CVE-2026-79538 | metatool-ai MetaMCP up to 2.4.22 MCP Inspector Proxy Endpoint server.ts createTransport code injection

SecurityVulns

A vulnerability labeled as critical has been found in metatool-ai MetaMCP up to 2.4.22. Affected by this issue is the function createTransport of the file routers/mcp-proxy/server.ts of the component MCP Inspector Proxy Endpoint. Such manipulation leads to code injection.

This vulnerability is traded as CVE-2026-79538. The attack may be launched remotely. There is no exploit available.VulDB Recent EntriesRead More