
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-55157 is an OS command injection vulnerability in the smart_user tool of the @ooples/token-optimizer-mcp npm package. The flaw allows any MCP client that can invoke the smart_user tool to execute arbitrary shell commands on the host system with the privileges of the MCP server process. It affects versions prior to 5.1.0 (confirmed on v5.0.1) and was first disclosed on June 10, 2026, with the GitHub Advisory Database entry published on August 14, 2026. The vulnerability carries a CVSS v3.1 base score of 8.4 (High) (GitHub Advisory, Security Advisory).
The root cause is CWE-78 (Improper Neutralization of Special Elements used in an OS Command). In the smart_user tool's get-user-info operation, the caller-supplied username argument is directly interpolated into a shell command string passed to Node.js's execAsync():
const { stdout: passwdOut } = await execAsync(
`getent passwd "${username}" || grep "^${username}:" /etc/passwd`
);Although the value is wrapped in double quotes, POSIX shells still evaluate command substitution constructs such as $(...) and backticks inside double quotes. An attacker can supply a crafted username value like $(id > /tmp/TOKEN_OPTIMIZER_SMART_USER_ID) to trigger arbitrary command execution before getent or grep receives its arguments. No privileges are required to call the tool — only the ability to send MCP JSON-RPC messages to the server (GitHub Advisory, Security Advisory).
Successful exploitation grants an attacker arbitrary OS command execution with the full privileges of the user running the token-optimizer-mcp server process, resulting in high confidentiality, integrity, and availability impact. An attacker can read sensitive files, create or modify arbitrary files, exfiltrate data, install backdoors, or disrupt the host system. Because MCP servers are commonly run in developer environments with broad local access, exploitation could expose source code, credentials, SSH keys, and other sensitive assets accessible to the server user (GitHub Advisory, Security Advisory).
A public proof-of-concept (PoC) is included in the GitHub Security Advisory, demonstrating exploitation via a Python script that sends crafted MCP JSON-RPC messages to the server. The attack requires no privileges and no user interaction, and has low complexity — any MCP client with access to the smart_user tool can exploit it. There is no evidence of in-the-wild exploitation or threat actor attribution at this time, and the CVE status remains "Reserved." CISA KEV catalog status and EPSS score are not currently available (GitHub Advisory, Security Advisory).
@ooples/token-optimizer-mcp version < 5.1.0 (e.g., v5.0.1) with the MCP server accessible via stdio or network transport.initialize message followed by a notifications/initialized notification.tools/call JSON-RPC request targeting the smart_user tool with operation: "get-user-info" and a crafted username value containing a command substitution payload, e.g.:{"operation": "get-user-info", "username": "$(id > /tmp/TOKEN_OPTIMIZER_SMART_USER_ID)", "useCache": false}node dist/server/index.js over stdin), triggering the vulnerable execAsync() call in smart_user./tmp/TOKEN_OPTIMIZER_SMART_USER_ID) or other artifacts created by the payload. The MCP server error response may also echo the injected command string, confirming it reached the shell.id payload with a reverse shell, credential harvester, or persistence mechanism to achieve the attacker's objective (GitHub Advisory, Security Advisory)./tmp/ with names matching TOKEN_OPTIMIZER_SMART_USER_ID* or TOKEN_OPTIMIZER_SMART_USER_PWNED; new or modified files in /tmp/ owned by the MCP server user; unexpected cron jobs or scripts created by the server process./tmp/token_optimizer_smart_user_poc.log) containing strings like Command failed: getent passwd "$(...)" or grep "^$(...):; Node.js process logs showing shell command failures with injected payloads visible in the command string./bin/sh, id, curl, wget, bash) visible in process trees; unusual outbound network connections from the MCP server process.Upgrade @ooples/token-optimizer-mcp to version 5.1.0 or later, which eliminates the vulnerability by replacing the shell-interpolated execAsync() call in smart_user with argv-mode execFileSafe() helpers that pass arguments directly to the OS without shell interpretation. The fix, released on July 20, 2026, also addresses related command injection issues across other smart_* tools. No configuration-based workaround is available for versions prior to 5.1.0 — upgrading is the only remediation (GitHub Advisory, v5.1.0 Release, Fix Commit).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."