CVE-2026-55156 | ooples token-optimizer-mcp up to 5.0.x Dashboard HTTP Server /api/session-summary path.join sessionId path traversal
A vulnerability labeled as problematic has been found in ooples token-optimizer-mcp up to 5.0.x. This impacts the function path.join of the file /api/session-summary of the component Dashboard HTTP Server. Such manipulation of the argument sessionId leads to path traversal.
This vulnerability is traded as CVE-2026-55156. The attack may be launched remotely. There is no exploit available.
The affected component should be upgraded.VulDB Recent EntriesRead More