CVE-2026-55157: 
JavaScript vulnerability analysis and mitigation

Overview

CVE-2026-55157 is an OS command injection vulnerability in the smart_user tool of the @ooples/token-optimizer-mcp npm package. The flaw allows any MCP client that can invoke the smart_user tool to execute arbitrary shell commands on the host system with the privileges of the MCP server process. It affects versions prior to 5.1.0 (confirmed on v5.0.1) and was first disclosed on June 10, 2026, with the GitHub Advisory Database entry published on August 14, 2026. The vulnerability carries a CVSS v3.1 base score of 8.4 (High) (GitHub Advisory, Security Advisory).

Technical details

The root cause is CWE-78 (Improper Neutralization of Special Elements used in an OS Command). In the smart_user tool's get-user-info operation, the caller-supplied username argument is directly interpolated into a shell command string passed to Node.js's execAsync():

const { stdout: passwdOut } = await execAsync(
  `getent passwd "${username}" || grep "^${username}:" /etc/passwd`
);

Although the value is wrapped in double quotes, POSIX shells still evaluate command substitution constructs such as $(...) and backticks inside double quotes. An attacker can supply a crafted username value like $(id > /tmp/TOKEN_OPTIMIZER_SMART_USER_ID) to trigger arbitrary command execution before getent or grep receives its arguments. No privileges are required to call the tool — only the ability to send MCP JSON-RPC messages to the server (GitHub Advisory, Security Advisory).

Impact

Successful exploitation grants an attacker arbitrary OS command execution with the full privileges of the user running the token-optimizer-mcp server process, resulting in high confidentiality, integrity, and availability impact. An attacker can read sensitive files, create or modify arbitrary files, exfiltrate data, install backdoors, or disrupt the host system. Because MCP servers are commonly run in developer environments with broad local access, exploitation could expose source code, credentials, SSH keys, and other sensitive assets accessible to the server user (GitHub Advisory, Security Advisory).

Exploitability

A public proof-of-concept (PoC) is included in the GitHub Security Advisory, demonstrating exploitation via a Python script that sends crafted MCP JSON-RPC messages to the server. The attack requires no privileges and no user interaction, and has low complexity — any MCP client with access to the smart_user tool can exploit it. There is no evidence of in-the-wild exploitation or threat actor attribution at this time, and the CVE status remains "Reserved." CISA KEV catalog status and EPSS score are not currently available (GitHub Advisory, Security Advisory).

Exploitation steps

  1. Identify the target: Confirm the target system is running @ooples/token-optimizer-mcp version < 5.1.0 (e.g., v5.0.1) with the MCP server accessible via stdio or network transport.
  2. Set up MCP communication: Establish a JSON-RPC 2.0 session with the MCP server by sending an initialize message followed by a notifications/initialized notification.
  3. Craft the malicious payload: Construct a tools/call JSON-RPC request targeting the smart_user tool with operation: "get-user-info" and a crafted username value containing a command substitution payload, e.g.:
    {"operation": "get-user-info", "username": "$(id > /tmp/TOKEN_OPTIMIZER_SMART_USER_ID)", "useCache": false}
  4. Send the payload: Pipe the JSON-RPC messages to the MCP server process (e.g., via node dist/server/index.js over stdin), triggering the vulnerable execAsync() call in smart_user.
  5. Confirm execution: Verify that the injected command executed by checking for the output file (e.g., /tmp/TOKEN_OPTIMIZER_SMART_USER_ID) or other artifacts created by the payload. The MCP server error response may also echo the injected command string, confirming it reached the shell.
  6. Escalate: Replace the benign id payload with a reverse shell, credential harvester, or persistence mechanism to achieve the attacker's objective (GitHub Advisory, Security Advisory).

Indicators of compromise

  • File System: Unexpected files in /tmp/ with names matching TOKEN_OPTIMIZER_SMART_USER_ID* or TOKEN_OPTIMIZER_SMART_USER_PWNED; new or modified files in /tmp/ owned by the MCP server user; unexpected cron jobs or scripts created by the server process.
  • Logs: MCP server error logs (e.g., /tmp/token_optimizer_smart_user_poc.log) containing strings like Command failed: getent passwd "$(...)" or grep "^$(...):; Node.js process logs showing shell command failures with injected payloads visible in the command string.
  • Process: Unexpected child processes spawned by the Node.js MCP server process (e.g., /bin/sh, id, curl, wget, bash) visible in process trees; unusual outbound network connections from the MCP server process.
  • Network: Unexpected outbound connections from the host running the MCP server to external IPs, particularly if a reverse shell payload was used (GitHub Advisory, Security Advisory).

Mitigation and workarounds

Upgrade @ooples/token-optimizer-mcp to version 5.1.0 or later, which eliminates the vulnerability by replacing the shell-interpolated execAsync() call in smart_user with argv-mode execFileSafe() helpers that pass arguments directly to the OS without shell interpretation. The fix, released on July 20, 2026, also addresses related command injection issues across other smart_* tools. No configuration-based workaround is available for versions prior to 5.1.0 — upgrading is the only remediation (GitHub Advisory, v5.1.0 Release, Fix Commit).

Additional resources


Source: This report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-101895HIGH8.7
  • JavaScript logoJavaScript
  • @angular/platform-server
NoYesSep 28, 2026
CVE-2026-55157HIGH8.4
  • JavaScript logoJavaScript
  • @ooples/token-optimizer-mcp
NoYesSep 28, 2026
CVE-2026-101914MEDIUM6.5
  • JavaScript logoJavaScript
  • @grpc/grpc-js-xds
NoYesSep 28, 2026
GHSA-6vj9-mwq6-2f5vMEDIUM5.9
  • JavaScript logoJavaScript
  • nodemailer
NoYesSep 28, 2026
CVE-2026-55156MEDIUM5.3
  • JavaScript logoJavaScript
  • @ooples/token-optimizer-mcp
NoYesSep 28, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management