PT-2026-102820 · Metatool Ai · Metamcp
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
metatool-ai MetaMCP versions 2.4.22 and earlier
Description
An insecure direct object reference (IDOR) exists in the MCP transport session dispatch. The session store, specifically the
getSession() function in session-lifetime-manager.ts, relies solely on the mcp-session-id header provided by the client without verifying the owner, namespace, or endpoint binding. Additionally, the per-endpoint authorization middleware only validates the owner of the URL endpoint and does not validate the session. An attacker can obtain active session IDs and namespace UUIDs via the GET /metamcp/health/sessions endpoint without authentication. By supplying another tenant's session ID, an attacker can list and execute private MCP tools of the victim tenant and exfiltrate data using the victim's forwarded credentials.Recommendations
Update metatool-ai MetaMCP to a version later than 2.4.22.
Restrict access to the
GET /metamcp/health/sessions endpoint to prevent the disclosure of active session IDs and namespace UUIDs.Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Metamcp