Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-49mq-fc6q-3h46 | Token Optimizer MCP: OS command injection in smart_user via username in get-user-info |
Mon, 28 Sep 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Token Optimizer MCP measures token savings per AI coding agent, optimizes context, and shares a live local knowledge graph across 16 CLI clients. Prior to version 5.1.0, token-optimizer-mcp is vulnerable to OS command injection in the smart_user tool. Any MCP client that can call the smart_user tool can execute arbitrary shell commands through the username argument of the get-user-info operation. The commands execute with the privileges of the user running the token-optimizer-mcp server. This issue has been patched in version 5.1.0. | |
| Title | Token Optimizer MCP: OS command injection in smart_user via username in get-user-info | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-28T17:48:16.422Z
Reserved: 2026-06-16T15:13:28.165Z
Link: CVE-2026-55157
No data.
Status : Received
Published: 2026-09-28T18:17:23.373
Modified: 2026-09-28T18:17:23.373
Link: CVE-2026-55157
No data.
OpenCVE Enrichment
No data.
-
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Github GHSA