CVE-2026-55156: 
JavaScript vulnerability analysis and mitigation

Overview

CVE-2026-55156 is an unauthenticated path traversal vulnerability in the dashboard HTTP server of the token-optimizer-mcp npm package (GHSA-76pc-mqxp-3rq5). It affects version 5.0.1 (commit 8137147) and was first published on June 10, 2026, with the advisory added to the GitHub Advisory Database on August 14, 2026. The vulnerability allows any network-accessible, unauthenticated attacker to read arbitrary .jsonl files from the server's filesystem by manipulating the sessionId query parameter on the /api/session-summary and /api/session-events endpoints. It carries a CVSS v3.1 base score of 5.3 (Medium) (GitHub Advisory, Security Advisory).

Technical details

The root cause is CWE-22 (Improper Limitation of a Pathname to a Restricted Directory). In src/server/web-server.ts at lines 73–88 and 297–311, both the /api/session-summary and /api/session-events handlers concatenate the caller-supplied sessionId query parameter directly into a filesystem path using path.join(hooksDataPath, \session-log-${sessionId}.jsonl`), then pass the result to fs.readFileSync. Node.js normalizes ..segments at resolution time, so a craftedsessionIdsuch asabc%2F..%2F..%2F..%2F..%2Ftraversal-targettraverses outside the intendedhooksDataPathdirectory. Neither endpoint implements any authentication middleware, meaning the attack requires no credentials and can be executed with a single HTTP GET request. A working proof-of-concept usingcurl` is publicly documented in the advisory (GitHub Advisory, Security Advisory).

Impact

An unauthenticated remote attacker can read the contents of any .jsonl file accessible to the process running the dashboard server. In typical deployments, this includes all session log files containing tool invocations, hook outputs, and token usage data, as well as any other .jsonl file reachable via directory traversal from hooksDataPath. The attack surface is constrained to files with the .jsonl extension, limiting but not eliminating the risk of sensitive data exposure. There is no integrity or availability impact; the vulnerability is purely a confidentiality concern (GitHub Advisory).

Exploitability

A working proof-of-concept is publicly documented in the GitHub Security Advisory, requiring only a single unauthenticated HTTP GET request with a URL-encoded traversal payload. No privileges or user interaction are required, and attack complexity is low. There is no known evidence of in-the-wild exploitation, no threat actor attribution, and the CVE status remains "Reserved." EPSS score and CISA KEV catalog status are not available for this CVE (GitHub Advisory, Security Advisory).

Exploitation steps

  1. Reconnaissance: Identify hosts running token-optimizer-mcp version 5.0.1 with the dashboard HTTP server exposed on port 3100 (default). Scan for open port 3100 using tools like nmap or masscan.
  2. Confirm endpoint availability: Send a baseline GET request to http://<target>:3100/api/session-events?sessionId=test to confirm the server is running and the endpoint responds.
  3. Craft traversal payload: Construct a sessionId value containing URL-encoded path traversal sequences, e.g., abc%2F..%2F..%2F..%2F..%2Ftarget-file where target-file is the base name (without .jsonl) of the file to read outside hooksDataPath.
  4. Send unauthenticated request: Execute curl -s "http://<target>:3100/api/session-events?sessionId=abc%2F..%2F..%2F..%2F..%2Ftarget-file" — no authentication headers are needed.
  5. Exfiltrate data: If the target .jsonl file exists, the server returns HTTP 200 with its contents in the JSON response body, confirming successful out-of-bounds file read (GitHub Advisory, Security Advisory).

Indicators of compromise

  • Network: Inbound HTTP GET requests to port 3100 targeting /api/session-events or /api/session-summary with sessionId query parameters containing URL-encoded path separators (%2F) or dot sequences (%2E%2E, ..).
  • Logs: Express access logs showing requests such as GET /api/session-events?sessionId=abc%2F..%2F..%2F..%2F..%2F<filename> returning HTTP 200 from unexpected source IPs.
  • Network: Responses from port 3100 with Content-Type: application/json and unusually large or unexpected payloads that do not correspond to known session IDs.
  • Process: The Node.js process running token-optimizer-mcp performing fs.readFileSync calls on paths outside the ~/.claude-global/hooks/data/ directory (GitHub Advisory).

Mitigation and workarounds

Upgrade to @ooples/token-optimizer-mcp version 5.1.0 or later, which was released on July 20, 2026 and includes the fix in commit b4ee96d. The patch validates sessionId against the strict regex /^[A-Za-z0-9_-]{1,64}$/ before path construction, adds a secondary path.resolve + containment check (resolveSessionLogPath), and applies express-rate-limit (300 req/min) to all dashboard routes. As a workaround for those unable to upgrade immediately, restrict network access to port 3100 to trusted hosts only using firewall rules, or disable the dashboard server if not required (GitHub Advisory, v5.1.0 Release, Fix Commit).

Additional resources


Source: This report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-101895HIGH8.7
  • JavaScript logoJavaScript
  • @angular/platform-server
NoYesSep 28, 2026
CVE-2026-55157HIGH8.4
  • JavaScript logoJavaScript
  • @ooples/token-optimizer-mcp
NoYesSep 28, 2026
CVE-2026-101914MEDIUM6.5
  • JavaScript logoJavaScript
  • @grpc/grpc-js-xds
NoYesSep 28, 2026
GHSA-6vj9-mwq6-2f5vMEDIUM5.9
  • JavaScript logoJavaScript
  • nodemailer
NoYesSep 28, 2026
CVE-2026-55156MEDIUM5.3
  • JavaScript logoJavaScript
  • @ooples/token-optimizer-mcp
NoYesSep 28, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management