PT-2026-102820 · Metatool Ai · Metamcp

·

CVE-2026-79537

·

Published

2026-09-29

·

Updated

2026-10-03

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions metatool-ai MetaMCP versions 2.4.22 and earlier
Description An insecure direct object reference (IDOR) exists in the MCP transport session dispatch. The session store, specifically the getSession() function in session-lifetime-manager.ts, relies solely on the mcp-session-id header provided by the client without verifying the owner, namespace, or endpoint binding. Additionally, the per-endpoint authorization middleware only validates the owner of the URL endpoint and does not validate the session. An attacker can obtain active session IDs and namespace UUIDs via the GET /metamcp/health/sessions endpoint without authentication. By supplying another tenant's session ID, an attacker can list and execute private MCP tools of the victim tenant and exfiltrate data using the victim's forwarded credentials.
Recommendations Update metatool-ai MetaMCP to a version later than 2.4.22. Restrict access to the GET /metamcp/health/sessions endpoint to prevent the disclosure of active session IDs and namespace UUIDs.

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-79537

Affected Products

Metamcp