CVE-2026-55157 | ooples token-optimizer-mcp up to 5.0.x smart_user Username os command injection

SecurityVulns

A vulnerability identified as problematic has been detected in ooples token-optimizer-mcp up to 5.0.x. This affects an unknown function of the component smart_user. This manipulation of the argument Username causes os command injection.

This vulnerability appears as CVE-2026-55157. The attack requires local access. There is no available exploit.

You should upgrade the affected component.VulDB Recent EntriesRead More