
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-55156 is an unauthenticated path traversal vulnerability in the dashboard HTTP server of the token-optimizer-mcp npm package (GHSA-76pc-mqxp-3rq5). It affects version 5.0.1 (commit 8137147) and was first published on June 10, 2026, with the advisory added to the GitHub Advisory Database on August 14, 2026. The vulnerability allows any network-accessible, unauthenticated attacker to read arbitrary .jsonl files from the server's filesystem by manipulating the sessionId query parameter on the /api/session-summary and /api/session-events endpoints. It carries a CVSS v3.1 base score of 5.3 (Medium) (GitHub Advisory, Security Advisory).
The root cause is CWE-22 (Improper Limitation of a Pathname to a Restricted Directory). In src/server/web-server.ts at lines 73–88 and 297–311, both the /api/session-summary and /api/session-events handlers concatenate the caller-supplied sessionId query parameter directly into a filesystem path using path.join(hooksDataPath, \session-log-${sessionId}.jsonl`), then pass the result to fs.readFileSync. Node.js normalizes ..segments at resolution time, so a craftedsessionIdsuch asabc%2F..%2F..%2F..%2F..%2Ftraversal-targettraverses outside the intendedhooksDataPathdirectory. Neither endpoint implements any authentication middleware, meaning the attack requires no credentials and can be executed with a single HTTP GET request. A working proof-of-concept usingcurl` is publicly documented in the advisory (GitHub Advisory, Security Advisory).
An unauthenticated remote attacker can read the contents of any .jsonl file accessible to the process running the dashboard server. In typical deployments, this includes all session log files containing tool invocations, hook outputs, and token usage data, as well as any other .jsonl file reachable via directory traversal from hooksDataPath. The attack surface is constrained to files with the .jsonl extension, limiting but not eliminating the risk of sensitive data exposure. There is no integrity or availability impact; the vulnerability is purely a confidentiality concern (GitHub Advisory).
A working proof-of-concept is publicly documented in the GitHub Security Advisory, requiring only a single unauthenticated HTTP GET request with a URL-encoded traversal payload. No privileges or user interaction are required, and attack complexity is low. There is no known evidence of in-the-wild exploitation, no threat actor attribution, and the CVE status remains "Reserved." EPSS score and CISA KEV catalog status are not available for this CVE (GitHub Advisory, Security Advisory).
token-optimizer-mcp version 5.0.1 with the dashboard HTTP server exposed on port 3100 (default). Scan for open port 3100 using tools like nmap or masscan.http://<target>:3100/api/session-events?sessionId=test to confirm the server is running and the endpoint responds.sessionId value containing URL-encoded path traversal sequences, e.g., abc%2F..%2F..%2F..%2F..%2Ftarget-file where target-file is the base name (without .jsonl) of the file to read outside hooksDataPath.curl -s "http://<target>:3100/api/session-events?sessionId=abc%2F..%2F..%2F..%2F..%2Ftarget-file" — no authentication headers are needed..jsonl file exists, the server returns HTTP 200 with its contents in the JSON response body, confirming successful out-of-bounds file read (GitHub Advisory, Security Advisory)./api/session-events or /api/session-summary with sessionId query parameters containing URL-encoded path separators (%2F) or dot sequences (%2E%2E, ..).GET /api/session-events?sessionId=abc%2F..%2F..%2F..%2F..%2F<filename> returning HTTP 200 from unexpected source IPs.Content-Type: application/json and unusually large or unexpected payloads that do not correspond to known session IDs.token-optimizer-mcp performing fs.readFileSync calls on paths outside the ~/.claude-global/hooks/data/ directory (GitHub Advisory).Upgrade to @ooples/token-optimizer-mcp version 5.1.0 or later, which was released on July 20, 2026 and includes the fix in commit b4ee96d. The patch validates sessionId against the strict regex /^[A-Za-z0-9_-]{1,64}$/ before path construction, adds a secondary path.resolve + containment check (resolveSessionLogPath), and applies express-rate-limit (300 req/min) to all dashboard routes. As a workaround for those unable to upgrade immediately, restrict network access to port 3100 to trusted hosts only using firewall rules, or disable the dashboard server if not required (GitHub Advisory, v5.1.0 Release, Fix Commit).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."