ai/metamcp
CVE-2026-79537
CWE-639
Advisory cover image
Critical
calendar
September 22, 2026
CVE-2026-79536 : Read-only mode bypass in bytebase/dbhub on MySQL and MariaDB
CVE-2026-79536
CWE-863
Advisory cover image
Medium
calendar
September 22, 2026
CVE-2026-79534 : Symlink allow-list bypass in mark3labs/mcp-filesystem-server
CVE-2026-79534
CWE-59
Advisory cover image
Medium
calendar
September 22, 2026
CVE-2026-79535 : OS command injection in mbailey/voicemode update_config
CVE-2026-79535
CWE-78
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.