MediumVulnerability
CVE-2026-55156: Token Optimizer MCP measures token savings per AI coding agent, optimizes context, and shares a live local knowledge…
- Source
- NVD(opens in a new tab)
- Identifier
- CVE-2026-55156
- Published
- Record updated
Summary
Token Optimizer MCP versions before 5.1.0 run a dashboard HTTP server whose /api/session-summary and /api/session-events endpoints have no authentication middleware. Both handlers join the caller-supplied sessionId query parameter into a filesystem path with path.join, and Node.js normalizes .. segments, so an unauthenticated network client can read any .jsonl file the server can access.
Mitigation
This issue has been patched in version 5.1.0.
Topics
Related items
- CriticalCVE-2026-108263: Astron Agent is an agentic workflow platform for building and running AI agents. Prior to 1.1.2, the default workflow coSimilar attack · NVD/CVE Database
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSimilar attack · BleepingComputer
- LowSocial Engineering AI Agents: The New BEC for 2026Similar attack · Dark Reading
- HighGHSA-cv3g-hj65-pcfh: PraisonAI: Shell command allowlist bypass via find -exec built-in actionSimilar attack · GitHub Advisory Database
- CriticalGHSA-9mp3-24cc-77mg: PraisonAI: AICoder Arbitrary File Write and Command Execution via LLM Tool CallsSimilar attack · GitHub Advisory Database