PT-2026-102437 · Modsetter · Surfsense
CVSS v3.1
7.4
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
MODSetter SurfSense versions prior to 2.0.4
Description
An issue in the MCP Connector Integration component allows for remote command injection. This occurs due to improper processing of the
/api/search-source/connectors/mcp/test endpoint.Recommendations
Update MODSetter SurfSense to version 2.0.4 or later.
As a temporary workaround, restrict access to the
/api/search-source/connectors/mcp/test endpoint to minimize the risk of exploitation.Exploit
Fix
Special Elements Injection
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Surfsense