In-app reader
token-optimizer-mcp is vulnerable to OS command injection in the smart_user tool.
The get-user-info operation accepts a user-controlled username argument and later interpolates it into a shell command executed through execAsync():
getent passwd "${username}" || grep "^${username}:" /etc/passwd
Discussion
Sign in to join the discussion.
Keep reading
Optional: create a free account to save items, track programs, and sync across web + app. Reading stays free.