PT-2026-69189 · Abdullah1854 · Mcp-Gateway
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
abdullah1854 MCPGateway versions up to 549f494a9e363f40530149de324b8097de424230
Description
Remote command injection is possible within the Claude Usage Range Endpoint component. The issue exists in the
getUsageByDateRange() function located in the src/services/claude-usage.ts file, where improper handling of the since argument allows an attacker to execute arbitrary commands on the system.Recommendations
As a temporary workaround, restrict access to the
getUsageByDateRange() function until a fix is released.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Command Injection
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mcp-Gateway